[AlphaSOC] Details dashboard adjustments
Closed this issue · 2 comments
ioj commented
Please make the following adjustments:
- Remove the second table as it's redundant
- Rename the dashboard to AlphaSOC Detailed View
- Add Source IP column to the table
- Remove the Flag column as it expands the same threat into many rows
- Adjust colum widths to be more sensible (e.g. a narrow Pipeline column, a wider Threat column, and so on).
- Sort by timestamp descending by default.
chrisforce1 commented
Is Source IP
always an IP here, or can it be an agent ID or hostname? If so, we should rename to Source
ioj commented
Always IP, unfortunately. As with Graylog, there are no advanced replacement, aggregation or conditional functions in standard Kibana visualizations.