View and analyze risk score data
editView and analyze risk score data
editThe Elastic Security app provides several options to monitor the change in the risk posture of hosts and users from your environment. Use the following places in the Elastic Security app to view and analyze risk score data:
We recommend that you prioritize alert triaging to identify anomalies or abnormal behavior patterns.
Entity Analytics dashboard
editFrom the Entity Analytics dashboard, you can access entity key performance indicators (KPIs), risk scores, and levels. You can also click the number link in the Alerts column to investigate and analyze the alerts on the Alerts page.
Alert triaging
editYou can prioritize alert triaging to analyze alerts associated with risky entities using the following features in the Elastic Security app.
Alerts page
editUse the Alerts table to investigate and analyze host and user risk levels and scores. We recommend adding the user.risk.calculated_level
and host.risk.calculated_level
columns to the Alerts table to easily display this data. To do this, select Fields, search for user.risk
and host.risk
, then select the appropriate fields from the list. Learn more about customizing the Alerts table.
You can use the drop-down filter controls to filter alerts by their risk score level. To do this, edit the default controls to filter by user.risk.calculated_level
or host.risk.calculated_level
:
Alert details flyout
editTo access risk score data in the alert details flyout, select Insights → Entities on the Overview tab:
Hosts and Users pages
editOn the Hosts and Users pages, you can access the risk score data:
-
In the Host risk level or User risk level column on the All hosts or All users tab:
-
On the Host risk or User risk tab:
Host and user details pages
editOn the host details and user details pages, you can access the risk score data:
-
In the Overview section:
-
On the Host risk or User risk tab: