Skip to content

Conversation

@benskelker
Copy link
Contributor

@benskelker benskelker commented Aug 17, 2020

Summary

Updates and renames the SIEM section in the Kibana docs.

Elastic Security preview

Advanced settings preview

[skip-ci]

@benskelker benskelker added release_note:skip Skip the PR/issue when compiling release notes v7.9.0 labels Aug 17, 2020
@benskelker benskelker requested review from KOTungseth, gchaps and karenzone and removed request for karenzone August 17, 2020 13:44
@benskelker benskelker changed the title [Socs]Security docs 7.9 updates [Docs]Security docs 7.9 updates Aug 17, 2020
`filebeat-*`, `packetbeat-*`, `endgame-*`, `logs-*`, and `apm-*-transaction*`. You can
change the default index patterns in
*Kibana > Management > Advanced Settings > siem:defaultIndex*.
*Kibana > Stack Management > Advanced Settings > securitySolution:defaultIndex*.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How about changing to something like this:

To change the default pattern patterns, go to Stack Management > Advanced Settings and then find the securitySolution:defaultIndex setting.

as the `Entity` itself, or any of the associated `Influencers`.
Machine Learning functionality is available throughout Elastic Security. You can
view the details of detected anomalies in the `Anomalies` table widget
shown on the Hosts, Network and associated Details pages. you can drag and drop
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
shown on the Hosts, Network and associated Details pages. you can drag and drop
shown on the Hosts, Network and associated Details pages. You can drag and drop

[role="xpack"]
[[siem-ui]]
== Using the SIEM UI
== Using Elastic Security UI
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
== Using Elastic Security UI
== Using Elastic Security


The Hosts view provides key metrics regarding host-related security events, and
The Hosts page provides key metrics regarding host-related security events, and
data tables and widgets that let you interact with the Timeline Event Viewer.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you rewrite without "widgets". Are these charts?

Guide for information on managing detection rules and signals via the UI
or the Detections API.
See {security-guide}/detection-engine-overview.html[Detections] for information
on managing detection rules and alerts via the UI or the Detections API.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How about removing "via the UI or the Detections API."


An analyst notices a suspicious user ID that warrants further investigation, and
clicks a url that links to the SIEM app.
clicks a url that links to Elastic Security.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
clicks a url that links to Elastic Security.
clicks a URL that links to Elastic Security.

clicks a url that links to the SIEM app.
clicks a url that links to Elastic Security.

The analyst uses the tables, widgets, and filtering and search capabilities in
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

be more specific than widget.

`siem:ipReputationLinks`:: A JSON array containing links for verifying the reputation of an IP address. The links are displayed on
{security-guide}/siem-ui-overview.html#network-ui[IP detail] pages.
`siem:enableNewsFeed`:: Enables the security news feed on the SIEM *Overview*
`securitySolution:defaultAnomalyScore`:: The threshold above which Machine Learning job anomalies are displayed in the Security app.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should Security app be changed to Elastic Security in this section?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The UI name in Kibana is Security, so guess not.

[[machine-learning]]
== Anomaly Detection with Machine Learning

For *{ess-trial}[Free Trial]*
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Free trial > Free trial

Platinum License > Platinum subscription

For *{ess-trial}[Free Trial]*
and *https://www.elastic.co/subscriptions[Platinum License]* deployments,
Machine Learning functionality is available throughout the SIEM app. You can
view the details of detected anomalies within the `Anomalies` table widget
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

table widgets > tables

Should Details be lower case?

@benskelker benskelker requested a review from gchaps August 18, 2020 02:39
Copy link
Contributor

@gchaps gchaps left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@benskelker benskelker merged commit 843c238 into elastic:master Aug 18, 2020
@benskelker benskelker deleted the 7.9-security-docs branch August 18, 2020 05:25
benskelker added a commit to benskelker/kibana that referenced this pull request Aug 18, 2020
* security docs 7.9 updates

* terminology

* updates advanced settings

* terminology

* corrections
benskelker added a commit that referenced this pull request Aug 18, 2020
* security docs 7.9 updates

* terminology

* updates advanced settings

* terminology

* corrections
benskelker added a commit that referenced this pull request Aug 18, 2020
* security docs 7.9 updates

* terminology

* updates advanced settings

* terminology

* corrections
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs release_note:skip Skip the PR/issue when compiling release notes v7.9.0 v7.10.0 v8.0.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants