Closed
Description
Description
We're introducing the entity type 'service' to the Entity Store. Previously, only 'user' and 'host' were supported.
The new 'service' entity type should be displayed on all pages where the 'user' and 'host' entities are displayed. Ex: Entity Store page, Risk Score page, Entity Dashboards.
It will allow users to investigate and protect the services installed in their environment easily.
The user only needs to enable the entity store to install the' service' entity type.
Background & resources
- PRs: [SecuritySolution] Add Service entity type to Entity Analytics kibana#204437
- Issues/metas: https://github.com/elastic/security-team/issues/11161 https://github.com/elastic/security-team/issues/10740
- Point of contact: @machadoum @jaredburgettelastic
- Test environments: https://kibana.siem.estc.dev/
Which documentation set does this change impact?
ESS only
ESS release
8.18
Serverless release
Early February, currently targeting the week of February 10th (please note that this is an estimate only)
Feature differences
Entity store is not supported on serverless
API docs impact
N/A
Prerequisites, privileges, feature flags
N/A