Skip to content

[Security] Entity Analytics: overview and privileged user monitoring #2191

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 13 commits into from
Jul 29, 2025

Conversation

natasha-moore-elastic
Copy link
Contributor

@natasha-moore-elastic natasha-moore-elastic commented Jul 21, 2025

Resolves #1646 by documenting the new Entity Analytics workflow in the Security app. This includes:

  • The new Entity analytics navigation item in the nav menu and the advanced setting that enables it
  • The new Entity analytics overview page, which has the same functionality as the existing Entity Analytics dashboard page (to be deprecated in a later Stack version)
  • The new privileged user monitoring capability

Previews

New pages:

Updated pages/sections:

@natasha-moore-elastic natasha-moore-elastic self-assigned this Jul 21, 2025
@natasha-moore-elastic natasha-moore-elastic added Serverless Improvements and changes to the Serverless Docs v9.1.0 labels Jul 21, 2025
serverless: all
```

| Action | Predefined role |
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Roles for serverless TBD

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We haven't created these roles yet, the feature isn't enabled in serverless yet @jaredburgettelastic whats our plan here?

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@natasha-moore-elastic we wont be releasing this in serverless for probably ~2 weeks does that affect the docs you wish to add?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @hop-dev, I've removed serverless references and updated the availability tags to reflect that it will only be available in 9.1. I'll spin off another doc issue to track when we need to add back the serverless references.

Copy link

@hop-dev hop-dev left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great work thank you!

Copy link
Contributor

@nastasha-solomon nastasha-solomon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great!

@natasha-moore-elastic natasha-moore-elastic enabled auto-merge (squash) July 29, 2025 08:09
@natasha-moore-elastic natasha-moore-elastic merged commit b744895 into main Jul 29, 2025
7 of 8 checks passed
@natasha-moore-elastic natasha-moore-elastic deleted the issue-1646-EA branch July 29, 2025 08:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[Stack]: New Entity Analytics Workflow (Overview and Privileged User Monitoring)
3 participants