I'm leaning towards option A. Being able to quickly search for similar events on other endpoints could be really useful for understanding the scope of this issue.
Option C looks promising, as a Process Timeline would give me a better understanding of the related events. But I'm not sure if that's the specific functionality of pivoting to an Event Search.
I think option B is the correct answer. It takes you to the raw Insight event data and provides you with a number of Event Actions, which is exactly what I need to investigate this detection further.
I see both points. But I think it's important to have a Process Timeline for that detection so you can see all related events. So, I would choose option C as the best choice.
I disagree with Elena. I believe that it takes you to the raw Insight event data and provides you with a number of Event Actions. Option B seems more logical to me.
Chery
1 months agoDelmy
4 days agoMarti
13 days agoLelia
17 days agoViki
1 months agoDaniel
13 days agoYvette
19 days agoJarvis
1 months agoFatima
2 months agoJerry
6 days agoOliva
13 days agoKimbery
19 days agoValentin
1 months agoMoon
1 months agoDorthy
2 months agoVirgilio
2 months agoMaia
2 months agoHillary
14 days agoSuzan
15 days agoHuey
21 days agoBrett
2 months agoCaprice
2 months agoMajor
2 months agoElena
3 months ago