Skip to content

Commit

Permalink
[8.x] [Serverless][8.16] New notes experience - Impacted screenshots …
Browse files Browse the repository at this point in the history
…and misc updates (backport #6072) (#6078)

* [Serverless][8.16] New notes experience - Impacted screenshots and misc updates (#6072)

* Re-adds images

* Adds notes to landing page for investigative tools

* Fix Serverless TOC

* Fixes threat intel images

* Adds size configs

* fixes file name

* Minor tweaks

(cherry picked from commit 1b13703)

# Conflicts:
#	docs/serverless/alerts/view-alert-details.asciidoc
#	docs/serverless/images/interactive-investigation-guides/-detections-ig-alert-flyout-invest-tab.png
#	docs/serverless/images/interactive-investigation-guides/-detections-ig-alert-flyout.png
#	docs/serverless/images/interactive-investigation-guides/-detections-ig-timeline-query.png
#	docs/serverless/images/interactive-investigation-guides/-detections-ig-timeline.png
#	docs/serverless/images/timeline-templates-ui/-events-create-a-timeline-template-field.png
#	docs/serverless/images/timelines-ui/-events-correlation-tab-eql-query.png
#	docs/serverless/images/timelines-ui/-events-timeline-sidebar.png
#	docs/serverless/images/timelines-ui/-events-timeline-ui-renderer.png
#	docs/serverless/images/timelines-ui/-events-timeline-ui-updated.png
#	docs/serverless/images/view-alert-details/-detections-alert-details-flyout-preview-panel.gif
#	docs/serverless/images/view-alert-details/-detections-alert-details-flyout-right-panel.png
#	docs/serverless/images/view-alert-details/-detections-expand-details-button.png
#	docs/serverless/images/view-alert-details/-detections-expanded-correlations-view.png
#	docs/serverless/images/view-alert-details/-detections-expanded-entities-view.png
#	docs/serverless/images/view-alert-details/-detections-expanded-prevalence-view.png
#	docs/serverless/images/view-alert-details/-detections-expanded-threat-intelligence-view.png
#	docs/serverless/images/view-alert-details/-detections-open-alert-details-flyout.gif
#	docs/serverless/index.asciidoc
#	docs/serverless/investigate/investigate-events.asciidoc
#	docs/serverless/investigate/timeline-templates-ui.asciidoc
#	docs/serverless/investigate/timelines-ui.asciidoc
#	docs/serverless/osquery/invest-guide-run-osquery.asciidoc
#	docs/serverless/rules/interactive-investigation-guides.asciidoc

* Delete docs/serverless directory and its contents

---------

Co-authored-by: Nastasha Solomon <[email protected]>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
  • Loading branch information
3 people authored Nov 8, 2024
1 parent 2523bd2 commit d54d126
Show file tree
Hide file tree
Showing 19 changed files with 7 additions and 7 deletions.
10 changes: 5 additions & 5 deletions docs/detections/alerts-view-details.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ IMPORTANT: If you've enabled grouping on the Alerts page, the alert details flyo
[[preview-panel]]
=== Preview panel

Some areas in the flyout provide previews when you click on them. For example, clicking **Show rule summary** in the rule description displays a preview of the rule's details. To close the preview, click **x**.
Some areas in the flyout provide previews when you click on them. For example, clicking **Show rule summary** in the rule description displays a preview of the rule's details. To close the preview, click **Back** or **x**.

[role="screenshot"]
image::images/alert-details-flyout-preview-panel.gif[Preview panel of the alert details flyout, 65%]
Expand All @@ -67,13 +67,13 @@ The left panel provides an expanded view of what's shown in the right panel. To
+

[role="screenshot"]
image::images/expand-details-button.png[Expand details button at the top of the alert details flyout, 45%]
image::images/expand-details-button.png[Expand details button at the top of the alert details flyout, 65%]

* Click one of the section titles on the **Overview** tab within the right panel.
+

[role="screenshot"]
image::images/alert-details-flyout-left-panel.png[Left panel of the alert details flyout, 45%]
image::images/alert-details-flyout-left-panel.png[Left panel of the alert details flyout, 65%]

[discrete]
[[about-section]]
Expand Down Expand Up @@ -201,7 +201,7 @@ From the right panel, click **Threat intelligence** to open the expanded Threat
NOTE: The expanded threat intelligence view queries indices specified in the `securitySolution:defaultThreatIndex` advanced setting. Refer to <<update-threat-intel-indices, Update default Elastic Security threat intelligence indices>> to learn more about threat intelligence indices.

[role="screenshot"]
image::images/expanded-threat-intelligence-view.png[Expanded view of threat intelligence on the alert, 70%]
image::images/expanded-threat-intelligence-view.png[Expanded view of threat intelligence on the alert, 80%]

The expanded Threat intelligence view shows individual indicators within the alert document. You can expand and collapse indicator details by clicking the arrow button at the end of the indicator label. Each indicator is labeled with values from the `matched.field` and `matched.atomic` fields and displays the threat intelligence provider.

Expand Down Expand Up @@ -256,7 +256,7 @@ NOTE: To access data about alerts related by process ancestry, you must have a h
From the right panel, click **Correlations** to open the expanded Correlations view within the left panel.

[role="screenshot"]
image::images/expanded-correlations-view.png[Expanded view of correlation data, 65%]
image::images/expanded-correlations-view.png[Expanded view of correlation data, 75%]

In the expanded view, corelation data is organized into several tables:

Expand Down
Binary file modified docs/detections/images/alert-details-flyout-preview-panel.gif
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/detections/images/alert-details-flyout-right-panel.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/detections/images/expand-details-button.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/detections/images/expanded-correlations-view.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/detections/images/expanded-entities-view.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/detections/images/expanded-prevalence-view.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/detections/images/expanded-threat-intelligence-view.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/detections/images/ig-alert-flyout-invest-tab.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/detections/images/ig-alert-flyout.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/detections/images/ig-timeline-query.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/detections/images/ig-timeline.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/detections/images/open-alert-details-flyout.gif
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/events/images/correlation-tab-eql-query.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/events/images/create-a-timeline-template-field.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/events/images/timeline-sidebar.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/events/images/timeline-ui-renderer.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/events/images/timeline-ui-updated.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
4 changes: 2 additions & 2 deletions docs/events/timeline-ui-overview.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@ Many types of events automatically appear in preconfigured views that provide re
contextual information, called *Event renderers*. All event renderers are turned off by default. To turn them on, use the **Event renderers** toggle at the top of the results pane. To only turn on specific event renderers, click the gear (image:images/customize-event-renderers.png[The customize event renderer button,20,20]) icon next to the toggle, and select the ones you want enabled. Close the **Customize event renderers** pane when you're done. Your changes are automatically applied to Timeline.

[role="screenshot"]
image::images/timeline-ui-renderer.png[example timeline with the event renderer highlighted]
image::images/timeline-ui-renderer.png[example timeline with the event renderer highlighted, 70%]

The example above displays the Flow event renderer, which highlights the movement of
data between its source and destination. If you see a particular part of the rendered event that
Expand Down Expand Up @@ -101,7 +101,7 @@ TIP: Collapse the query builder to provide more space for Timeline results by cl
Click a filter to access additional operations such as *Add filter*, *Clear all*, *Load saved query*, and more:

[role="screenshot"]
image::images/timeline-ui-filter-options.png[width=30%]
image::images/timeline-ui-filter-options.png[width=60%]

Here are examples of various types of filters:

Expand Down

0 comments on commit d54d126

Please sign in to comment.