The reimagined alert experience, first introduced in Elastic Security 8.10, brought an entirely new prebuilt, investigative experience to alerts by providing insights to the analyst, such as related entities, correlated events, and visualization previewing. Over the last few releases, this experience has been steadily improving by extending the alert experience to all events and bringing the new design to the investigative workspace called Timeline.
Now in Elastic Security 8.15, we allow pivoting between experiences without changing the primary context. For instance, a user can be viewing an alert and then preview correlated alerts, related events, and details about the host and user entities. This enables the user to see other Elastic Security experiences without disrupting their core workflow like alert investigation.
Leave a Reply