Adding annotations/notes/comments to individual records via Kibana

Hello. I use ELK to ingest and review huge amounts of data related to cyber security incidents (logs that are sent to me, timeline of laptops, etc.).

As I go through the data is would be useful to add notes to individual document records, For example: notable entry, follow-up, false positive, malware, upload, etc..

Aside from making my own reporting easier, this would also make it easier to collaborate with my colleagues.

Is there anyway to accomplish this with ELK? If so, would this require a specific version of ELK?

Welcome to our community! :smiley:
Check out https://www.elastic.co/siem, it might have what you want.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.