[Docs]7.7 SIEM doc updates (#63951)

* SIEM section doc updates

* corrections

* more corrections
This commit is contained in:
Ben Skelker 2020-04-21 20:14:25 +03:00 committed by GitHub
parent 0c14424321
commit b7aab690f4
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
3 changed files with 19 additions and 1 deletions

View file

@ -217,6 +217,8 @@ might increase the search time. This setting is off by default. Users must opt-i
[horizontal]
`siem:defaultAnomalyScore`:: The threshold above which Machine Learning job anomalies are displayed in the SIEM app.
`siem:defaultIndex`:: A comma-delimited list of Elasticsearch indices from which the SIEM app collects events.
`siem:ipReputationLinks`:: A JSON array containing links for verifying the reputation of an IP address. The links are displayed on
{siem-guide}/siem-ui-overview.html#network-ui[IP detail] pages.
`siem:enableNewsFeed`:: Enables the security news feed on the SIEM *Overview*
page.
`siem:newsFeedUrl`:: The URL from which the security news feed content is

Binary file not shown.

After

Width:  |  Height:  |  Size: 305 KiB

View file

@ -35,7 +35,7 @@ image::siem/images/network-ui.png[]
[float]
[[detections-ui]]
=== Detections (Beta)
=== Detections (beta)
The Detections feature automatically searches for threats and creates
signals when they are detected. Signal detection rules define the conditions
@ -50,6 +50,22 @@ or the Detections API.
[role="screenshot"]
image::siem/images/detections-ui.png[]
[float]
[[cases-ui]]
=== Cases (beta)
Cases are used to open and track security issues directly in SIEM.
Cases list the original reporter and all users who contribute to a case
(`participants`). Case comments support Markdown syntax, and allow linking to
saved Timelines. Additionally, you can send cases to external systems from
within SIEM (currently ServiceNow).
For information about opening, updating, and closing cases, see
{siem-guide}/cases-overview.html[Cases] in the SIEM Guide.
[role="screenshot"]
image::siem/images/cases-ui.png[]
[float]
[[timelines-ui]]
=== Timeline