6.3 Operationalizing Lens in SOC Triage & Drilldowns
Key Takeaways
Kibana Lens bridges exploratory hunting and standardized SOC monitoring through quick pivots: Visualize from the Discover field list and Open in Lens from Security app charts, with Show top N in the alert flyout for a fast look.
Saving Lens visualizations by reference in the Visualize Library enables centralized updates across enterprise dashboards, while embedding by value provides isolated operational scratchpads.
Dashboard drilldowns transform static Lens charts into interactive investigation launchpads, navigating to other dashboards, Kibana pages or external ticketing and threat intelligence platforms.
Interactive cross-filtering and temporal brushing allow analysts to isolate attack phases by clicking anomalous chart dimensions, instantly propagating filters across all dashboard panels.
Structured hypothesis testing in Lens validates adversary tactics (such as password spraying or lateral SMB staging) by comparing observed distributions against historical entity baselines.
Visualizations in a Security Operations Center must be more than static reporting artifacts; they must function as active investigative instruments. In high-pressure triage scenarios, every second spent re-keying filters, opening disconnected browser tabs, or manually reconstructing baseline timelines increases Mean Time to Respond (MTTR). Operationalizing Kibana Lens involves embedding dynamic visual analytics directly into frontline SOC workflows—from instantaneous field pivots in Alert Flyouts to automated drilldowns into Elastic Security Timelines.
Mastering how to transition seamlessly between microscopic event investigation and macroscopic visual correlation allows analysts to rapidly test threat hypotheses, isolate lateral movement, and produce forensic audit records for incident response cases.
Rapid Ad-Hoc Lens Generation from Discover and Alert Flyouts
Frontline SOC analysts typically begin an investigation inside Elastic Security Alerts or Kibana Discover. When an anomalous indicator appears (such as an unknown parent process or an unfamiliar external IP address), the analyst needs an immediate historical baseline: Has this binary ever executed before on this host? How many other endpoints are communicating with this external IP?
Traditionally, answering these questions required navigating away to Visualize, creating a new chart, selecting the index pattern, applying filters, and selecting aggregations. That process slows an investigation down. Kibana and the Security app provide faster pivots.
+---------------------------------------------------------------------------------------------------+
| FAST PIVOTS INTO LENS AND TOP-VALUE CHARTS |
+---------------------------------------------------------------------------------------------------+
| 1. ALERT DETAILS FLYOUT (Security app) |
| Hover over a value such as process.name: powershell.exe |
| Inline actions: Filter In | Filter Out | Add to timeline | Show top N | Copy to clipboard |
| -> Show top N opens a quick top-values chart for that field in context |
+---------------------------------------------------------------------------------------------------+
| 2. SECURITY APP CHARTS (Alerts page trend, Hosts/Users KPI charts, Overview histograms) |
| Options menu (...) -> Inspect | Add to new or existing case | Open in Lens |
| -> Open in Lens keeps the chart's data view, query and time range for further editing |
+---------------------------------------------------------------------------------------------------+
| 3. DISCOVER FIELD LIST |
| Select a field -> Visualize -> Lens opens with the field, data view, query and time range |
+---------------------------------------------------------------------------------------------------+
The Discover Field List "Visualize" Shortcut
In Kibana Discover, each field in the left-hand field list has a details popover. When an analyst selects a field (such as process.executable or user.name) and clicks Visualize, Kibana opens Lens:
- The active Data View is automatically bound to the canvas.
- The selected field is automatically placed into a suitable dimension.
- The time range and the query and filters from Discover carry over.
Pivoting from the Security App
The alert details flyout does not open Lens directly. Instead, hovering over a field value in the flyout (or the Alerts table) shows inline actions: Filter In, Filter Out, Add to timeline, Show top N and Copy to clipboard. Show top N gives an immediate top-values chart for that field, which is often enough to tell whether a value is rare or routine.
For a full Lens session, use the charts built into the Security app. The Alerts page trend and count charts, the Hosts and Users KPI charts and the Overview histograms all have an options menu with Inspect, Add to new or existing case and Open in Lens. Open in Lens keeps the chart's data view, query and time range, so the analyst can expand the time window to 30 or 90 days and check whether the alerted behavior is an unprecedented spike or routine administrative activity.
Saving Visualizations: By-Reference vs. By-Value Architecture
Once an analyst creates or refines a Lens visualization, it can be persisted within Kibana. Understanding the architectural distinction between By Reference and By Value is critical for SOC dashboard management and configuration hygiene.
+---------------------------------------------------------------------------------------------------+
| SAVING LENS OBJECTS: BY-REFERENCE VS. BY-VALUE ARCHITECTURE |
+---------------------------------------------------------------------------------------------------+
| BY REFERENCE (Visualize Library): |
| +-----------------------+ References +-----------------------+ |
| | Visualize Library | ------------------------> | SOC Triage Dashboard | |
| | Saved Object: | References +-----------------------+ |
| | [lens-auth-matrix] | ------------------------> | Exec Threat Dashboard | |
| +-----------------------+ +-----------------------+ |
| [Central maintenance: Updating the formula once propagates universally across all 10 dashboards] |
+---------------------------------------------------------------------------------------------------+
| BY VALUE (Dashboard-Embedded Panels): |
| +-----------------------------------------------------------------------------------------------+ |
| | SOC Triage Dashboard (Saved Object) | |
| | - Panel 1: [Embedded Lens Spec: Standalone JSON payload] | |
| | - Panel 2: [Embedded Lens Spec: Standalone JSON payload] | |
| +-----------------------------------------------------------------------------------------------+ |
| [Isolated editing: Modifying Panel 1 does not affect any other dashboard or library object] |
+---------------------------------------------------------------------------------------------------+
1. Saving to the Visualize Library (By Reference)
- When a Lens visualization is saved to the Visualize Library, Kibana creates an independent saved object of type
lens. - Dashboards link to this saved object by referencing its unique identifier (
id). - Operational Advantage: Universal propagation. If the detection engineering team updates a formula (e.g., refining the authentication failure ratio calculation), saving the library object instantly updates every dashboard across the entire enterprise that displays that panel.
- Recommended Use Case: Standardized SOC monitors, operational metrics, executive compliance dashboards, and tier-1 overview displays.
2. Embedding Directly into Dashboards (By Value)
- When building or editing a dashboard, analysts can create a Lens panel directly within the dashboard editor without saving it to the library.
- The complete Lens specification (dimensions, metrics, styles) is serialized directly inside the dashboard's saved object definition.
- Operational Advantage: Isolation and hygiene. Prevents the Visualize Library from becoming cluttered with hundreds of temporary, one-off investigative charts created during specific incident triage sessions.
- Recommended Use Case: Temporary incident response war rooms, ad-hoc threat hunt dashboards, and analyst personal scratchpads.
Dashboard Drilldown Engineering
Static visualizations display metrics; operationalized visualizations drive actions. In Kibana Lens, Dashboard Drilldowns transform visual components into interactive launching pads that route analysts directly to relevant investigation tools with pre-populated contextual filters.
Drilldown Types in Elastic Security Workflows
- Dashboard-to-Dashboard Drilldowns:
- Enables hierarchical navigation from high-level operational overviews to specialized deep-dive dashboards.
- Example: Clicking an anomalous host bar on a global "SOC Perimeter Threat Matrix" dashboard automatically navigates the analyst to the "Host Endpoint Forensics" dashboard, carrying forward the selected
host.nameand the exact time window of the anomaly.
- URL Drilldowns to Kibana and Security App Pages:
- A URL drilldown can open another Kibana page, such as a Security app page (for example
/app/security/timelines) or Discover. - Kibana's internal URL state format differs between apps, so the practical method is to copy a working app URL and substitute drilldown variables into it. When both source and target are dashboards, use a dashboard drilldown instead, which carries filters and time range automatically.
- A URL drilldown can open another Kibana page, such as a Security app page (for example
- External URL Drilldowns (SOAR & Threat Intelligence):
- Lens panels can link directly to external enterprise systems, such as SIEM ticketing platforms (Jira, ServiceNow), network PCAP repositories, or threat intelligence databases (VirusTotal, AbuseIPDB, GreyNoise).
Parameter Substitution and Template Syntax
URL drilldowns use mustache-style variables to inject values from the clicked chart element and the panel context:
https://www.virustotal.com/gui/ip-address/{{event.value}}
When an analyst clicks a bar representing an IP address, Kibana substitutes {{event.value}} into the URL. Other commonly used variables include:
{{event.key}}and{{event.value}}: the clicked field and value.{{context.panel.query.query}}: the panel's current query.{{context.panel.timeRange.from}}and{{context.panel.timeRange.to}}: the panel's time range, useful for opening a target page on the same window.
URL drilldowns also support helpers such as {{encodeURIComponent event.value}} so values with special characters stay valid inside a URL.
Context-Sensitive Filtering and Interactive Brushing
During active triage, analysts must iteratively refine the operational scope without typing repetitive KQL statements. Lens provides seamless Cross-Filtering and Interactive Brushing:
- Click-to-Filter: Clicking on any visual element (a slice of a donut chart, a bar segment, or a data table cell) presents an immediate context menu with two primary actions:
- Filter for value (
+): Adds an explicit positive KQL filter to the global dashboard (e.g.,process.name: "powershell.exe"). - Filter out value (
-): Adds an explicit negative KQL filter (e.g.,not process.name: "powershell.exe") to suppress benign background noise.
- Filter for value (
- Temporal Brushing (Time Scrubbing):
- On any time-series Lens chart (XY bar, line, area), an analyst can click and drag across an anomalous peak.
- Kibana instantly updates the global dashboard time picker to match the highlighted window, automatically re-querying all adjacent panels (network logs, process trees, alert lists) to synchronize with that exact incident interval.
- Filter Pinning & Kibana Spaces:
- Applied filters can be pinned to persist across Kibana navigation. An analyst can filter for an infected hostname in Lens, pin the filter, and navigate to Discover, Timelines, or Elastic Maps while maintaining strict investigative focus.
Structured Hypothesis Testing in Active Incident Triage
When investigating sophisticated cyber attacks, seasoned SOC analysts employ the scientific method: formulating threat hypotheses, testing them against telemetry, and validating or refuting conclusions.
+---------------------------------------------------------------------------------------------------+
| HYPOTHESIS-DRIVEN TRIAGE METHODOLOGY WITH LENS |
+---------------------------------------------------------------------------------------------------+
| 1. INITIAL ALERT TRIAGE |
| Alert: Anomaly detected on domain controller dc-corp01 (Event ID 5140: Network Share Access) |
+---------------------------------------------------------------------------------------------------+
|
v
+---------------------------------------------------------------------------------------------------+
| 2. FORMULATE THREAT HYPOTHESIS |
| "An adversary has compromised account svc-deploy and is performing lateral movement by |
| enumerating administrative C$ and IPC$ shares across multiple internal workstations." |
+---------------------------------------------------------------------------------------------------+
|
v
+---------------------------------------------------------------------------------------------------+
| 3. CONSTRUCT AD-HOC LENS TEST PANEL |
| - Data View: logs-system.* |
| - KQL Filter: winlog.event_id: 5140 and user.name: "svc-deploy" |
| - X-Axis: @timestamp |
| - Y-Axis: unique_count(destination.ip) |
| - Breakdown: winlog.event_data.ShareName (Top 5 terms) |
+---------------------------------------------------------------------------------------------------+
|
v
+---------------------------------------------------------------------------------------------------+
| 4. BASELINE EVALUATION & OUTCOME |
| - Historical Baseline (Last 30 Days): svc-deploy contacts exactly 1 backup target at 02:00. |
| - Current Observation: svc-deploy contacted 85 distinct hosts via C$ share within 10 minutes. |
| => HYPOTHESIS VALIDATED: Active Lateral Movement Campaign in Progress! |
+---------------------------------------------------------------------------------------------------+
|
v
+---------------------------------------------------------------------------------------------------+
| 5. OPERATIONAL RESPONSE: Escalate to Elastic Security Case & Attach Lens Visual Evidence |
+---------------------------------------------------------------------------------------------------+
Hypothesis Validation Steps in Lens
- Define the Test Metric: Identify the ECS fields that prove or disprove the threat. For lateral movement, the key metric is
unique_count(destination.ip)grouped byuser.name. - Isolate the Subject Entity: Apply targeted KQL filters to focus on the suspicious actor or host.
- Expand the Historical Horizon: Temporarily expand the time picker from the incident window (e.g., Last 1 hour) to Last 30 days or Last 90 days. If the behavior occurs routinely every Tuesday, it is likely a scheduled vulnerability scan or management script. If the behavior is unprecedented in 90 days, the hypothesis is strongly validated.
- Document and Attach: Export the resulting Lens panel or save it directly into an Elastic Security Case as visual corroboration for incident handlers and forensic responders.
Lens Drilldown & Interaction Configuration Reference
The following table summarizes the interaction capabilities, configuration mechanisms, and practical SOC use cases available in Kibana Lens:
| Interaction Mechanism | Configuration Path | Target Destination | Parameter Syntax | SecOps Operational Utility |
|---|---|---|---|---|
| URL Drilldown (Threat Intel) | Panel Settings > Drilldowns > Create Drilldown > URL | External Repositories (VirusTotal, AbuseIPDB) | https://site.com/ip/{{event.value}} | 1-click external reputation validation for suspicious IP addresses and file hashes. |
| URL Drilldown (Kibana page) | Panel Settings > Drilldowns > Create Drilldown > URL | Security app page or Discover | {{event.value}}, {{context.panel.timeRange.from}} inserted into a copied app URL | Moves from an anomaly peak to a pre-scoped investigation page. |
| Dashboard Drilldown | Panel Settings > Drilldowns > Create Drilldown > Dashboard | Specialized Host or User Dashboard | Automatic Context Mapping | Navigates from global SOC perimeter monitoring to targeted endpoint investigation. |
| Contextual Cross-Filter | Direct Click on Chart Element > '+' or '-' | Global Dashboard Filter Bar | Automatic KQL generation | Instantly isolates specific attackers, malicious processes, or target ports. |
| Temporal Brushing | Click-and-Drag across Chart Time Series | Global Dashboard Time Picker | Absolute ISO 8601 Window | Restricts all dashboard panels to the exact micro-burst duration of an intrusion. |
| Discover Pivot | Discover Field Sidebar > Hover Field > 'Visualize' | Ad-Hoc Lens Workspace | Inherits active query and time | Instant visual baselining of unfamiliar ECS fields encountered during hunting. |
| Security Chart Pivot | Security app chart > Options menu (…) > Open in Lens | Lens editor | Keeps the chart's data view, query and time range | Removes manual chart setup during active alert triage; use Show top N in the flyout for a quick look. |
Exam Preparation Tip: For the Elastic Certified SIEM Analyst examination, understand the operational difference between library-saved Lens objects (by reference) and dashboard-embedded panels (by value), and know how dashboard URL drilldowns leverage
{{event.value}}tokens to bridge Lens charts with external threat intelligence and internal Elastic Security Timelines.
A SOC analyst wants to configure a Kibana Lens dashboard panel showing suspicious external connections so that clicking on any destination IP address automatically redirects the analyst to an external threat intelligence lookup page with that IP pre-populated in the query URL. Which Kibana capability enables this contextual workflow?
Creating an Elasticsearch ingest pipeline with a redirect processor
Configuring a URL Drilldown on the Lens panel using dynamic parameter tokens such as {{event.value}}
Adding a Painless script field that executes an HTTP GET request to external REST APIs
Exporting the Lens panel as an interactive Vega visualization with embedded webhooks
A SIEM lead engineer is designing an enterprise SOC dashboard suite. The team requires a standardized 'Authentication Anomaly Matrix' Lens visualization to be displayed on ten different departmental dashboards. When the detection engineering team updates the underlying Lens formula to account for a new authentication provider, the update must immediately reflect across all ten dashboards without requiring manual edits to each dashboard. How should the Lens visualization be saved and added to the dashboards?
Save the Lens chart 'by value' directly inside each dashboard's JSON definition file
Deploy a Fleet Agent policy that pushes the updated visualization XML to all Kibana instances
Save the Lens chart to the Visualize Library 'by reference' and link it to each of the ten dashboards
Export the Lens visualization as a saved search and mount it as an index pattern alias
While hunting in Kibana Discover for unauthorized administrative tool usage, an analyst discovers an unusual execution of 'rportfwd.exe'. The analyst needs to immediately determine whether this executable has ever been run previously in the environment over the past 90 days. What is the fastest operational method in Kibana to transition from this Discover hit into a historical frequency visualization?
In the Discover field sidebar, locate 'process.name', hover over the field or click its value, and select 'Visualize' to auto-generate a Lens chart scoped to that binary
Navigate to Stack Management, create a Painless runtime field for 'rportfwd.exe', and execute a cluster-wide reindex task
Open Dev Tools and run a raw Lucene multi-search API call against all historical warm indices
Export the matching events from Discover to CSV and import them into Microsoft Excel for trend modeling
Sections you finish are checked off in the contents.