Configure workspace settings
Decide how your teams share the Elastic Security app and which data it shows them. You can give each team its own set of rules and alerts, add custom indices to the data that Elastic Security pages show, and add fields that you calculate from your existing data.
These settings affect every user who works in the same Kibana space, so change them when your teams, data sources, or investigation needs change.
Use the following settings to organize your workspace:
- Spaces: Separate your security operations into independent workspaces. Detection rules, rule exceptions, value lists, alerts, Timelines, cases, and Kibana advanced settings in a space are only available to users who have access to that space.
- Data views: Decide which indices, data streams, and aliases appear on Elastic Security pages that show events or alerts. The first time a user opens Elastic Security in a space, the default data view for that space generates. The default data view doesn't include custom indices, so to show them, change the default data view or create a new one. The Alerts page always reads from the alert index of the current space, whichever data view is active.
- Runtime fields: Add calculated fields to the active data view, such as two fields combined into one. Elasticsearch evaluates runtime fields each time a query runs, so they can affect performance.
| Your goal | Start here |
|---|---|
| Give teams separate rules, alerts, and cases | Spaces and Elastic Security |
|
|
Spaces and Elastic Defend FAQ |
| Show data from custom indices, or switch the data that a page shows | Data views and Elastic Security |
| Add a calculated field to your alerts and events | Create runtime fields in Elastic Security |
After you configure your workspace, you can:
- Give users access to the features they need in each space.
- Set data sources for detection rules to control which indices your rules search.