I'm leaning towards option A. Being able to quickly search for similar events on other endpoints could be really useful for understanding the scope of this issue.
Option C looks promising, as a Process Timeline would give me a better understanding of the related events. But I'm not sure if that's the specific functionality of pivoting to an Event Search.
I think option B is the correct answer. It takes you to the raw Insight event data and provides you with a number of Event Actions, which is exactly what I need to investigate this detection further.
I see both points. But I think it's important to have a Process Timeline for that detection so you can see all related events. So, I would choose option C as the best choice.
I disagree with Elena. I believe that it takes you to the raw Insight event data and provides you with a number of Event Actions. Option B seems more logical to me.
Chery
24 days agoLelia
23 hours agoViki
26 days agoYvette
3 days agoJarvis
20 days agoFatima
1 months agoKimbery
3 days agoValentin
18 days agoMoon
18 days agoDorthy
1 months agoVirgilio
2 months agoMaia
2 months agoHuey
5 days agoBrett
1 months agoCaprice
2 months agoMajor
2 months agoElena
2 months ago