Company
Date Published
Author
-
Word count
556
Language
-
Hacker News points
None

Summary

Elastic Security enhances threat investigations and collaboration by allowing users to export and import Timelines and Timeline templates between Kibana Spaces or instances. The Timeline feature serves as a dynamic workspace for investigations, enabling users to drag and drop queries and collect data from multiple indices to analyze complex threats. It auto-saves progress for team review and supports the creation of templates that filter out noisy alerts, ensuring a unified perspective on potential threats. To share a Timeline, users can export it as an ndjson file, which contains the necessary information to recreate the Timeline elsewhere. Importing a Timeline requires editing the savedObjectId in the ndjson file to prevent conflicts with existing Timelines, while templates allow for updates through file imports by adjusting the templateTimelineVersion. Elastic Security documentation offers further guidance, and new users can explore its features via Elasticsearch Service on Elastic Cloud.