-
Notifications
You must be signed in to change notification settings - Fork 997
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Related containers / correlation enhancements #3227
Labels
Milestone
Comments
labo-flg
added a commit
that referenced
this issue
Sep 28, 2024
5 tasks
labo-flg
added a commit
that referenced
this issue
Oct 8, 2024
Gwendoline-FAVRE-FELIX
pushed a commit
that referenced
this issue
Jan 7, 2025
Gwendoline-FAVRE-FELIX
pushed a commit
that referenced
this issue
Jan 7, 2025
Gwendoline-FAVRE-FELIX
pushed a commit
that referenced
this issue
Jan 7, 2025
Gwendoline-FAVRE-FELIX
pushed a commit
that referenced
this issue
Jan 7, 2025
Gwendoline-FAVRE-FELIX
pushed a commit
that referenced
this issue
Jan 7, 2025
Gwendoline-FAVRE-FELIX
pushed a commit
that referenced
this issue
Jan 7, 2025
Gwendoline-FAVRE-FELIX
pushed a commit
that referenced
this issue
Jan 7, 2025
Gwendoline-FAVRE-FELIX
pushed a commit
that referenced
this issue
Jan 7, 2025
Gwendoline-FAVRE-FELIX
pushed a commit
that referenced
this issue
Jan 7, 2025
Gwendoline-FAVRE-FELIX
pushed a commit
that referenced
this issue
Jan 7, 2025
Gwendoline-FAVRE-FELIX
pushed a commit
that referenced
this issue
Jan 7, 2025
Gwendoline-FAVRE-FELIX
pushed a commit
that referenced
this issue
Jan 7, 2025
delemaf
added a commit
that referenced
this issue
Jan 9, 2025
delemaf
added a commit
that referenced
this issue
Jan 9, 2025
delemaf
added a commit
that referenced
this issue
Jan 9, 2025
delemaf
added a commit
that referenced
this issue
Jan 9, 2025
Gwendoline-FAVRE-FELIX
added a commit
that referenced
this issue
Jan 14, 2025
delemaf
added a commit
that referenced
this issue
Jan 15, 2025
Gwendoline-FAVRE-FELIX
added a commit
that referenced
this issue
Jan 15, 2025
Co-authored-by: FlorianDelemarre <[email protected]>
delemaf
added a commit
that referenced
this issue
Jan 15, 2025
delemaf
added a commit
that referenced
this issue
Jan 15, 2025
delemaf
added a commit
that referenced
this issue
Jan 21, 2025
5 tasks
delemaf
added a commit
that referenced
this issue
Jan 21, 2025
delemaf
added a commit
that referenced
this issue
Jan 22, 2025
SamuelHassine
added
the
solved
use to identify issue that has been solved (must be linked to the solving PR)
label
Jan 27, 2025
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Use case
When we display the list of "correlated containers":
Right now, it is based on common observables and indicators. That being said:
In addition to this, when you are exploring the "correlation view" in the graph (3 clicks away), it is correlating on "everything", not only indicators and observables, so you have to refilter. So to get the real details about correlated containers in the overview, assuming you know how this work, it is more than 5 or 6 clicks away.
We need to implement a quick button here:
This button will open a dialog with a table of correlations with details. Something like the list of containers and the number of common objects and you can expand to see the the list of those objects for each container.
What's the functional need
ability to understand among the different correlated cases/reports, the level of correlation (is it high, low...)
ability to view the list of correlated entities
ability to pivot on them/perform actions on them
Potential solution
Potential Solution 1
Add a counter next to each report/cases to indicate the amount of correlated entities/observables
Ability to click on a CTA and be redirected to data/entities to see the list of entities/observables
To do this, add a new filter "contained in = Container A" that would list all entities contained in entity A
Add a filter on the meta type Entity Type = Observable
The screen data entities should be filtered on "contained in = Container A AND container B" AND "entity Type = Indicator OR observable"
BONUS: extend the correlation between containers of different types (ex: a report can be correlated with a case)
Potential Solution 2
Add a counter next to each report/cases to indicate the amount of correlated entities/observables
click on CTA to open a modal that contains all containers correlated, with an option to expand the view of correlated entities
The text was updated successfully, but these errors were encountered: