-
Notifications
You must be signed in to change notification settings - Fork 187
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Remove discover] Implement embeddable dashboard on Threat hunting module #6478
Comments
Update 06/03/2024Progress was made by migrating the Threat Hunting overview definitions. The visualizations are already made with embeddables. Likewise, the visualizations are integrated with the searchbar bidirectionally.
Evidence |
Update 07/03/2024Added the Note The examples below only have the definitions changed from the first two visualizations. So does the screenshot shown below. Structure of normal panels
Structure of panels with pinned agent
Capture showing the change of the dashboard depending on whether or not there is an agent pinnedEvidence_Change_Pinned_Agent.webm |
Update 08/03/2024The aesthetics of the KPIs were adjusted using embeddable visualizations. It is analyzed that the queries for the new KPIs are correct according to the previous queries.Total metric Level 12 or Above metric Authentication failure metric Authentication success metric To continue:
Current screen without agent pinnedCurrent screen with pinned agent |
Update 13/03/2024
EvidenceEvidence_Changes_2024-03-13.webm |
Update 18/04/2024
Hide alerts and allow agents evidenceCurrent screenPinned agent behaviorEvidence_Pinned_Agent_2024-04-18.webm |
Update 19/04/2024
|
Update 22/04/2024
Current behaviorEvidence_1.webm |
Update 24/04/2024
|
Description
We have to implement the embeddable dashboard on Threat hunting -> dashboard tab and deprecate any use of kibana-integrations components.
Warning
The embeddable panel id must be unique including general and agents visualizations. Otherwise, the visualizations will not refresh when we pin an agent, because they are cached by id
Current Threat Hunting screens
Tasks
hide alerts
,allow agents
and filter order.hide alerts
,allow agents
and filter order.Source task
The text was updated successfully, but these errors were encountered: