Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Remove "missing fields" from alerts trend graph and count table #108841

Closed
machadoum opened this issue Aug 17, 2021 · 2 comments
Assignees
Labels
enhancement New value added to drive a business result Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting Security Solution Threat Hunting Team v7.15.0 v8.0.0

Comments

@machadoum
Copy link
Member

"all others" and "0.0.0.0" labels inside the alerts table trend graph and count table are inaccurate and misleading. It currently displays "All others", but it is a bucket containing all events with missing fields. After some discussion, we agreed to remove it from the table and graph for now.

Screenshot 2021-08-16 at 17 54 39

Screenshot 2021-08-16 at 17 52 07

@machadoum machadoum added enhancement New value added to drive a business result v8.0.0 Team:Threat Hunting Security Solution Threat Hunting Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. v7.15.0 labels Aug 17, 2021
@machadoum machadoum self-assigned this Aug 17, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-threat-hunting (Team:Threat Hunting)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New value added to drive a business result Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting Security Solution Threat Hunting Team v7.15.0 v8.0.0
Projects
None yet
Development

No branches or pull requests

2 participants