[Security][9.5 & Serverless] Document the new flyout system for alert and event details - #7719
[Security][9.5 & Serverless] Document the new flyout system for alert and event details#7719nastasha-solomon wants to merge 17 commits into
Conversation
… and event details Rewrites the alert details flyout page around the new EUI session flyout (main + tools flyouts, no more right/left/preview panels), and updates related pages that referenced the old panel model. Fixes #7607. Co-authored-by: Cursor <cursoragent@cursor.com>
Elastic Docs AI PR menuCheck the box to run an AI review for this pull request.
Powered by GitHub Agentic Workflows and docs-actions. For more information, reach out to the docs team. |
Elastic Docs Style Checker (Vale)Summary: 1 warning found
|
| File | Line | Rule | Message |
|---|---|---|---|
| solutions/security/detect-and-alert/view-detection-alert-details.md | 23 | Elastic.DirectionalLanguage | Don't use directional language. Use 'in the following section' instead of 'described below'. |
The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.
There was a problem hiding this comment.
Looks good overall, added a few comments for your consideration.
Thanks!
Edit: I've also pushed a commit (b137dba) that replaces the "expand" wording in two other EA files.
|
|
||
| ## Entity details flyout | ||
|
|
||
| Refer to [Details flyouts](/solutions/security/get-started/elastic-security-ui.md#details-flyouts) for the flyout's shared header controls, footer, and child flyout navigation. |
There was a problem hiding this comment.
| Refer to [Details flyouts](/solutions/security/get-started/elastic-security-ui.md#details-flyouts) for the flyout's shared header controls, footer, and child flyout navigation. | |
| Refer to [Details flyouts](/solutions/security/get-started/elastic-security-ui.md#details-flyouts) for the toolbar controls, footer, and child flyout navigation shared across {{elastic-sec}} flyouts. |
Matches the wording from manage-discoveries-from-attacks-page.md and view-detection-alert-details.md, which I prefer slightly since it states what surface the flyout is shared across.
| You can also chat with AI Assistant from several particular pages in {{elastic-sec}} where you can easily send context-specific data and prompts to AI Assistant. | ||
|
|
||
| * [Alert details](/solutions/security/detect-and-alert/view-detection-alert-details.md) or Event details flyout: Click **Chat** while viewing the details of an alert or event. | ||
| * [Alert details](/solutions/security/detect-and-alert/view-detection-alert-details.md) or Event details flyout: {applies_to}`stack: ga 9.5+` {applies_to}`serverless: ga` Click **Ask AI Assistant** (or **Add to chat**, if [Agent Builder](/explore-analyze/ai-features/elastic-agent-builder.md) is enabled) in the footer while viewing the details of an alert or event. |
There was a problem hiding this comment.
The instructions in this section are specifically for opening/chatting with AI Assistant, so I think mentioning Agent Builder and its button would cause confusion (or imply that you can still chat with AI Assistant from the Agent Builder chat).
I also think that adding an applies to tag here could be misinterpreted to mean that the whole functionality described in the bullet is available from 9.5, rather than just the button's name change. I'd propose leaving it out here, and slightly rewording the version-scoped note to clarify the button's name change.
| * [Alert details](/solutions/security/detect-and-alert/view-detection-alert-details.md) or Event details flyout: {applies_to}`stack: ga 9.5+` {applies_to}`serverless: ga` Click **Ask AI Assistant** (or **Add to chat**, if [Agent Builder](/explore-analyze/ai-features/elastic-agent-builder.md) is enabled) in the footer while viewing the details of an alert or event. | |
| * [Alert details](/solutions/security/detect-and-alert/view-detection-alert-details.md) or Event details flyout: Click **Ask AI Assistant** in the footer while viewing the details of an alert or event. |
| {applies_to}`stack: ga 9.5+` {applies_to}`serverless: ga` Whenever an analyst opens an alert produced by that rule, the guide is available from the [Investigation section](/solutions/security/detect-and-alert/view-detection-alert-details.md#investigation-section) on the **Overview** tab of the alert details flyout. | ||
|
|
||
| ::::{note} | ||
| :applies_to: stack: ga 9.0-9.4 | ||
| In these versions, the guide renders in the **Investigation** tab of the alert details flyout instead. | ||
| :::: |
There was a problem hiding this comment.
I'm a bit confused – I feel like line 21 is true for both pre-9.5 and 9.5+. The guide was available from the Investigation section before 9.5, right? (it just rendered differently when you clicked to open it)
The note reads like the Investigation tab was next to the Overview, Table, and JSON tabs in pre-9.5 versions, but I don't think that was the case.
| 1. {applies_to}`stack: ga 9.5+` {applies_to}`serverless: ga` Open an alert's details flyout, then click **Show investigation guide** in the [Investigation section](/solutions/security/detect-and-alert/view-detection-alert-details.md#investigation-section) on the **Overview** tab. | ||
|
|
||
| ::::{note} | ||
| :applies_to: stack: ga 9.0-9.4 | ||
| In these versions, open an alert's details flyout and go to the **Investigation** tab instead. | ||
| :::: | ||
|
|
There was a problem hiding this comment.
Same as https://github.com/elastic/docs-content/pull/7719/changes#r3727637522 - I think line 239 is true across versions.
8.19 docs say that the Investigation section is located on the Overview tab with a Show investigation guide button.
| When a rule generates an alert, Osquery automatically collects data on the host. | ||
|
|
||
| {applies_to}`stack: ga 9.5+` {applies_to}`serverless: ga` Query results are shown in the [**Response** section](/solutions/security/detect-and-alert/view-detection-alert-details.md#response-overview) on the **Overview** tab of the alert details flyout. Click **Response** to view the query results in a new flyout. | ||
|
|
||
| ::::{note} | ||
| :applies_to: stack: ga 9.0-9.4 | ||
| In {{stack}} 9.0.x-9.4.x, query results are displayed within the **Response** tab in the left panel of the alert details flyout. | ||
| :::: |
There was a problem hiding this comment.
| When a rule generates an alert, Osquery automatically collects data on the host. | |
| {applies_to}`stack: ga 9.5+` {applies_to}`serverless: ga` Query results are shown in the [**Response** section](/solutions/security/detect-and-alert/view-detection-alert-details.md#response-overview) on the **Overview** tab of the alert details flyout. Click **Response** to view the query results in a new flyout. | |
| ::::{note} | |
| :applies_to: stack: ga 9.0-9.4 | |
| In {{stack}} 9.0.x-9.4.x, query results are displayed within the **Response** tab in the left panel of the alert details flyout. | |
| :::: | |
| When a rule generates an alert, Osquery automatically collects data on the host. Query results are available from the [**Response** section](/solutions/security/detect-and-alert/view-detection-alert-details.md#response-overview) on the **Overview** tab of the alert details flyout. Click **Response** to view the query results. |
Similar to previous comments about the Investigation section, I think we can phrase this with language that's true across versions and avoids adding applies tags.
…ls.md Co-authored-by: natasha-moore-elastic <137783811+natasha-moore-elastic@users.noreply.github.com>
Co-authored-by: natasha-moore-elastic <137783811+natasha-moore-elastic@users.noreply.github.com>
…ls.md Co-authored-by: natasha-moore-elastic <137783811+natasha-moore-elastic@users.noreply.github.com>
…ls.md Co-authored-by: natasha-moore-elastic <137783811+natasha-moore-elastic@users.noreply.github.com>
Summary
For 9.5, the new flyout system (EUI session flyout) goes GA in Security Solution, replacing the legacy right/left/preview panel model with a single flyout plus child flyouts that layer on top of it. This rewrites the primary affected page, adds a shared "Details flyouts" reference for the mechanics common to all of these flyouts (to avoid re-documenting the same header/footer/navigation on every page), and updates related pages that referenced the old panel structure or were missing version tags for the new behavior.
Fixes #7607.
All UI details (button labels, icons, which actions open a new flyout vs. a popover, and which behaviors are version-gated) were verified against the Kibana source rather than assumed.
Previews
applies_totag to the Insights section.applies_totags and legacy notes for the pre-9.5 wording.securitySolution:enableNewFlyoutadvanced setting, fixes a broken anchor left over from the old page structure, and points the legacy-flyout reference to the new shared Details flyouts section.Follow-ups (not included in this PR)
A few screenshots likely still show the old flyout chrome and should be recaptured separately:
security-ig-alert-flyout.png,security-ig-alert-flyout-invest-tab.png(investigation guide)security-alerts-flyout-rs.png,security-risk-summary.png(risk score data)security-alerts-flyout-table.png(table settings menu)security-osquery-results-tab.png(Osquery response actions)Generative AI disclosure
Tool(s) and model(s) used: Cursor (Claude)