8.1 Security App Capabilities & the Explore Pages (Hosts, Network, Users)

Key Takeaways

  • The Security app groups its capabilities into detection rules, the Alerts page, investigation tools (Timeline, visual event analyzer, Session View, Osquery), Explore, dashboards, Cases and AI features.

  • The Hosts page has Events, All hosts, Uncommon processes, Anomalies, Host risk and Sessions tabs, and its Sessions tab opens Linux sessions in Session View.

  • The Network page combines an interactive map (which needs Maps privileges) with Events, Flows, DNS, HTTP, TLS and Anomalies tabs.

  • IP details pages show location, first and last seen, the related host, alert metrics and reputation links that default to Talos and VirusTotal.

  • The Users page has Events, All users, Authentications, Anomalies and User risk tabs, and host and user risk tabs require Platinum with the risk engine turned on.

Last updated: September 2026

The Security app is where most of the SIEM Analyst objectives live. Elastic's objectives ask you to recognize the capabilities of the Security App and use Explore within the Security App to view security-related events. This section gives you a map of the app and then walks through the three Explore pages: Hosts, Network and Users.

What the Security App Does

The Security app is a Kibana application that works on data matched by the securitySolution:defaultIndex setting (Beats and Elastic Agent indices such as logs-* by default) and on the detection alerts in .alerts-security.alerts-<space-id>. Its capabilities group naturally by job:

JobSecurity App CapabilityWhere You Find It
DetectPrebuilt and custom detection rules (query, EQL, threshold, indicator match, new terms, ES|QL, machine learning), exceptions, value listsRules
TriageAlerts page with filters, grouping, charts, tags and assignees; alert details flyoutAlerts
InvestigateTimeline (KQL, EQL correlation, ES|QL), visual event analyzer, Session View, OsqueryTimelines and the Timeline bar at the bottom of most pages
ExploreHosts, Network and Users pages with KPIs, tables and details pagesExplore
MonitorDefault dashboards: Overview, Detection & Response, Entity Analytics, Data Quality, Kubernetes, cloud security dashboards, Detection rule monitoringDashboards
Respond and trackCases with external connectors; endpoint response actions and host isolationCases; alert and endpoint actions
IntelligenceIngested threat indicators and threat intelligence enrichment of alertsIntelligence; alert flyout Insights
AIElastic AI Assistant and Attack Discovery (Enterprise)Chat buttons; Attack discovery page
Protect endpoints and cloudElastic Defend endpoints, policies and artifacts; cloud posture and vulnerability findingsManage / Assets; Findings

Two conventions tie these areas together:

  • Timeline everywhere. The Timeline bar is available across the app, and most tables and charts offer Add to timeline or drag-and-drop into Timeline. Values flow from Explore, Alerts and dashboards straight into an investigation.
  • Consistent inline actions. Hovering over a value typically offers Filter In, Filter Out, Add to timeline, Show top N and Copy to clipboard. Charts offer an options menu with Inspect, Add to new or existing case and Open in Lens.

Explore: The Hosts Page

The Hosts page summarizes every host that appears in your security data and its events.

  • KPI charts show the number of hosts and unique IPs for the selected time range. Their actions menu lets you inspect the query, open the chart in Lens, or add it to a case.
  • Tabs below the charts:
    • Events: all host events. Show only external alerts filters to alerts received from external monitoring tools.
    • All hosts: high-level host details.
    • Uncommon processes: processes that run on few hosts, a quick way to spot unusual binaries.
    • Anomalies: anomalies found by machine learning jobs.
    • Host risk: the latest host risk score and level for each host. It needs a Platinum subscription or higher, and the risk engine must be turned on.
    • Sessions: Linux process sessions that open in Session View.
  • Host details page (click a host name in All hosts): asset criticality, a summary with host ID, first and last seen, IP addresses, operating system and risk data, alert metrics by severity, rule and status, and the same tabs filtered to that host.
  • Host details flyout: opened by clicking a host name in the Alerts table, the Entity Analytics dashboard and other tables. It shows the host risk summary (with View risk contributions listing the top 10 contributing alerts), asset criticality, and observed data.

Explore: The Network Page

The Network page focuses on network activity.

  • Interactive map: shows source and destination points. You need Read or All privileges for Maps, and the map data must be configured (network map data). From the map you can add a filter, drag a field to Timeline, click a host name to open the Hosts page, or click an IP to open its IP details page.
  • Widgets: network events, DNS queries, unique flow IDs, TLS handshakes and unique private IPs.
  • Tabs: Events, Flows (source and destination IPs and countries), DNS, HTTP, TLS (handshake details) and Anomalies.
  • IP details page: location, first and last seen, the associated host ID and host name, and external reputation links, which default to Talos and VirusTotal and can be changed in advanced settings. It also shows alert metrics and the same tables filtered to that IP.

Explore: The Users Page

The Users page covers identities and authentication.

  • KPI charts: total users and successful and failed authentications.
  • Tabs:
    • Events: events that contain user.name, which you can stack by event.action, event.dataset or event.module.
    • All users: user names, when they were last active, and their domains.
    • Authentications: authentication events with success and failure counts and the last successful destination host.
    • Anomalies: machine learning anomalies involving user data.
    • User risk: the latest user risk score and level (Platinum or higher, risk engine turned on).
  • User details page and flyout: asset criticality, a summary, alert metrics, and the user risk summary with contributing alerts.

Using Explore in an Investigation

A typical flow shows how the pages connect:

  1. An alert fires for suspicious PowerShell on wks-fin-04. From the Alerts table, click the host name to open the host details flyout. The host risk is High, and several other alerts contributed to it.
  2. Open the host's details page. On Uncommon processes, rclone.exe appears on this host and almost nowhere else.
  3. Switch to the Network page, filter to the host, and check the Flows and DNS tabs. Large outbound flows go to an unfamiliar IP.
  4. Click the IP to open its IP details page, and use the VirusTotal and Talos links to check its reputation.
  5. Drag the host name and the IP into Timeline to build a combined query, pin the key events, and attach the Timeline to a case.
PageBest ForKey Tabs
HostsWhat ran where; rare processes; Linux sessions; host riskEvents, All hosts, Uncommon processes, Anomalies, Host risk, Sessions
NetworkWho talked to whom; DNS, HTTP and TLS details; IP reputationEvents, Flows, DNS, HTTP, TLS, Anomalies
UsersAuthentication behavior; account activity; user riskEvents, All users, Authentications, Anomalies, User risk
Test Your Knowledge

An analyst wants to replay the Linux process sessions recorded on a web server, starting from the Explore area of the Security app. Which page and tab provide this?

A

Network page, TLS tab

B

Users page, Authentications tab

C

Hosts page, Sessions tab

D

Hosts page, All hosts tab

Test Your Knowledge

While reviewing the Network page, an analyst clicks an external IP address. Which default reputation links does the resulting IP details page provide?

A

AbuseIPDB and Shodan

B

Talos and VirusTotal

C

GreyNoise and URLhaus

D

MISP and AlienVault OTX

Test Your Knowledge

A team on a Basic license opens the Hosts page and finds the Host risk tab empty. What is required for it to show host risk scores?

A

A Platinum subscription or higher, with the risk scoring engine turned on

B

Installing the Network Packet Capture integration

C

Enabling the Uncommon processes machine learning job

D

Adding the host.risk field to the Security default data view

Test Your Knowledge

Which Explore page gives counts of successful and failed authentications and a table listing, for each user, the number of successes and failures and the last successful destination host?

A

Hosts page

B

Network page

C

Users page

D

Overview dashboard

Sections you finish are checked off in the contents.