Elastic rule Hyperlinks in Highlighted Fields

Is it possible to create a custom clickable hyperlink in the highlighted fields. The link could be constructed in several ways but generally constructed from data that is present in the alert it self.

The reason for this would be that when an alert condition is triggered from external sources users would more easily be able to pivot from Elastic Security to the provider of the data for additional context and specific capability.

This type of function is already able to be done in Kibana Dataview to construct a url and set the value as a hyperlink and should also be possible in Elastic Security. Also, this would allow for detection engineers to provide additional capability and integration with external assets.

Hi @welch27330,

Did I get you correctly that you are talking about Alert’s Highlighted Fields?

In that case you may pick only a field from the list. The fields shown as hyperlinks are predefined and handled in a different way.

Anyway it’s an interesting idea you are suggesting and worth to be considered for the implementation.