Configure workspace settings

Decide how your teams share the Elastic Security app and which data it shows them. You can give each team its own set of rules and alerts, add custom indices to the data that Elastic Security pages show, and add fields that you calculate from your existing data.

These settings affect every user who works in the same Kibana space, so change them when your teams, data sources, or investigation needs change.

Use the following settings to organize your workspace:

  • Spaces: Separate your security operations into independent workspaces. Detection rules, rule exceptions, value lists, alerts, Timelines, cases, and Kibana advanced settings in a space are only available to users who have access to that space.
  • Data views: Decide which indices, data streams, and aliases appear on Elastic Security pages that show events or alerts. The first time a user opens Elastic Security in a space, the default data view for that space generates. The default data view doesn't include custom indices, so to show them, change the default data view or create a new one. The Alerts page always reads from the alert index of the current space, whichever data view is active.
  • Runtime fields: Add calculated fields to the active data view, such as two fields combined into one. Elasticsearch evaluates runtime fields each time a query runs, so they can affect performance.
Your goal Start here
Give teams separate rules, alerts, and cases Spaces and Elastic Security
Understand how spaces scope Elastic Defend policies, artifacts, and response actions Spaces and Elastic Defend FAQ
Show data from custom indices, or switch the data that a page shows Data views and Elastic Security
Add a calculated field to your alerts and events Create runtime fields in Elastic Security

After you configure your workspace, you can: