Under the Security posture there is a "Notable Events By Urgency" chart but it only shows medium, low and informational. I need to report High and critical notable events.
Why doesn't the chart show all categories of urgency?
The query under 'Notable Events By Urgency' panel is not filtering events by severity.
Query used in the panel:
| `es_notable_events` | search timeDiff_type=current | stats sum(count) as count by urgency | `stats2chart("urgency")`
Tip: Press Ctrl + Shift + E
(in Windows) to expand the macro in the query.
If the notable events (including 'High' and 'Critical' ones) exists in the lookup table es_notable_events
, you can see them under the 'Notable Events By Urgency' panel
@rhoush
If my answer helped you, please accept and/or upvote it!
Version is 5.3.0 Build 9
What version of ES do you have? It shows data from the last 24 hours, so if you don't have any notables that are high or critical from the last 24 hours of data, they might not appear. It should show all categories of urgency, but only if there is >0 results for them.