[Security Solution] Discussion - Security Profile experience for security users in One Discover #189897
Labels
Feature:Discover in Security
Team:Threat Hunting:Investigations
Security Solution Investigations Team
triage_needed
Milestone
Summary
Currently, One Discover does not gives security solution a way to know if a user is a security user or not. This might result in below issues:
Profile Conflict
Security wants to give users a "Security Experience" for all the events irrespective of where that event originated. For example, that event could be a
log
event or an event from any of thebeats
.For simplicity, if we assume it is a
log
event, then it is difficult for One Discover to know which profile should take precedence because that event is relevant to both Security and O11y.Data Source Profile Resolution
Since security does not have any particular index ( in addition to
.alerts-security*
) it wants to look at, users of security can create their custom data view and may look at any index they want.Because of this, it is not straightforward to create any kind of heuristics to determine whether the security profile should be activated.
Possible Solutions
/app/security/discover...
or/app/o11y/discover...
The text was updated successfully, but these errors were encountered: