11.2 Elastic Security Timeline & Timeline Templates

Key Takeaways

  • The Elastic Security Timeline is an interactive chronological investigation canvas that aggregates multi-data-stream telemetry from endpoints, networks, cloud logs, and security alerts.

  • The drag-and-drop query builder turns dropped fields into filters, joining horizontally adjacent filters with AND and vertically adjacent filters with OR.

  • Pinned events stay on the Timeline's Pinned tab regardless of later query, time range or data view changes.

  • Notes can be added to individual events or to the whole Timeline (Notes tab), and Attach to case links the saved Timeline to a new or existing case.

  • Timeline templates use template filters with placeholders such as {host.name} that are filled from the alert when a rule with that template is investigated in Timeline.

Last updated: September 2026

The Investigative Role of Elastic Security Timeline

When a Tier 1 triage analyst determines that an alert represents a confirmed or suspected security incident, the operational focus shifts from validation to deep chronological reconstruction. Traditional log search interfaces—such as flat Discover tables or fragmented dashboard panels—are poorly suited for tracking complex adversary tradecraft. Multi-stage intrusions span disparate data streams: an initial phishing payload arrives in email logs, executes on an endpoint, generates authentication attempts in Active Directory audit trails, and establishes outbound network connections recorded by firewalls.

The Elastic Security Timeline serves as the central investigative canvas for incident responders and threat hunters. It allows investigators to correlate events across heterogeneous data streams, customize field visualizations on the fly, pin crucial forensic artifacts, attach investigative notes, and seamlessly transition findings into incident cases. Understanding both ad-hoc Timelines and parameterized Timeline Templates is essential for conducting rapid, structured incident analysis.


Interactive Query Canvas & Multi-Data-Stream Correlation

The Timeline interface is designed as an interactive, multi-tiered query workbench that queries across all indices mapped in the active Security Data View (including logs-endpoint.events.*, logs-network.*, logs-system.*, and .alerts-security.alerts-*).

+--------------------------------------------------------------------------+
| Timeline: [ Compromised Admin Account Investigation ]                   |
+--------------------------------------------------------------------------+
| KQL: user.name: "admin_corp" and not process.name: "explorer.exe"        |
| Time: [ 2026-09-30 08:00:00 TO 2026-09-30 11:30:00 ] [ Auto-Refresh: Off]|
+--------------------------------------------------------------------------+
| [ Pinned Events (2) v ]                                                  |
|  - 08:14:22 | srv-dc01 | mimikatz.exe | Pinned by rchen: "LSASS Dump"    |
|  - 08:29:05 | srv-dc01 | 198.51.100.5 | Pinned by rchen: "C2 Exfil"      |
+--------------------------------------------------------------------------+
| Chronological Event Stream (@timestamp descending)                     |
| Timestamp    | Event Dataset   | Host      | User       | Summary Action |
|--------------|-----------------|-----------|------------|----------------|
| 08:31:10.120 | network.socket  | srv-dc01  | admin_corp | Outbound 443   |
| 08:29:05.882 | network.socket  | srv-dc01  | admin_corp | Outbound 8080  |
| 08:14:22.014 | endpoint.proc   | srv-dc01  | admin_corp | Process Create |
| 08:02:40.900 | system.auth     | srv-dc01  | admin_corp | Logon Success  |
+--------------------------------------------------------------------------+

1. Query Bar and Timeline Tabs

Timeline has its own KQL query bar and time picker, and a fixed set of tabs:

  • Query: KQL searching plus the drag-and-drop query builder.
  • Correlation: EQL queries; events in the same matched sequence are grouped, shaded and ordered from oldest to newest.
  • ES|QL: Piped ES|QL queries (hidden indices such as .alerts-* must be typed in manually).
  • Analyzer and Session: The visual event analyzer and Session View for a selected event.
  • Notes and Pinned: The investigation's notes and pinned events.

2. Multi-Data-Stream Chronological Alignment

Timeline normalizes event streams into a unified temporal sequence. Because all ingested data adheres to the Elastic Common Schema (ECS), events from Cisco firewalls, Windows event logs, Linux auditd streams, and Zeek network monitors interleave chronologically based on @timestamp. This provides analysts with a unified, millisecond-accurate narrative of adversary actions.

3. Drag-and-Drop Query Builder

Analysts can drag fields and values from tables, histograms, event renderers or the alert flyout, or use Add to timeline, into the query builder below the query bar. The layout defines the logic: horizontally adjacent filters are joined with AND, and vertically adjacent filters with OR. Each filter's menu can:

  • Exclude results (turn it into a NOT condition, e.g. excluding process.name: "svchost.exe").
  • Temporarily disable it without deleting it.
  • Convert a field-with-value filter into a field exists filter.
  • Load a saved query, or clear all filters.

4. Customizing View Columns and Inline JSON Inspection

Investigators can tailor the Timeline table layout to match the nature of the threat. Clicking the Customize Columns menu allows fields such as process.command_line, file.hash.sha256, or dns.question.name to be added or removed. Rows can be expanded to reveal an inline key-value inspector and a raw JSON document view, identical to the Kibana Discover experience.


Preserving Forensic Evidence: Event Pinning and Markdown Notes

During an active incident investigation, an analyst might evaluate tens of thousands of log records to identify five critical adversary actions. If the analyst modifies the KQL search query to investigate another phase of the attack, those five records would disappear from the screen. Elastic Security solves this challenge through Event Pinning and Investigative Notes.

1. Event Pinning Mechanics

Every event row in the Timeline displays a pin icon. Clicking the pin icon "pins" that specific document to the Timeline:

  • Pinned Tab: Pinned events are listed on the Timeline's Pinned tab.
  • Query Independence: Pinned events remain locked in the view regardless of subsequent query changes. If the analyst clears the search bar, switches KQL queries, expands the time range by three weeks, or changes the data view, all pinned events remain on the Pinned tab.
  • Chronological Reference: Pinned events serve as temporal anchors, allowing the investigator to visually evaluate newly queried events against established adversary milestones.

2. Investigative Markdown Notes

Timeline provides two distinct levels of notes for documenting forensic rationales:

  • Event-Level Notes: Analysts can attach a markdown note directly to any individual event (e.g., "08:14:22 - Attacker executed modified Mimikatz binary disguised as taskhost.exe to dump LSASS memory"). An indicator badge appears on the event row, and the note content is indexed alongside the timeline saved object.
  • Timeline Notes: Investigation notes on the whole Timeline, shown on the Notes tab, for incident hypotheses, summaries or shift handoff instructions.

3. Case Synchronization

When the analyst is ready to escalate or archive their investigation, clicking Attach to case (then Attach to new case or Attach to existing case) adds a link to the saved Timeline in the case. Anyone reviewing the case can open the Timeline with its queries, pinned events, notes and column layout.


Timeline Templates: Architecture and Parameterized Playbooks

While ad-hoc Timelines provide flexibility for unique investigations, repetitive operational threats require standardized investigation procedures. If five different Tier 1 analysts investigate five separate "Brute Force Authentication" alerts, they should not each independently devise search queries, select columns, and build filters from scratch. Timeline Templates solve this operational inconsistency.

+--------------------------------------------------------------------------+
| Timeline Template Definition: "Host & User Authentication Triage"        |
+--------------------------------------------------------------------------+
| Parameterized Query:                                                     |
|  host.name: "{host.name}" and (user.name: "{user.name}" or               |
|  event.category: "authentication") and not event.outcome: "unknown"      |
+--------------------------------------------------------------------------+
| Configured Columns: [@timestamp, event.action, source.ip, user.name]     |
+--------------------------------------------------------------------------+
                                    |
                                    v Alert Triggers: Rule "SSH Brute Force"
                         Alert Payload ECS Values:
                         - host.name = "srv-web01"
                         - user.name = "root"
                                    |
                                    v 1-Click Launch: "Investigate in Timeline"
+--------------------------------------------------------------------------+
| Instantiated Active Timeline:                                            |
| KQL: host.name: "srv-web01" and (user.name: "root" or                   |
|      event.category: "authentication") and not event.outcome: "unknown"  |
+--------------------------------------------------------------------------+

1. Template Architecture and Variable Syntax

A Timeline Template is a saved investigative blueprint containing pre-selected columns, configured filter pills, and a parameterized KQL query. Templates can hold two kinds of filters. A regular filter defines both the field and its value, such as host.name : "win-server". A template filter defines only the field and uses a curly-bracket placeholder for the value, added with Add template field or Convert to template field in the query builder:

  • {host.name}: Replaced by the host name from the triggering alert or context.
  • {user.name}: Replaced by the user identity associated with the alert.
  • {process.name}: Replaced by the initiating executable.
  • {destination.ip} / {source.ip}: Replaced by the network endpoints involved.

2. Runtime Parameter Substitution

When a Timeline Template is instantiated from an alert, Elastic Security reads the ECS fields of the triggering alert document and dynamically substitutes those values into the curly-bracket variable placeholders. For example, if a template contains:

host.name: "{host.name}" and process.name: "{process.name}"

And the alert fired on an endpoint where host.name is finance-ws09 and process.name is certutil.exe, the instantiated timeline query instantly resolves to:

host.name: "finance-ws09" and process.name: "certutil.exe"

This completely eliminates the need for analysts to manually copy and paste values between windows.

3. Binding Timeline Templates to Detection Rules

Detection engineers choose a template in the rule's Timeline template setting when they create or edit the rule, so templates must exist before the rule is built:

  • When an analyst uses Investigate in timeline on an alert from that rule, Timeline opens with the template's layout and filters, and each template filter is replaced with the alert's value.
  • This gives every analyst the same starting point for that threat category, such as an Active Directory triage template for credential-attack rules.

Elastic also loads prebuilt Timeline templates with its prebuilt rules, including Alerts Involving a Single Host, Alerts Involving a Single User, Generic Endpoint, Generic Network, Generic Process, Generic Threat Match, and Comprehensive File/Network/Process/Registry templates. Prebuilt templates can't be deleted or exported, but you can duplicate them as a starting point.


Comparison: Ad-Hoc Timeline vs. Timeline Templates

The following table contrasts the functional and operational characteristics of ad-hoc Timelines versus reusable Timeline Templates:

Operational FeatureAd-Hoc TimelineTimeline Template
Primary PurposeOpen-ended threat hunting; bespoke incident root-cause analysisStandardized, repeatable investigation playbooks for known threat classes
Query StructureStatic KQL, Lucene, or ES|QL queries crafted interactivelyParameterized queries containing dynamic variable tokens ({field})
Variable SupportNone (Values are hardcoded literal strings)Full support for dynamic ECS field replacement at launch time
Rule AssociationCannot be directly pre-bound to detection rulesDirectly bound to detection rules via rule management settings
Column ConfigurationModifiable on the fly; saved with timeline objectPre-configured by detection engineering to match the threat playbook
Operational LevelPrimarily Tier 2 / Tier 3 Incident Responders and HuntersPrimarily Tier 1 / Tier 2 Analysts executing standardized triage SOPs
Case IntegrationPinned events and notes attach directly to CasesInstantiated instance attaches to Cases with all populated findings
Loading diagram...
Timeline Template Dynamic Variable Substitution and Detection Rule Integration
Test Your Knowledge

A detection engineer is designing a standardized investigation playbook for a detection rule that catches suspicious parent-child process relationships across Windows endpoints. The engineer wants Timeline to open automatically filtered to the specific endpoint and user found in the alert. How should the Timeline template's filters be authored?

A

host.name: * and user.name: * and event.action: 'process-created'

B

SELECT * FROM 'logs-endpoint.events.*' WHERE host.name == alert.host.name

C

host.name: "$HOST" AND user.name: "$USER" with Bash environment variable expansion enabled

D

As template filters host.name: "{host.name}" and user.name: "{user.name}", using the curly-bracket placeholder syntax

Test Your Knowledge

An incident responder conducting a complex investigation in the Elastic Security Timeline identifies three critical log entries: a malicious binary creation, an outbound C2 connection, and a persistence registry modification. The responder wants to ensure these three entries remain visible on screen while they continue testing various KQL queries and adjusting time ranges. What action must the responder take?

A

Export the three events to a local CSV spreadsheet and re-import them as custom runtime fields.

B

Write a Painless ingest script that flags the three documents with a permanent Elasticsearch tag.

C

Pin the three events using the pin icon on each row so they are kept on the Timeline's Pinned tab.

D

Duplicate the browser tab three times, keeping one event visible in each independent session.

Test Your Knowledge

How does the drag-and-drop filtering functionality in the Elastic Security Timeline accelerate multi-data-stream threat correlation for an investigator?

A

It lets an analyst drag field values from alert flyouts, tables or histograms into the Timeline query builder, where they become filters (AND side by side, OR stacked) that can be excluded or disabled without typing syntax.

B

It automatically moves the underlying physical Elasticsearch shards to faster NVMe storage tiers.

C

It recompiles the Kibana web application JavaScript bundle to run faster client-side aggregations.

D

It automatically executes remote PowerShell scripts to collect forensic memory dumps from endpoints.

Sections you finish are checked off in the contents.