Skip to content

11 files changed

+72
-289
lines changed

raw-migrated-files/docs-content/serverless/security-behavioral-detection-use-cases.md

Lines changed: 0 additions & 30 deletions
This file was deleted.

raw-migrated-files/docs-content/serverless/security-ers-requirements.md

Lines changed: 0 additions & 56 deletions
This file was deleted.

raw-migrated-files/docs-content/serverless/security-machine-learning.md

Lines changed: 0 additions & 68 deletions
This file was deleted.

raw-migrated-files/docs-content/serverless/security-ml-requirements.md

Lines changed: 0 additions & 16 deletions
This file was deleted.

raw-migrated-files/docs-content/serverless/security-turn-on-risk-engine.md

Lines changed: 0 additions & 53 deletions
This file was deleted.

raw-migrated-files/toc.yml

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -197,7 +197,6 @@ toc:
197197
- file: docs-content/serverless/security-alerts-manage.md
198198
- file: docs-content/serverless/security-automated-response-actions.md
199199
- file: docs-content/serverless/security-automatic-import.md
200-
- file: docs-content/serverless/security-behavioral-detection-use-cases.md
201200
- file: docs-content/serverless/security-benchmark-rules-kspm.md
202201
- file: docs-content/serverless/security-benchmark-rules.md
203202
- file: docs-content/serverless/security-blocklist.md
@@ -228,7 +227,6 @@ toc:
228227
- file: docs-content/serverless/security-endpoint-management-req.md
229228
- file: docs-content/serverless/security-endpoints-page.md
230229
- file: docs-content/serverless/security-environment-variable-capture.md
231-
- file: docs-content/serverless/security-ers-requirements.md
232230
- file: docs-content/serverless/security-event-filters.md
233231
- file: docs-content/serverless/security-get-started-with-kspm.md
234232
- file: docs-content/serverless/security-host-isolation-exceptions.md
@@ -239,8 +237,6 @@ toc:
239237
- file: docs-content/serverless/security-linux-file-monitoring.md
240238
- file: docs-content/serverless/security-llm-connector-guides.md
241239
- file: docs-content/serverless/security-llm-performance-matrix.md
242-
- file: docs-content/serverless/security-machine-learning.md
243-
- file: docs-content/serverless/security-ml-requirements.md
244240
- file: docs-content/serverless/security-overview-dashboard.md
245241
- file: docs-content/serverless/security-policies-page.md
246242
- file: docs-content/serverless/security-posture-faq.md
@@ -262,7 +258,6 @@ toc:
262258
- file: docs-content/serverless/security-triage-alerts-with-elastic-ai-assistant.md
263259
- file: docs-content/serverless/security-trusted-applications.md
264260
- file: docs-content/serverless/security-tune-detection-signals.md
265-
- file: docs-content/serverless/security-turn-on-risk-engine.md
266261
- file: docs-content/serverless/security-view-alert-details.md
267262
- file: docs-content/serverless/security-visualize-alerts.md
268263
- file: docs-content/serverless/security-vuln-management-dashboard-dash.md

solutions/security/advanced-entity-analytics/anomaly-detection.md

Lines changed: 2 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -6,21 +6,15 @@ mapped_urls:
66

77
# Anomaly detection
88

9-
% What needs to be done: Align serverless/stateful
109

11-
% Use migrated content from existing pages that map to this page:
12-
13-
% - [x] ./raw-migrated-files/security-docs/security/machine-learning.md
14-
% - [ ] ./raw-migrated-files/docs-content/serverless/security-machine-learning.md
15-
16-
[{{ml-cap}}](/explore-analyze/machine-learning/anomaly-detection.md) functionality is available when you have the appropriate subscription, are using a **{{ess-trial}}[cloud deployment]**, or are testing out a **Free Trial**. Refer to [Machine learning job and rule requirements](/solutions/security/advanced-entity-analytics/machine-learning-job-rule-requirements.md) for more information.
10+
[{{ml-cap}}](/explore-analyze/machine-learning/anomaly-detection.md) functionality is available when you have the appropriate role, subscription, are using a [cloud deployment](https://cloud.elastic.co/registration?page=docs&placement=docs-body), or are testing out a **Free Trial**. Refer to [Machine learning job and rule requirements](/solutions/security/advanced-entity-analytics/machine-learning-job-rule-requirements.md) for more information.
1711

1812
You can view the details of detected anomalies within the `Anomalies` table widget shown on the Hosts, Network, and associated details pages, or even narrow to the specific date range of an anomaly from the `Max anomaly score by job` field in the overview of the details pages for hosts and IPs. These interfaces also offer the ability to drag and drop details of the anomaly to Timeline, such as the `Entity` itself, or any of the associated `Influencers`.
1913

2014

2115
## Manage {{ml}} jobs [manage-jobs]
2216

23-
If you have the `machine_learning_admin` role, you can use the **ML job settings** interface on the **Alerts**, **Rules**, and **Rule Exceptions** pages to view, start, and stop {{elastic-sec}} {{ml}} jobs.
17+
If you have the appropriate role, you can use the **ML job settings** interface on the **Alerts**, **Rules**, and **Rule Exceptions** pages to view, start, and stop {{elastic-sec}} {{ml}} jobs.
2418

2519
:::{image} ../../../images/security-ml-ui.png
2620
:alt: ML job settings UI on the Alerts page

solutions/security/advanced-entity-analytics/behavioral-detection-use-cases.md

Lines changed: 2 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -6,18 +6,6 @@ mapped_urls:
66

77
# Behavioral detection use cases
88

9-
% What needs to be done: Align serverless/stateful
10-
11-
% Use migrated content from existing pages that map to this page:
12-
13-
% - [x] ./raw-migrated-files/security-docs/security/behavioral-detection-use-cases.md
14-
% - [ ] ./raw-migrated-files/docs-content/serverless/security-behavioral-detection-use-cases.md
15-
16-
% Internal links rely on the following IDs being on this page (e.g. as a heading ID, paragraph ID, etc):
17-
18-
$$$ml-integrations$$$
19-
20-
$$$security-behavioral-detection-use-cases-elastic-integrations-for-behavioral-detection-use-cases$$$
219

2210
Behavioral detection identifies potential internal and external threats based on user and host activity. It uses a threat-centric approach to flag suspicious activity by analyzing patterns, anomalies, and context enrichment.
2311

@@ -29,7 +17,8 @@ The behavioral detection feature is built on {{elastic-sec}}'s foundational SIEM
2917
Behavioral detection integrations provide a convenient way to enable behavioral detection capabilities. They streamline the deployment of components that implement behavioral detection, such as data ingestion, transforms, rules, {{ml}} jobs, and scripts.
3018

3119
::::{admonition} Requirements
32-
* Behavioral detection integrations require a [Platinum subscription](https://www.elastic.co/pricing) or higher.
20+
* In {{stack}}, behavioral detection integrations require a [Platinum subscription](https://www.elastic.co/pricing) or higher.
21+
* In serverless, behavioral detection integrations require the Security Analytics Complete [project feature](/deploy-manage/deploy/elastic-cloud/project-settings.md).
3322
* To learn more about the requirements for using {{ml}} jobs, refer to [Machine learning job and rule requirements](/solutions/security/advanced-entity-analytics/machine-learning-job-rule-requirements.md).
3423

3524
::::

0 commit comments

Comments
 (0)