# Customize Detection Columns?

**URL:** <https://discuss.elastic.co/t/customize-detection-columns/254455>\
**Category:** SIEM\
**Created:** [November 5, 2020, 9:00pm UTC](https://discuss.elastic.co/t/customize-detection-columns/254455 "2020-11-05T21:00:27Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![ikiril01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikiril01/32/70934_2.png) [@ikiril01](https://discuss.elastic.co/u/ikiril01)\
**Post date:** [November 5, 2020, 9:00pm UTC](https://discuss.elastic.co/t/customize-detection-columns/254455/1 "2020-11-05T21:00:27Z")

</div>

Is it possible to customize the columns in the detections alerts view? I'd like to incorporate some fields from the underlying events, if possible.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/0/40989a5533e1ba31728b25286220b4134e304a60.png)

---

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [November 5, 2020, 9:43pm UTC](https://discuss.elastic.co/t/customize-detection-columns/254455/2 "2020-11-05T21:43:49Z")

</div>

Hi @ikiril01!

Both timeline and our alerts tables have the ability to customize the columns that are displayed; I'm guessing your screenshot is of timeline ! On alerts tables, the feature can be found here:

 ![Detections_-_Kibana](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e1b1f2cfe68325890c1df5eab9742d5a95a2a2ba.png)

---

<div class="post-metadata">

**Author:** ![ikiril01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikiril01/32/70934_2.png) [@ikiril01](https://discuss.elastic.co/u/ikiril01)\
**Post date:** [November 5, 2020, 9:49pm UTC](https://discuss.elastic.co/t/customize-detection-columns/254455/3 "2020-11-05T21:49:10Z")

</div>

Right @RylandHerrick - the problem is that the current set of fields I see in "Customize Columns" doesn't include some specific event fields that I'm interested in being able to sort on.

Therefore, I need the ability to include some custom fields in this set. I saw that this was possible for the events table, but I'm not sure if the same is true for the alerts table.

Here's the post on customizing it for events: [SIEM -- Event Columns (Only Default Category)](https://discuss.elastic.co/t/siem-event-columns-only-default-category/234478)

---

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [November 6, 2020, 1:34am UTC](https://discuss.elastic.co/t/customize-detection-columns/254455/4 "2020-11-06T01:34:12Z")

</div>

@ikiril01 thanks for clarifying! I was able to verify this behavior myself.

The source of the behavior is that while Events and Timeline are looking at both the source indexes _and_ the internal alerts index to retrieve field data, the Alerts table is only looking at the alerts index. If the fields you're looking to display are not ECS fields, then the alerts index won't have mappings for them and thus they won't be available as columns.

Do you have examples of the fields that you're interested in displaying? I've reached out to the timeline team to see if this is expected behavior, but in the meantime I think the quickest solution would be to convert those fields to their ECS equivalents to get the behavior that you're looking for.

---

<div class="post-metadata">

**Author:** ![ikiril01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikiril01/32/70934_2.png) [@ikiril01](https://discuss.elastic.co/u/ikiril01)\
**Post date:** [November 6, 2020, 4:46pm UTC](https://discuss.elastic.co/t/customize-detection-columns/254455/5 "2020-11-06T16:46:29Z")

</div>

@RylandHerrick thanks for looking into it! It makes sense that it doesn't support the same set of fields as the events table since it only looks at the alerts index. I suppose there's no way to propagate specific fields from events to alerts?

As far as examples, we're basically just adding some custom labels to events that help us identify which enclave a machine belong to (e.g., "labels.enclave" = "lab", etc.), which would be useful to sort alerts by as well. Unfortunately there's no mapping to ECS since these are just labels.

---

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [November 6, 2020, 8:04pm UTC](https://discuss.elastic.co/t/customize-detection-columns/254455/6 "2020-11-06T20:04:22Z")

</div>

Hey @ikiril01, I spoke with both Detections and Timeline folks and this is the expected behavior for the reasons discussed. However, if you _really_ want those additional columns for alerts there is a way to do so:

**Disclaimer: the following is not recommended nor supported, proceed at your own risk.**

First, ensure that the fields you wish to add do not conflict with existing signals index. This means no conflicts with ECS fields, nor with the detections-specific `signal` fields. If these criteria are met, you can create a new signals index with your additional mappings in the following manner:

1. Create a new index template based on the signals index template but with your additional mappings
  - This is most easily done through kibana's [index management](https://www.elastic.co/guide/en/kibana/current/managing-indices.html) UI: cloning the existing signals index template, choosing a new name/pattern, and adding your additional mappings.

2. Update your Detection Engine to use your new signals index:
  - Add/update your `kibana.yml` configuration to include `xpack.securitySolution.signalsIndex: "NEW-SIGNALS-INDEX-NAME"`

The next time your rules execute, they should begin populating your new signals index, and you should now be able to view/sort/investigate those additional signal fields in your alerts tables.

---

<div class="post-metadata">

**Author:** ![ikiril01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikiril01/32/70934_2.png) [@ikiril01](https://discuss.elastic.co/u/ikiril01)\
**Post date:** [November 6, 2020, 8:14pm UTC](https://discuss.elastic.co/t/customize-detection-columns/254455/7 "2020-11-06T20:14:14Z")

</div>

@RylandHerrick awesome! I'll give that a shot. Appreciate the quick response 🙂

---

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [November 6, 2020, 8:15pm UTC](https://discuss.elastic.co/t/customize-detection-columns/254455/8 "2020-11-06T20:15:53Z")

</div>

@ikiril01 the above being said, I would reiterate the suggestion of finding an appropriate ECS field for those labels as that's a much smoother, supported experience. For the `labels.enclave` example you provided, the [`host fields`](https://www.elastic.co/guide/en/ecs/current/ecs-host.html), particularly [`host.geo.name`](https://www.elastic.co/guide/en/ecs/current/ecs-geo.html), seems appropriate. Here's [an example of configuring that on an auditbeat agent](https://www.elastic.co/guide/en/beats/auditbeat/current/add-host-metadata.html).

If you do find that there is not an ECS field to support your use case, we'd love to hear it! We absolutely want to make ECS as useful as possible.

---

<div class="post-metadata">

**Author:** ![ikiril01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikiril01/32/70934_2.png) [@ikiril01](https://discuss.elastic.co/u/ikiril01)\
**Post date:** [November 9, 2020, 10:24pm UTC](https://discuss.elastic.co/t/customize-detection-columns/254455/9 "2020-11-09T22:24:39Z")

</div>

@RylandHerrick I tried the steps you provided above, namely cloning the elastic SIEM signals index, adding the mappings, and updating the kibana.yml config file to point to this index. Right now, this doesn't seem to be working - it looks like there are no alerts that are being loaded from the new index (it remains blank and just shows "loading alerts"). Anything else I should take a look at? Oh, and we're running 7.9.3 if that helps.

Update: I was able to get it working by simply updating the mappings for the default signals index. Go figure. It does what I want now (shows the labels field for sorting), so appreciate the help once again!

---

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [November 12, 2020, 10:30pm UTC](https://discuss.elastic.co/t/customize-detection-columns/254455/10 "2020-11-12T22:30:58Z")

</div>

@ikiril01 that's great to hear! Would you mind detailing what mappings changes were necessary, in case others encounter your issue?

---

<div class="post-metadata">

**Author:** ![ikiril01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikiril01/32/70934_2.png) [@ikiril01](https://discuss.elastic.co/u/ikiril01)\
**Post date:** [November 13, 2020, 9:14pm UTC](https://discuss.elastic.co/t/customize-detection-columns/254455/11 "2020-11-13T21:14:01Z")

</div>

@RylandHerrick sure! The first thing I did to test things out was just update the SIEM signals index mapping directly:

```auto
PUT /.siem-signals-default-000001/_mapping
{
  "properties": {
    "labels": {
          "properties": {
            "foo": {
              "type": "keyword"
            }
          }
    }
  }
}

```

Once I tested that to make sure it was working, I created a new index template for the SIEM signals template (with an `order` of `1` so it doesn't conflict with the original):

```auto
PUT /_template/.siem-signals-custom
{
  "order" : 1,
  "index_patterns" : [".siem-signals-default-*"],
  "mappings" : {
    "properties": {
       "labels": {
          "properties": {
            "foo": {
              "type": "keyword"
            }
          }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2020, 9:14pm UTC](https://discuss.elastic.co/t/customize-detection-columns/254455/12 "2020-12-11T21:14:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
