11.2 Elastic Security Timeline & Timeline Templates
Key Takeaways
The Elastic Security Timeline is an interactive chronological investigation canvas that aggregates multi-data-stream telemetry from endpoints, networks, cloud logs, and security alerts.
The drag-and-drop query builder turns dropped fields into filters, joining horizontally adjacent filters with AND and vertically adjacent filters with OR.
Pinned events stay on the Timeline's Pinned tab regardless of later query, time range or data view changes.
Notes can be added to individual events or to the whole Timeline (Notes tab), and Attach to case links the saved Timeline to a new or existing case.
Timeline templates use template filters with placeholders such as {host.name} that are filled from the alert when a rule with that template is investigated in Timeline.
The Investigative Role of Elastic Security Timeline
When a Tier 1 triage analyst determines that an alert represents a confirmed or suspected security incident, the operational focus shifts from validation to deep chronological reconstruction. Traditional log search interfaces—such as flat Discover tables or fragmented dashboard panels—are poorly suited for tracking complex adversary tradecraft. Multi-stage intrusions span disparate data streams: an initial phishing payload arrives in email logs, executes on an endpoint, generates authentication attempts in Active Directory audit trails, and establishes outbound network connections recorded by firewalls.
The Elastic Security Timeline serves as the central investigative canvas for incident responders and threat hunters. It allows investigators to correlate events across heterogeneous data streams, customize field visualizations on the fly, pin crucial forensic artifacts, attach investigative notes, and seamlessly transition findings into incident cases. Understanding both ad-hoc Timelines and parameterized Timeline Templates is essential for conducting rapid, structured incident analysis.
Interactive Query Canvas & Multi-Data-Stream Correlation
The Timeline interface is designed as an interactive, multi-tiered query workbench that queries across all indices mapped in the active Security Data View (including logs-endpoint.events.*, logs-network.*, logs-system.*, and .alerts-security.alerts-*).
+--------------------------------------------------------------------------+
| Timeline: [ Compromised Admin Account Investigation ] |
+--------------------------------------------------------------------------+
| KQL: user.name: "admin_corp" and not process.name: "explorer.exe" |
| Time: [ 2026-09-30 08:00:00 TO 2026-09-30 11:30:00 ] [ Auto-Refresh: Off]|
+--------------------------------------------------------------------------+
| [ Pinned Events (2) v ] |
| - 08:14:22 | srv-dc01 | mimikatz.exe | Pinned by rchen: "LSASS Dump" |
| - 08:29:05 | srv-dc01 | 198.51.100.5 | Pinned by rchen: "C2 Exfil" |
+--------------------------------------------------------------------------+
| Chronological Event Stream (@timestamp descending) |
| Timestamp | Event Dataset | Host | User | Summary Action |
|--------------|-----------------|-----------|------------|----------------|
| 08:31:10.120 | network.socket | srv-dc01 | admin_corp | Outbound 443 |
| 08:29:05.882 | network.socket | srv-dc01 | admin_corp | Outbound 8080 |
| 08:14:22.014 | endpoint.proc | srv-dc01 | admin_corp | Process Create |
| 08:02:40.900 | system.auth | srv-dc01 | admin_corp | Logon Success |
+--------------------------------------------------------------------------+
1. Query Bar and Timeline Tabs
Timeline has its own KQL query bar and time picker, and a fixed set of tabs:
- Query: KQL searching plus the drag-and-drop query builder.
- Correlation: EQL queries; events in the same matched sequence are grouped, shaded and ordered from oldest to newest.
- ES|QL: Piped ES|QL queries (hidden indices such as
.alerts-*must be typed in manually). - Analyzer and Session: The visual event analyzer and Session View for a selected event.
- Notes and Pinned: The investigation's notes and pinned events.
2. Multi-Data-Stream Chronological Alignment
Timeline normalizes event streams into a unified temporal sequence. Because all ingested data adheres to the Elastic Common Schema (ECS), events from Cisco firewalls, Windows event logs, Linux auditd streams, and Zeek network monitors interleave chronologically based on @timestamp. This provides analysts with a unified, millisecond-accurate narrative of adversary actions.
3. Drag-and-Drop Query Builder
Analysts can drag fields and values from tables, histograms, event renderers or the alert flyout, or use Add to timeline, into the query builder below the query bar. The layout defines the logic: horizontally adjacent filters are joined with AND, and vertically adjacent filters with OR. Each filter's menu can:
- Exclude results (turn it into a NOT condition, e.g. excluding
process.name: "svchost.exe"). - Temporarily disable it without deleting it.
- Convert a field-with-value filter into a field exists filter.
- Load a saved query, or clear all filters.
4. Customizing View Columns and Inline JSON Inspection
Investigators can tailor the Timeline table layout to match the nature of the threat. Clicking the Customize Columns menu allows fields such as process.command_line, file.hash.sha256, or dns.question.name to be added or removed. Rows can be expanded to reveal an inline key-value inspector and a raw JSON document view, identical to the Kibana Discover experience.
Preserving Forensic Evidence: Event Pinning and Markdown Notes
During an active incident investigation, an analyst might evaluate tens of thousands of log records to identify five critical adversary actions. If the analyst modifies the KQL search query to investigate another phase of the attack, those five records would disappear from the screen. Elastic Security solves this challenge through Event Pinning and Investigative Notes.
1. Event Pinning Mechanics
Every event row in the Timeline displays a pin icon. Clicking the pin icon "pins" that specific document to the Timeline:
- Pinned Tab: Pinned events are listed on the Timeline's Pinned tab.
- Query Independence: Pinned events remain locked in the view regardless of subsequent query changes. If the analyst clears the search bar, switches KQL queries, expands the time range by three weeks, or changes the data view, all pinned events remain on the Pinned tab.
- Chronological Reference: Pinned events serve as temporal anchors, allowing the investigator to visually evaluate newly queried events against established adversary milestones.
2. Investigative Markdown Notes
Timeline provides two distinct levels of notes for documenting forensic rationales:
- Event-Level Notes: Analysts can attach a markdown note directly to any individual event (e.g., "08:14:22 - Attacker executed modified Mimikatz binary disguised as taskhost.exe to dump LSASS memory"). An indicator badge appears on the event row, and the note content is indexed alongside the timeline saved object.
- Timeline Notes: Investigation notes on the whole Timeline, shown on the Notes tab, for incident hypotheses, summaries or shift handoff instructions.
3. Case Synchronization
When the analyst is ready to escalate or archive their investigation, clicking Attach to case (then Attach to new case or Attach to existing case) adds a link to the saved Timeline in the case. Anyone reviewing the case can open the Timeline with its queries, pinned events, notes and column layout.
Timeline Templates: Architecture and Parameterized Playbooks
While ad-hoc Timelines provide flexibility for unique investigations, repetitive operational threats require standardized investigation procedures. If five different Tier 1 analysts investigate five separate "Brute Force Authentication" alerts, they should not each independently devise search queries, select columns, and build filters from scratch. Timeline Templates solve this operational inconsistency.
+--------------------------------------------------------------------------+
| Timeline Template Definition: "Host & User Authentication Triage" |
+--------------------------------------------------------------------------+
| Parameterized Query: |
| host.name: "{host.name}" and (user.name: "{user.name}" or |
| event.category: "authentication") and not event.outcome: "unknown" |
+--------------------------------------------------------------------------+
| Configured Columns: [@timestamp, event.action, source.ip, user.name] |
+--------------------------------------------------------------------------+
|
v Alert Triggers: Rule "SSH Brute Force"
Alert Payload ECS Values:
- host.name = "srv-web01"
- user.name = "root"
|
v 1-Click Launch: "Investigate in Timeline"
+--------------------------------------------------------------------------+
| Instantiated Active Timeline: |
| KQL: host.name: "srv-web01" and (user.name: "root" or |
| event.category: "authentication") and not event.outcome: "unknown" |
+--------------------------------------------------------------------------+
1. Template Architecture and Variable Syntax
A Timeline Template is a saved investigative blueprint containing pre-selected columns, configured filter pills, and a parameterized KQL query. Templates can hold two kinds of filters. A regular filter defines both the field and its value, such as host.name : "win-server". A template filter defines only the field and uses a curly-bracket placeholder for the value, added with Add template field or Convert to template field in the query builder:
{host.name}: Replaced by the host name from the triggering alert or context.{user.name}: Replaced by the user identity associated with the alert.{process.name}: Replaced by the initiating executable.{destination.ip}/{source.ip}: Replaced by the network endpoints involved.
2. Runtime Parameter Substitution
When a Timeline Template is instantiated from an alert, Elastic Security reads the ECS fields of the triggering alert document and dynamically substitutes those values into the curly-bracket variable placeholders. For example, if a template contains:
host.name: "{host.name}" and process.name: "{process.name}"
And the alert fired on an endpoint where host.name is finance-ws09 and process.name is certutil.exe, the instantiated timeline query instantly resolves to:
host.name: "finance-ws09" and process.name: "certutil.exe"
This completely eliminates the need for analysts to manually copy and paste values between windows.
3. Binding Timeline Templates to Detection Rules
Detection engineers choose a template in the rule's Timeline template setting when they create or edit the rule, so templates must exist before the rule is built:
- When an analyst uses Investigate in timeline on an alert from that rule, Timeline opens with the template's layout and filters, and each template filter is replaced with the alert's value.
- This gives every analyst the same starting point for that threat category, such as an Active Directory triage template for credential-attack rules.
Elastic also loads prebuilt Timeline templates with its prebuilt rules, including Alerts Involving a Single Host, Alerts Involving a Single User, Generic Endpoint, Generic Network, Generic Process, Generic Threat Match, and Comprehensive File/Network/Process/Registry templates. Prebuilt templates can't be deleted or exported, but you can duplicate them as a starting point.
Comparison: Ad-Hoc Timeline vs. Timeline Templates
The following table contrasts the functional and operational characteristics of ad-hoc Timelines versus reusable Timeline Templates:
| Operational Feature | Ad-Hoc Timeline | Timeline Template |
|---|---|---|
| Primary Purpose | Open-ended threat hunting; bespoke incident root-cause analysis | Standardized, repeatable investigation playbooks for known threat classes |
| Query Structure | Static KQL, Lucene, or ES|QL queries crafted interactively | Parameterized queries containing dynamic variable tokens ({field}) |
| Variable Support | None (Values are hardcoded literal strings) | Full support for dynamic ECS field replacement at launch time |
| Rule Association | Cannot be directly pre-bound to detection rules | Directly bound to detection rules via rule management settings |
| Column Configuration | Modifiable on the fly; saved with timeline object | Pre-configured by detection engineering to match the threat playbook |
| Operational Level | Primarily Tier 2 / Tier 3 Incident Responders and Hunters | Primarily Tier 1 / Tier 2 Analysts executing standardized triage SOPs |
| Case Integration | Pinned events and notes attach directly to Cases | Instantiated instance attaches to Cases with all populated findings |
A detection engineer is designing a standardized investigation playbook for a detection rule that catches suspicious parent-child process relationships across Windows endpoints. The engineer wants Timeline to open automatically filtered to the specific endpoint and user found in the alert. How should the Timeline template's filters be authored?
host.name: * and user.name: * and event.action: 'process-created'
SELECT * FROM 'logs-endpoint.events.*' WHERE host.name == alert.host.name
host.name: "$HOST" AND user.name: "$USER" with Bash environment variable expansion enabled
As template filters host.name: "{host.name}" and user.name: "{user.name}", using the curly-bracket placeholder syntax
An incident responder conducting a complex investigation in the Elastic Security Timeline identifies three critical log entries: a malicious binary creation, an outbound C2 connection, and a persistence registry modification. The responder wants to ensure these three entries remain visible on screen while they continue testing various KQL queries and adjusting time ranges. What action must the responder take?
Export the three events to a local CSV spreadsheet and re-import them as custom runtime fields.
Write a Painless ingest script that flags the three documents with a permanent Elasticsearch tag.
Pin the three events using the pin icon on each row so they are kept on the Timeline's Pinned tab.
Duplicate the browser tab three times, keeping one event visible in each independent session.
How does the drag-and-drop filtering functionality in the Elastic Security Timeline accelerate multi-data-stream threat correlation for an investigator?
It lets an analyst drag field values from alert flyouts, tables or histograms into the Timeline query builder, where they become filters (AND side by side, OR stacked) that can be excluded or disabled without typing syntax.
It automatically moves the underlying physical Elasticsearch shards to faster NVMe storage tiers.
It recompiles the Kibana web application JavaScript bundle to run faster client-side aggregations.
It automatically executes remote PowerShell scripts to collect forensic memory dumps from endpoints.
Sections you finish are checked off in the contents.