google / timesketch

Collaborative forensic timeline analysis
Apache License 2.0
2.62k stars 589 forks source link

UI feedback: Improve initial search UX #2900

Open jkppr opened 1 year ago

jkppr commented 1 year ago

When working on a new sketch the initial explore page has a lot of white space and no information on how to get started. The analyst has just their list of timelines and an empty search bar (see screenshot below).

image

While observing how analysts work with timesketch and from feedback, we noticed that many analysts start by running the * search to get all events for all timelines. This operation gets more and more expensive with larger timelines until it can even break (e.g. searching * on 50M events, does not work well and will most likely generate an error 500.)

The main task with this issue is to explore and track possible options to improve the start of an investigation.

Possible ideas that have been provided during feedback sessions:

image