# Customize Columns for SIEM Signals and External Alerts not persistent?

**URL:** <https://discuss.elastic.co/t/customize-columns-for-siem-signals-and-external-alerts-not-persistent/229825>\
**Category:** SIEM\
**Created:** [April 26, 2020, 9:00am UTC](https://discuss.elastic.co/t/customize-columns-for-siem-signals-and-external-alerts-not-persistent/229825 "2020-04-26T09:00:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [April 26, 2020, 9:00am UTC](https://discuss.elastic.co/t/customize-columns-for-siem-signals-and-external-alerts-not-persistent/229825/1 "2020-04-26T09:00:35Z")

</div>

Hello,

Is there a way to make changes to columns for `Signals` and `External Alerts` consistent? Because currently by default (7.6.1) `External Alerts` colums are always reverted to this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/2/42a26659189721dfdf917dcd22a5176f9c032360.png)

Which makes no sense.. As:

`event.module` is irrelevant when `event.dataset` is shown. `observer.name` is a field which doesn't even exist (instead of `observer.hostname`)

Also `agent.id` is really not useful to show on an already crowded space.

Every time I make changes to the columns and refresh the page, the columns seems to be reset?

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![Mike\_Paquette](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_paquette/32/119011_2.png) [@Mike\_Paquette](https://discuss.elastic.co/u/Mike_Paquette)\
**Post date:** [April 26, 2020, 1:12pm UTC](https://discuss.elastic.co/t/customize-columns-for-siem-signals-and-external-alerts-not-persistent/229825/2 "2020-04-26T13:12:37Z")

</div>

Hi @willemdh thanks for the post. You raise several good points here, but the common theme is that you want to be able to customize the column selections shown in the various views and have your changes persist.

Persistent, or "sticky" column customization is a much-requested enhancement, and we are looking to implement that in a future release, possibly storing these settings per-user using local storage. Please let us know if there are other related settings you'd like to see persisted? For example, do you have a default column sort-order you prefer?

> Is there a way to make changes to columns for `Signals` and `External Alerts` consistent?

This too is common feedback, and we're working towards a more consistent way to present the various kinds of alerts that are relevant to analysts. Today, while consistency is desired, keep in mind that signals and external alerts are different objects, and do have different fields available for display.

> `event.module` is irrelevant when `event.dataset` is shown.

Fair point when event.dataset is populated with the "module.dataset" convention, but that convention is not strictly required by ECS, so there is sometimes value in having both fields present.

> `observer.name` is a field which doesn't even exist (instead of `observer.hostname` )

`observer.name` is a defined ECS field, and would provide context to an analyst about, for example, which instance or a web proxy had produced the external alert, but your point is valid, that `observer.hostname` may be populated more commonly, and essentially provides similar context.

> Also `agent.id` is really not useful to show on an already crowded space.

Good point - thanks for the feedback.

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [April 27, 2020, 10:03am UTC](https://discuss.elastic.co/t/customize-columns-for-siem-signals-and-external-alerts-not-persistent/229825/3 "2020-04-27T10:03:58Z")

</div>

Hi @Mike_Paquette, As always thanks for the fast and detailed answer.

> [@Mike\_Paquette](#):
>
> the common theme is that you want to be able to customize the column selections shown in the various views and have your changes persist

Correct. The fact that the column selection is (not yet) persistent, imho makes SIEM quite annoying to use. As there are soo many different views on this, if I were Elastic, I would aim high and allow Elastic admins to set a default column selection per space, while also allowing individual users to override the default and further customize to their own needs.

> but that convention is not strictly required by ECS

Filebeat event.dataset field's are already using that convention, but Auditbeat, Packetbeat, Heartbeat, Winlogbeat events don't. Why aren't they? Imho, as a major categorization field, which is used in a lot of Elastic's components, this should be the case. If event.dataset always contains the 'module', there would be no / less need to also show eventModule, which would save a lot of column space.

> Please let us know if there are other related settings you'd like to see persisted? For example, do you have a default column sort-order you prefer?

Imho at this moment the default sort order should be @timestamp

It should however be very easy to switch to sorting based on `event.severity` (for External Alerts) or on `signal.rule.risk_score` for Signals.

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2020, 10:04am UTC](https://discuss.elastic.co/t/customize-columns-for-siem-signals-and-external-alerts-not-persistent/229825/4 "2020-05-25T10:04:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![christos.nasikas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christos.nasikas/32/45611_2.png) [@christos.nasikas](https://discuss.elastic.co/u/christos.nasikas)\
**Post date:** [July 23, 2020, 3:25pm UTC](https://discuss.elastic.co/t/customize-columns-for-siem-signals-and-external-alerts-not-persistent/229825/5 "2020-07-23T15:25:18Z")

</div>

Hi @willemdh!

I would like to inform you that persistent column customization was implemented in this [PR](https://github.com/elastic/kibana/pull/67156)
