Skip to content

Commit 89e9276

Browse files
Automatic migration 9.1 updates (#2304)
Fixes internal/[70](elastic/docs-content-internal#70) and [internal/71](elastic/docs-content-internal#71) by updating the automatic migration docs. For previews, refer to the comment below. --------- Co-authored-by: Mike Birnstiehl <[email protected]>
1 parent f78862e commit 89e9276

File tree

5 files changed

+25
-3
lines changed

5 files changed

+25
-3
lines changed
88.7 KB
Loading
-2.43 KB
Loading
60.2 KB
Loading
31.1 KB
Loading

solutions/security/get-started/automatic-migration.md

Lines changed: 25 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -56,9 +56,23 @@ You can ingest your data before migrating your rules, or migrate your rules firs
5656

5757
6. After you upload your Splunk rules, Automatic Migration will detect whether they use any Splunk macros or lookups. If so, follow the instructions which appear to export and upload them. Alternatively, you can complete this step later — however, until you upload them, some of your migrated rules will have a `partially translated` status. If you upload them now, you don't have to wait on the page for them to be processed — a notification will appear when processing is complete.
5858

59-
7. Click **Translate** to start the rule translation process. You don't need to stay on this page. A notification will appear when the process is complete.
59+
7. Click **Translate** to start the rule translation process. You don't need to stay on this page. A notification will appear when the process is complete. A name for this migration is automatically created. If necessary, use the **More actions** ({icon}`boxes_vertical`) button to rename or pause the migration.
6060

61-
8. When migration is complete, click the notification or return to the **Get started** page then click **View translated rules** to open the **Translated rules** page.
61+
::::{image} /solutions/images/security-siem-migration-rule-status-more-actions.png
62+
:alt: The rule migration status view
63+
:width: 850px
64+
:screenshot:
65+
::::
66+
67+
8. Use the **Add SIEM data with Integrations** section to set up data ingestion from third-party sources. If at least one rule migration has completed, the **Recommended** tab shows integrations that provide the data needed by your translated rules. These include both Elastic-managed integrations and any applicable custom creations you made using [automatic import](/solutions/security/get-started/automatic-import.md).
68+
69+
::::{image} /solutions/images/security-siem-migration-integrations-panel.png
70+
:alt: The add integrations panel.
71+
:width: 850px
72+
:screenshot:
73+
::::
74+
75+
9. When migration is complete, click the notification or return to the **Get started** page then click **View translated rules** to open the **Translated rules** page.
6276

6377

6478
## The Translated rules page
@@ -98,7 +112,15 @@ The table's fields are as follows:
98112

99113
* **Author:** Shows one of two possible values: `Elastic`, or `Custom`. Elastic-authored rules are created by Elastic and update automatically. Custom rules are translated by the Automatic Migration tool or your team, and do not update automatically.
100114
* **Integrations:** Shows the number of Elastic integrations that must be installed to provide data for the rule to run successfully.
101-
* **Actions:** Allows you to click **Install** to add a rule to Elastic. Installed rules must also be enabled before they will run. To install rules in bulk, select the check box at the top of the table before clicking **Install**.
115+
* **Actions:**
116+
* To add a rule to Elastic, select one or more `translated` rules then click **Install**. Then select them again and click **Enable**.
117+
* To reprocess a rule using the same or a different LLM connector, select one or more rules that weren't successfully translated then click **Reprocess**. A menu appears where you can select which AI connector to use.
118+
119+
::::{image} /solutions/images/security-siem-migration-reprocess-modal.png
120+
:alt: The reprocess rule modal
121+
:width: 450px
122+
:screenshot:
123+
::::
102124

103125
## Finalize translated rules
104126

0 commit comments

Comments
 (0)