Project

General

Profile

Actions

Feature #7706

open

Users should be able to choose which information about events should be displayed in the event search

Added by Jakub Judiny 10 months ago. Updated 4 months ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Development - GUI
Target version:
Start date:
02/20/2024
Due date:
% Done:

0%

Estimated time:
To be discussed:
No

Description

Now there are fixed fields displayed in the event search (detected at, sources, severity, category, detector and abuse group). But it could be useful to allow users to choose which fields (e.g. description, port, protocol) should be displayed there instead - this could be helpful when searching for something specific, that cannot be specified through our form.

Based on input from Pavla Hlučková.

Example use case: I want to see description (or other field not displayed there by default) of the searched events without needing to open them all, which could save a lot of time and clicks.


Related issues

Related to Mentat - Feature #7707: All fields in search form should have negationsNew02/20/2024

Actions
Actions #1

Updated by Jakub Judiny 10 months ago

  • Related to Feature #7707: All fields in search form should have negations added
Actions #2

Updated by Jakub Judiny 10 months ago

  • Description updated (diff)
Actions #3

Updated by Jakub Judiny 10 months ago

  • Description updated (diff)
Actions #4

Updated by Jakub Judiny 10 months ago

  • Description updated (diff)
Actions #5

Updated by Jakub Judiny 4 months ago

Another possible use case: When user is trying to search events based on target fields such as target class, only source IP addresses will be displayed in the show view, which is not very useful when user is concerned with targets.

Actions #6

Updated by Pavel Kácha 4 months ago

Note: In RT#1274769 wish for target ports and services visible on search results was mentioned.

Actions

Also available in: Atom PDF