Skip to content

[REQUEST]: Enable endpoint actions in events #674

Open
@christineweng

Description

@christineweng

Description

Endpoint actions (isolate/release, respond) were available in alerts. This PR extends the availability to events. If a host can be isolated, it will show up for an event. 2 places where users expect to see updates:

  • When investigating in analyzer (must be open in flyout), clicking an event opens an event preview, isolate host and respond are now available in take action
  • When in event flyout (from host, user table), the options are also shown in the take action menu.

Image

Resources

PR: elastic/kibana#206857
Issue: https://github.com/elastic/security-team/issues/11248

This enhancement will go to 8.19, 9.1 and serverless

Which documentation set does this change impact?

Elastic On-Prem and Cloud (all)

Feature differences

The feature is identical in all deployment methods

What release is this request related to?

N/A

Collaboration model

The documentation team

Point of contact.

Main contact: @christineweng

Stakeholders: @paulewing @elastic/security-defend-workflows

Metadata

Metadata

Labels

Team:SecurityIssues owned by the Security Docs Team

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions