Skip to content

Commit 6478dad

Browse files
First draft
1 parent 1ce1967 commit 6478dad

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

solutions/security/detect-and-alert/cross-cluster-search-detection-rules.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,12 @@ applies_to:
99

1010
[Cross-cluster search](../../search/cross-cluster-search.md) is an {{es}} feature that allows one cluster (the *local* cluster) to query data in a separate cluster (the *remote* cluster). {{elastic-sec}}'s detection rules can perform a cross-cluster search to query data in remote clusters.
1111

12+
::::{admonition} Requirements
13+
* In {{stack}}, using cross-cluster search for {esql} rules requires an [Enterprise subscription](https://www.elastic.co/pricing).
14+
% * In serverless, behavioral detection integrations require the Security Analytics Complete [project feature](/deploy-manage/deploy/elastic-cloud/project-settings.md).
15+
* To learn more about the requirements for using cross-cluster search, refer to [Cross-cluster search](../../search/cross-cluster-search.md).
16+
17+
::::
1218

1319
## Set up cross-cluster search in detection rules [set-up-ccs-rules]
1420

0 commit comments

Comments
 (0)