Skip to content

Commit a0a2754

Browse files
[Security] Advanced setting for ES|QL risk scoring
1 parent c0eb09f commit a0a2754

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

solutions/security/get-started/configure-advanced-settings.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -252,3 +252,9 @@ serverless: ga
252252

253253
The `securitySolution:enablePrivilegedUserMonitoring` setting allows you to access the [Entity analytics overview page](/solutions/security/advanced-entity-analytics/overview.md) and the [privileged user monitoring](/solutions/security/advanced-entity-analytics/privileged-user-monitoring.md) feature. This setting is turned off by default.
254254

255+
## Turn off {{esql}}-based risk scoring
256+
```yaml {applies_to}
257+
stack: ga 9.2
258+
serverless: ga
259+
```
260+
By default, [entity risk scoring](/solutions/security/advanced-entity-analytics/entity-risk-scoring.md) calculations are based on {{esql}} queries. Turn off `securitySolution:enableEsqlRiskScoring` to use scripted metrics instead.

0 commit comments

Comments
 (0)