securityonion icon indicating copy to clipboard operation
securityonion copied to clipboard

FEATURE: Expose new rule summary to Alerts page

Open dougburks opened this issue 4 months ago • 1 comments

As an analyst, if I'm on the Alerts page looking at an alert that I've never seen before and I'm having trouble parsing the syntax, then it might be helpful to have the the new rule summary available to help me understand what it's looking for. I can use the Tune Detection menu item to go to the Detections page TUNING tab and then click the OVERVIEW tab, but it would be nice to save a click or two. When triaging hundreds or thousands of alerts, those clicks can add up.

This was discussed on a call on 10/3/2024 and we brainstormed a couple of options:

  • A simple option would be a new menu entry similar to Tune Detection that would go to the Detections page but instead of going to the TUNING tab it would go to the OVERVIEW tab.
  • A more complex option would be a button or menu item that would create a popup (NOT a tooltip) on the Alerts page itself with the rule summary information.

dougburks avatar Oct 03 '24 19:10 dougburks