-
Notifications
You must be signed in to change notification settings - Fork 197
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[7.9] "What's changed" - Security update overview #58
Comments
@caitlinbetz totally agree with this! This can also be an FAQ style, if applicable. Let's keep a running list of questions/'what's new" content in the comments here. |
@caitlinbetz following up on this. Let's start compiling a list of changes. I'll add my thoughts in the comments too. @benskelker since you are the most familiar with SIEM, perhaps you can weigh in as well? |
@jmikell821 @caitlinbetz @benskelker I added some chunks in the "what changed" section above. |
@jmikell821 @caitlinbetz @dontcallmesherryli - also added some stuff |
I would like to add that not only the alert table is persistent but all tables in Security. Specifically, Host (Events and External alerts) and Network (External alerts). |
Description
We want to include documentation to help communicate some of the changes as a result of the combined security app in 7.9. We want to get ahead of questions like "where are my signals?" and help users better understand where new and old features now live in the unified app.
What's Changed
Terminology changes for 7.9:
Old → New
Detection Alerts
: Alerts occurring within the Elastic Security from the Detection Engine / Detection RulesExternal Alerts
: Alerts originating outside of Elastic SecurityKibana Alerts
: Alerts native to Kibana not necessarily security-relatedNote: Some navigation changes happened due to renaming of Signals
What's New
Administration Tab:
Other stuff:
Notes
The text was updated successfully, but these errors were encountered: