-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security Solution][Entity Analytics] Adding alert contribution score in risk summary #174443
Conversation
Pinging @elastic/security-entity-analytics (Team:Entity Analytics) |
💔 Build Failed
Failed CI StepsTest Failures
Metrics [docs]Module Count
Async chunks
HistoryTo update your PR or re-run it, just comment with: |
category_1_score: number; | ||
category_1_count: number; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is this the best way to do this? @machadoum
1f1dd63
to
00b2d42
Compare
I am confused with the number 375 from your screenshot. I think the original idea, was to show the number related to how much alerts contributed as part of the final risk score. So final risk score - is 63 Alert contributing - should be <= 63. My understanding, that it should be always equal final risk score, until we have asset enrichment multiplier |
…isk Summary (#174574) Adding context in Risk Summary, part of [#8207](elastic/security-team#8207) Meta This PR handles both [#8357](elastic/security-team#8357) and [#8359](elastic/security-team#8359) <img width="609" alt="Screenshot 2024-01-10 at 12 06 00" src="https://github.com/elastic/kibana/assets/2423976/1f516eb9-1723-4c88-80b9-b61905a59f6a"> Closing #174443 since this PR includes those changes as well --------- Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
Adding alert cumulative contribution to risk score in #8357