Skip to content

Commit 8d9c472

Browse files
[Security Solution][Entity Analytics][Risk Scoring] Update risk information flyout text and add management link (elastic#243596)
## Summary This PR updates the Risk Information flyout to improve clarity and add a link to the entity risk scoring management screen. ### Changes: - Updated terminology from "hosts and users" to "entities" for consistency - Added a link to the entity risk scoring management screen in the risk calculation explanation - Improved the description of asset criticality behavior to reflect that it's based on assigned criticality levels rather than feature enablement ### Related Issue: [EA-12731](elastic/security-team#12731) ### Checklist: - [x] Updated text for better clarity and consistency - [x] Added link to management screen for better user guidance - [x] Verified linting passes ### Screenshot <img width="878" height="836" alt="image" src="https://github.com/user-attachments/assets/8b1f3333-f9d4-4328-ac2c-4992d57ef6b7" />
1 parent 3f9076d commit 8d9c472

5 files changed

Lines changed: 21 additions & 7 deletions

File tree

x-pack/platform/plugins/private/translations/translations/de-DE.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38116,7 +38116,7 @@
3811638116
"xpack.securitySolution.riskInformation.howOftenTitle": "Wie oft wird das Risiko berechnet?",
3811738117
"xpack.securitySolution.riskInformation.introText": "Entity Risk Analytics identifiziert riskante Hosts und Nutzer in Ihrer Umgebung.",
3811838118
"xpack.securitySolution.riskInformation.levelHeader": "Risikostufe",
38119-
"xpack.securitySolution.riskInformation.riskCalculationStep1": "Bewertet nur Nutzer und Hosts (Entitäten), die mit Erkennungs-Alerts verknüpft sind, die nicht geschlossen wurden.",
38119+
"xpack.securitySolution.riskInformation.riskCalculationStep1": "Bewertet nur Entitäten, die mit Erkennungs-Alerts verknüpft sind, die nicht geschlossen wurden. Dieses Verhalten kann in {managementLink} konfiguriert werden.",
3812038120
"xpack.securitySolution.riskInformation.riskCalculationStep2": "Erzeugt einen 'Alert'-Kategorie-Score, indem Alerts nach Entitäts-Identifikator aggregiert werden, sodass Alerts mit höheren Risikowerten mehr beitragen als solche mit niedrigeren Risikowerten.",
3812138121
"xpack.securitySolution.riskInformation.riskCalculationStep3": "Wenn die Feature „Asset-Kritikalität“ in Ihrem Bereich aktiviert ist, überprüft die Risikobewertung für Entitäten die Klassifizierungsstufe der Asset-Kritikalität der Entität und generiert einen Score-Modifikator in der Kategorie „Asset-Kritikalität“.",
3812238122
"xpack.securitySolution.riskInformation.riskCalculationStep4": "Erzeugt das Entitätsrisiko als normalisierte numerische Risiko-Score.",

x-pack/platform/plugins/private/translations/translations/fr-FR.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38481,7 +38481,7 @@
3848138481
"xpack.securitySolution.riskInformation.howOftenTitle": "À quelle fréquence le risque est-il calculé ?",
3848238482
"xpack.securitySolution.riskInformation.introText": "L'analyse de risque des entités détecte les hôtes et les utilisateurs risqués à l'intérieur de votre environnement.",
3848338483
"xpack.securitySolution.riskInformation.levelHeader": "Niveau de risque",
38484-
"xpack.securitySolution.riskInformation.riskCalculationStep1": "Uniquement les utilisateurs et les hôtes (entités) de scores associés aux alertes de détection non fermées.",
38484+
"xpack.securitySolution.riskInformation.riskCalculationStep1": "Seules les entités associées aux alertes de détection non fermées sont notées. Ce comportement peut être configuré dans {managementLink}.",
3848538485
"xpack.securitySolution.riskInformation.riskCalculationStep2": "Génère un score de catégorie \"Alerte\" en regroupant les alertes par identificateur d'entité, afin que les alertes ayant des scores de risque plus élevés contribuent davantage que les alertes dont les scores de risque sont moins élevés.",
3848638486
"xpack.securitySolution.riskInformation.riskCalculationStep3": "Si la fonctionnalité \"Criticité des ressources\" est activée dans votre espace, le score de risque des entités vérifie le niveau de classification de la criticité de l'entité et génère un modificateur de score dans la catégorie \"Criticité des ressources\".",
3848738487
"xpack.securitySolution.riskInformation.riskCalculationStep4": "Génère le niveau de risque des entités en tant que score numérique normalisé.",

x-pack/platform/plugins/private/translations/translations/ja-JP.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38522,7 +38522,7 @@
3852238522
"xpack.securitySolution.riskInformation.howOftenTitle": "リスクを計算する頻度",
3852338523
"xpack.securitySolution.riskInformation.introText": "Entity Risk Analyticsは、環境内のリスクのあるホストとユーザーを明らかにします。",
3852438524
"xpack.securitySolution.riskInformation.levelHeader": "リスクレベル",
38525-
"xpack.securitySolution.riskInformation.riskCalculationStep1": "クローズされていない検出アラートに関連付けられたユーザーとホスト(エンティティ)のみスコア付けします。",
38525+
"xpack.securitySolution.riskInformation.riskCalculationStep1": "クローズされていない検出アラートに関連付けられたエンティティのみスコア付けします。この動作は {managementLink} で設定できます。",
3852638526
"xpack.securitySolution.riskInformation.riskCalculationStep2": "エンティティID別にアラートを集約することで、「アラート」カテゴリスコアを生成します。リスクスコアが高いアラートがリスクスコアが低いアラートよりも大きく寄与するように設定されます。",
3852738527
"xpack.securitySolution.riskInformation.riskCalculationStep3": "スペースで「アセット重要度」機能が有効な場合は、エンティティリスクスコアによって、エンティティのアセット重要度分類ティアが検証され、「アセット重要度」カテゴリの下でスコア修飾子が生成されます。",
3852838528
"xpack.securitySolution.riskInformation.riskCalculationStep4": "正規化された数値スコアとしてエンティティリスクを生成します。",

x-pack/platform/plugins/private/translations/translations/zh-CN.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38502,7 +38502,7 @@
3850238502
"xpack.securitySolution.riskInformation.howOftenTitle": "多久计算一次风险?",
3850338503
"xpack.securitySolution.riskInformation.introText": "实体风险分析将显示您的环境中存在的有风险主机和用户。",
3850438504
"xpack.securitySolution.riskInformation.levelHeader": "风险级别",
38505-
"xpack.securitySolution.riskInformation.riskCalculationStep1": "仅对与尚未关闭的检测告警关联的用户和主机(实体)评分。",
38505+
"xpack.securitySolution.riskInformation.riskCalculationStep1": "仅对与尚未关闭的检测告警关联的实体评分。可在 {managementLink} 中配置此行为。",
3850638506
"xpack.securitySolution.riskInformation.riskCalculationStep2": "通过按实体标识符聚合告警来生成“告警”类别分数,从而使风险分数高的告警贡献高于风险分数低的告警。",
3850738507
"xpack.securitySolution.riskInformation.riskCalculationStep3": "如果在工作区中启用了“资产关键度”功能,实体风险评分会验证实体的资产关键度分类层,并在“资产关键度”类别下生成分数修饰符。",
3850838508
"xpack.securitySolution.riskInformation.riskCalculationStep4": "以标准化数字分数的形式生成实体风险。",

x-pack/solutions/security/plugins/security_solution/public/entity_analytics/components/risk_information/index.tsx

Lines changed: 17 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,8 @@ import {
3636
} from '../../../../common/entity_analytics/asset_criticality';
3737
import { AssetCriticalityBadge } from '../asset_criticality';
3838
import { EntityAnalyticsLearnMoreLink } from '../entity_analytics_learn_more_link';
39+
import { SecuritySolutionLinkAnchor } from '../../../common/components/links';
40+
import { SecurityPageName } from '../../../../common/constants';
3941

4042
const SpacedOrderedList = styled.ol`
4143
li {
@@ -141,7 +143,7 @@ export const RiskInformationFlyout = ({ handleOnClose }: { handleOnClose: () =>
141143
<p>
142144
<FormattedMessage
143145
id="xpack.securitySolution.riskInformation.introText"
144-
defaultMessage="Entity Risk Analytics surfaces risky hosts and users from within your environment."
146+
defaultMessage="Entity Risk Analytics surfaces risky entities within your environment."
145147
/>
146148
</p>
147149
<p>
@@ -203,7 +205,19 @@ export const RiskInformationFlyout = ({ handleOnClose }: { handleOnClose: () =>
203205
<li>
204206
<FormattedMessage
205207
id="xpack.securitySolution.riskInformation.riskCalculationStep1"
206-
defaultMessage="Only scores users and hosts (entities) associated with detection alerts that have not been closed."
208+
defaultMessage="Only scores entities associated with detection alerts that have not been closed. This behavior is configurable in the {managementLink}."
209+
values={{
210+
managementLink: (
211+
<SecuritySolutionLinkAnchor
212+
deepLinkId={SecurityPageName.entityAnalyticsManagement}
213+
>
214+
<FormattedMessage
215+
id="xpack.securitySolution.riskInformation.managementScreenLink"
216+
defaultMessage="entity risk scoring management screen"
217+
/>
218+
</SecuritySolutionLinkAnchor>
219+
),
220+
}}
207221
/>
208222
</li>
209223
<li>
@@ -215,7 +229,7 @@ export const RiskInformationFlyout = ({ handleOnClose }: { handleOnClose: () =>
215229
<li>
216230
<FormattedMessage
217231
id="xpack.securitySolution.riskInformation.riskCalculationStep3"
218-
defaultMessage="If the 'Asset Criticality' feature is enabled in your space, entity risk scoring verifies the asset criticality classification tier of the entity and generates a score modifier under the 'Asset Criticality' category."
232+
defaultMessage="If an asset criticality level has been assigned to the entity, entity risk scoring retrieves the criticality level and applies a score modifier under the 'Asset Criticality' category."
219233
/>
220234
<EuiSpacer size="s" />
221235
<EuiBasicTable

0 commit comments

Comments
 (0)