Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Threat Hunting Dashboard is now harder to threat hunt #485

Open
madhatta-ct opened this issue Jan 14, 2025 · 0 comments
Open

Threat Hunting Dashboard is now harder to threat hunt #485

madhatta-ct opened this issue Jan 14, 2025 · 0 comments

Comments

@madhatta-ct
Copy link

Is your feature request related to a problem? Please describe.

I run Wazuh in production with about 5000 endpoints spread across a few estates. Since removing the field selector on the left hand side of the Events tab we have found it increasingly harder to threat hunt.
The auto-population of the Top 5 in the results was how we'd filter out the noise and find co-relation, we now have to try and simulate that experience using the Discover applet, but isn't the point of Threat Hunting to discover? We have found ways to get more or less the same functionality, but at significantly more clicks

Describe the solution you'd like

When you make changes that could impact the way users interact with the product, I'd like to see an option to switch back to the the previous iteration, similar to how Outlook has a toggle to switch to "Classic" view. I understand that would potentially mean maintaining legacy code and new, but sometimes newer isn't better. We had processes we followed to threat hunt and removing functionality without replacing it without something similar or better or the ability to retain the old should be considered please :). Unless.. I am just being blind and this exists already

Additional context

v4.8.1

Image

v4.9.2

Image

Thanks for reading :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant