Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution][Alert Details] - clicking on a value in the value column should open a preview #189864

Closed
PhilippeOberti opened this issue Aug 5, 2024 · 4 comments
Assignees
Labels
Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting:Investigations Security Solution Investigations Team Team:Threat Hunting Security Solution Threat Hunting Team v8.16.0
Milestone

Comments

@PhilippeOberti
Copy link
Contributor

Description

In the alert details expandable flyout Table tab we show all the field/value pairs. Some of them (host.ip, host.name, kibana.alert.rule.name, user.name...) can be interacted with. The user can click on the value and the current behavior is to open the corresponding detailed page in a new tab (host detail, user detail, network detail, rule detail...)

To be consistent with the recent work that enabled host and user previews as well as alert previews throughout the flyout, we should apply the same logic here and open the preview panels instead of navigating to a new page.
Users will still be able to navigate to the detailed pages after opening the previews, by clicking on the footer of those preview panels.

Current behavior

Screen.Recording.2024-08-05.at.11.16.58.AM.mov
Screen.Recording.2024-08-05.at.11.17.33.AM.mov

Desired behavior

Screen.Recording.2024-08-05.at.11.22.13.AM.mov

Acceptance criteria

  • all the values in the Table tab should open a preview (if the preview panel for it exists)

Notes

The network/ip flyout currently doesn't have a preview flyout. The work is logged in this ticket.

@PhilippeOberti PhilippeOberti added Team:Threat Hunting Security Solution Threat Hunting Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting:Investigations Security Solution Investigations Team v8.16.0 labels Aug 5, 2024
@PhilippeOberti PhilippeOberti added this to the 8.16 milestone Aug 5, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-threat-hunting (Team:Threat Hunting)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-threat-hunting-investigations (Team:Threat Hunting:Investigations)

@christineweng christineweng self-assigned this Aug 5, 2024
@christineweng
Copy link
Contributor

#190560 enables preview in table tab

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting:Investigations Security Solution Investigations Team Team:Threat Hunting Security Solution Threat Hunting Team v8.16.0
Projects
None yet
Development

No branches or pull requests

3 participants