Skip to content

Commit af42c48

Browse files
turn on ers
1 parent 5f970d8 commit af42c48

File tree

3 files changed

+6
-68
lines changed

3 files changed

+6
-68
lines changed

raw-migrated-files/docs-content/serverless/security-turn-on-risk-engine.md

Lines changed: 0 additions & 53 deletions
This file was deleted.

raw-migrated-files/toc.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -318,7 +318,6 @@ toc:
318318
- file: docs-content/serverless/security-triage-alerts-with-elastic-ai-assistant.md
319319
- file: docs-content/serverless/security-trusted-applications.md
320320
- file: docs-content/serverless/security-tune-detection-signals.md
321-
- file: docs-content/serverless/security-turn-on-risk-engine.md
322321
- file: docs-content/serverless/security-ui.md
323322
- file: docs-content/serverless/security-view-alert-details.md
324323
- file: docs-content/serverless/security-visual-event-analyzer.md

solutions/security/advanced-entity-analytics/turn-on-risk-scoring-engine.md

Lines changed: 6 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -6,29 +6,18 @@ mapped_urls:
66

77
# Turn on the risk scoring engine
88

9-
% What needs to be done: Align serverless/stateful
10-
11-
% Use migrated content from existing pages that map to this page:
12-
13-
% - [x] ./raw-migrated-files/security-docs/security/turn-on-risk-engine.md
14-
% - [ ] ./raw-migrated-files/docs-content/serverless/security-turn-on-risk-engine.md
15-
16-
% Internal links rely on the following IDs being on this page (e.g. as a heading ID, paragraph ID, etc):
17-
18-
$$$upgrade-risk-engine$$$
199

2010
::::{important}
21-
To use entity risk scoring, your role must have the appropriate privileges. For more information, refer to [Entity risk scoring requirements](/solutions/security/advanced-entity-analytics/entity-risk-scoring-requirements.md).
11+
To use entity risk scoring, your role must have the appropriate user role or privileges. For more information, refer to [Entity risk scoring requirements](/solutions/security/advanced-entity-analytics/entity-risk-scoring-requirements.md).
2212
::::
2313

2414

25-
2615
## Preview risky entities [_preview_risky_entities]
2716

2817
You can preview risky entities before installing the latest risk engine. The preview shows the riskiest hosts and users found in the 1000 sampled entities during the time frame selected in the date picker.
2918

3019
::::{note}
31-
The preview is limited to two risk scores per {{kib}} instance.
20+
The preview is limited to two risk scores per {{kib}} instance or serverless project.
3221
::::
3322

3423

@@ -44,7 +33,7 @@ To preview risky entities, find **Entity Risk Score** in the navigation menu or
4433

4534
::::{note}
4635
* To view risk score data, you must have alerts generated in your environment.
47-
* If you previously installed the original user and host risk score modules, and you’re upgrading to {{stack}} version 8.11 or newer, refer to [Upgrade to the latest risk engine](/solutions/security/advanced-entity-analytics/turn-on-risk-scoring-engine.md#upgrade-risk-engine).
36+
* In {{stack}}, if you previously installed the original user and host risk score modules, and you’re upgrading to {{stack}} version 8.11 or newer, refer to [Upgrade to the latest risk engine](/solutions/security/advanced-entity-analytics/turn-on-risk-scoring-engine.md#upgrade-risk-engine).
4837

4938
::::
5039

@@ -63,6 +52,9 @@ You can also choose to include `Closed` alerts in risk scoring calculations and
6352

6453

6554
## Upgrade to the latest risk engine [upgrade-risk-engine]
55+
```yaml {applies_to}
56+
stack:
57+
```
6658
6759
If you upgraded to 8.11 from an earlier {{stack}} version, and you have the original risk engine installed, you can upgrade to the latest risk engine. You will be prompted to upgrade in places where risk score data exists, such as:
6860

0 commit comments

Comments
 (0)