alphasoc/alphasocbeat

[AlphaSOC] Details dashboard adjustments

Closed this issue · 2 comments

ioj commented

Please make the following adjustments:

  • Remove the second table as it's redundant
  • Rename the dashboard to AlphaSOC Detailed View
  • Add Source IP column to the table
  • Remove the Flag column as it expands the same threat into many rows
  • Adjust colum widths to be more sensible (e.g. a narrow Pipeline column, a wider Threat column, and so on).
  • Sort by timestamp descending by default.

image

Is Source IP always an IP here, or can it be an agent ID or hostname? If so, we should rename to Source

ioj commented

Always IP, unfortunately. As with Graylog, there are no advanced replacement, aggregation or conditional functions in standard Kibana visualizations.