You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Endpoint actions (isolate/release, respond) were available in alerts. This PR extends the availability to events. If a host can be isolated, it will show up for an event. 2 places where users expect to see updates:
When investigating in analyzer (must be open in flyout), clicking an event opens an event preview, isolate host and respond are now available in take action
When in event flyout (from host, user table), the options are also shown in the take action menu.
Description
Endpoint actions (isolate/release, respond) were available in alerts. This PR extends the availability to events. If a host can be isolated, it will show up for an event. 2 places where users expect to see updates:
Resources
PR: elastic/kibana#206857
Issue: https://github.com/elastic/security-team/issues/11248
This enhancement will go to
8.19
,9.1
and serverlessWhich documentation set does this change impact?
Elastic On-Prem and Cloud (all)
Feature differences
The feature is identical in all deployment methods
What release is this request related to?
N/A
Collaboration model
The documentation team
Point of contact.
Main contact: @christineweng
Stakeholders: @paulewing @elastic/security-defend-workflows
The text was updated successfully, but these errors were encountered: