Skip to content

Commit fa497ae

Browse files
benskelkerBen Skelker
authored andcommitted
[Docs]Timeline and Template UI updates (elastic#84)
* timeline and template updates * uncomments out original timeline section in SIEM UI * removes original timeline IDs to avoid build conflict * add all actions screenshot * add all actions screenshot * corrections * adds filter explanation and legend
1 parent b1fc7e9 commit fa497ae

18 files changed

+315
-7
lines changed

docs/siem/images/timeline-ui.png

224 KB
Loading

docs/siem/index.asciidoc

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,4 +14,8 @@ include::detections/machine-learning/ml-index.asciidoc[]
1414

1515
include::detections/detections-index.asciidoc[]
1616

17+
include::timeline/timeline-ui-overview.asciidoc[]
18+
19+
include::timeline/timeline-templates.asciidoc[]
20+
1721
include::cases/cases-index.asciidoc[]

docs/siem/siem-ui.asciidoc

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -233,7 +233,6 @@ The Cases page is used to open and track security issues directly in the
233233
image::images/cases-ui-home.png[]
234234

235235
[float]
236-
[[timelines-ui]]
237236
== Timelines
238237

239238
Use Timeline as your workspace for alert investigations or threat hunting.
@@ -260,7 +259,6 @@ can also link to timelines from Cases and external ticketing systems.
260259

261260

262261
[discrete]
263-
[[raw]]
264262
==== Focus on signals or raw events
265263

266264
Many security events in Timeline are presented in an easy-to-follow rendered
@@ -272,7 +270,6 @@ You can click and expand events from within Timeline to see the underlying
272270
event data, either in tabular form, as as {es} JSON.
273271

274272
[discrete]
275-
[[narrow-expand]]
276273
==== Narrow or expand your query
277274

278275
You can specify logical `AND` and `OR` operations with an item's placement in
@@ -281,7 +278,6 @@ sets are `OR`-ed together. As you hover the item over the drop area, you can see
281278
whether your placement is on target to create an `AND` or `OR` filters.
282279

283280
[discrete]
284-
[[pivot]]
285281
==== Pivot on a data point
286282

287283
Click a filter to access additional operations such as exclude, temporarily
@@ -290,7 +286,6 @@ item so that it is excluded.
290286

291287
[discrete]
292288
[[row-renderer]]
293-
==== Get more context for each event
294289

295290
As you build and modify your queries, you can see the results of your
296291
interactions in the details pane below.
@@ -301,7 +296,6 @@ event. If you see a particular item that interests you, you can drag it to the
301296
drop area for further introspection.
302297

303298
[discrete]
304-
[[import-export-timelines]]
305299
==== Export and import timelines
306300

307301
You can import and export timelines, which enables importing timelines from one
@@ -320,7 +314,6 @@ then select _Export selected_.
320314
the timeline `ndjson` file.
321315

322316
[discrete]
323-
[[other]]
324317
==== Other actions
325318

326319
The Timeline is flexible and highly interactive. As you would expect, the
108 KB
Loading
190 KB
Loading
9.92 KB
Loading
16.1 KB
Loading
70.4 KB
Loading
9.17 KB
Loading
10 KB
Loading

0 commit comments

Comments
 (0)