Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[7.9] "What's changed" - Security update overview #58

Closed
caitlinbetz opened this issue Jul 7, 2020 · 5 comments
Closed

[7.9] "What's changed" - Security update overview #58

caitlinbetz opened this issue Jul 7, 2020 · 5 comments
Assignees
Labels
Team: Docs v7.9.0 Features in the 7.9 Release

Comments

@caitlinbetz
Copy link

caitlinbetz commented Jul 7, 2020

Description

We want to include documentation to help communicate some of the changes as a result of the combined security app in 7.9. We want to get ahead of questions like "where are my signals?" and help users better understand where new and old features now live in the unified app.

What's Changed

Terminology changes for 7.9:

Old → New

  • Endpoint → Host
  • Signal Detection Rules → Detection Rules
  • Whitelist → Exception(s) / Exception List
  • Elastic SIEM & Endpoint Security → Elastic Security
  • Management → Administration
  • Signals → Detection Alerts (See note below)
    • Detection Alerts: Alerts occurring within the Elastic Security from the Detection Engine / Detection Rules
    • External Alerts: Alerts originating outside of Elastic Security
    • Kibana Alerts: Alerts native to Kibana not necessarily security-related
  • Resolver → No name, will be referred to as an action: "Analyze Event"
  • Sensor → Endpoint

Note: Some navigation changes happened due to renaming of Signals

  • Top Nav naming:
  1. Alerts → Detections
  2. URL will be app/security/detections
  • Under "Detection":
  1. Alert page title → Detection alerts
  2. Alert count → Trend
  3. Alert list → nothing (blank space)
  4. URL will be app/security/detections
  • Under "Overview":
  1. Alert Count → Detection Alert Trend
  2. External Alert Count → External Alert Trend
  • Inside Timeline Event filter drop down
  1. Alert Events → Detection Alerts

What's New

Administration Tab:

  • New Administration tab is dedicated to managing Hosts that are running endpoint security. From this page you can view hosts, view and edit the advanced integration options,

Other stuff:

Notes

@caitlinbetz caitlinbetz added Team: Docs v7.9.0 Features in the 7.9 Release labels Jul 7, 2020
@jmikell821
Copy link
Contributor

@caitlinbetz totally agree with this! This can also be an FAQ style, if applicable. Let's keep a running list of questions/'what's new" content in the comments here.

@jmikell821
Copy link
Contributor

@caitlinbetz following up on this. Let's start compiling a list of changes. I'll add my thoughts in the comments too. @benskelker since you are the most familiar with SIEM, perhaps you can weigh in as well?

@dontcallmesherryli
Copy link

@jmikell821 @caitlinbetz @benskelker I added some chunks in the "what changed" section above.

@benskelker
Copy link
Contributor

benskelker commented Aug 4, 2020

@jmikell821 @caitlinbetz @dontcallmesherryli - also added some stuff

@cnasikas
Copy link
Member

cnasikas commented Aug 4, 2020

Alert table customisations are now persistent, on both the Detections and Rule details pages (elastic/kibana#67156) cc @spong @cnasikas

I would like to add that not only the alert table is persistent but all tables in Security. Specifically, Host (Events and External alerts) and Network (External alerts).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team: Docs v7.9.0 Features in the 7.9 Release
Projects
None yet
Development

No branches or pull requests

5 participants