Skip to content

[7.9] "What's changed" - Security update overview #58

@caitlinbetz

Description

@caitlinbetz

Description

We want to include documentation to help communicate some of the changes as a result of the combined security app in 7.9. We want to get ahead of questions like "where are my signals?" and help users better understand where new and old features now live in the unified app.

What's Changed

Terminology changes for 7.9:

Old → New

  • Endpoint → Host
  • Signal Detection Rules → Detection Rules
  • Whitelist → Exception(s) / Exception List
  • Elastic SIEM & Endpoint Security → Elastic Security
  • Management → Administration
  • Signals → Detection Alerts (See note below)
    • Detection Alerts: Alerts occurring within the Elastic Security from the Detection Engine / Detection Rules
    • External Alerts: Alerts originating outside of Elastic Security
    • Kibana Alerts: Alerts native to Kibana not necessarily security-related
  • Resolver → No name, will be referred to as an action: "Analyze Event"
  • Sensor → Endpoint

Note: Some navigation changes happened due to renaming of Signals

  • Top Nav naming:
  1. Alerts → Detections
  2. URL will be app/security/detections
  • Under "Detection":
  1. Alert page title → Detection alerts
  2. Alert count → Trend
  3. Alert list → nothing (blank space)
  4. URL will be app/security/detections
  • Under "Overview":
  1. Alert Count → Detection Alert Trend
  2. External Alert Count → External Alert Trend
  • Inside Timeline Event filter drop down
  1. Alert Events → Detection Alerts

What's New

Administration Tab:

  • New Administration tab is dedicated to managing Hosts that are running endpoint security. From this page you can view hosts, view and edit the advanced integration options,

Other stuff:

Notes

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions