You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
% Internal links rely on the following IDs being on this page (e.g. as a heading ID, paragraph ID, etc):
17
-
18
-
$$$upgrade-risk-engine$$$
19
9
20
10
::::{important}
21
-
To use entity risk scoring, your role must have the appropriate privileges. For more information, refer to [Entity risk scoring requirements](/solutions/security/advanced-entity-analytics/entity-risk-scoring-requirements.md).
11
+
To use entity risk scoring, your role must have the appropriate user role or privileges. For more information, refer to [Entity risk scoring requirements](/solutions/security/advanced-entity-analytics/entity-risk-scoring-requirements.md).
You can preview risky entities before installing the latest risk engine. The preview shows the riskiest hosts and users found in the 1000 sampled entities during the time frame selected in the date picker.
29
18
30
19
::::{note}
31
-
The preview is limited to two risk scores per {{kib}} instance.
20
+
The preview is limited to two risk scores per {{kib}} instance or serverless project.
32
21
::::
33
22
34
23
@@ -44,7 +33,7 @@ To preview risky entities, find **Entity Risk Score** in the navigation menu or
44
33
45
34
::::{note}
46
35
* To view risk score data, you must have alerts generated in your environment.
47
-
*If you previously installed the original user and host risk score modules, and you’re upgrading to {{stack}} version 8.11 or newer, refer to [Upgrade to the latest risk engine](/solutions/security/advanced-entity-analytics/turn-on-risk-scoring-engine.md#upgrade-risk-engine).
36
+
*In {{stack}}, if you previously installed the original user and host risk score modules, and you’re upgrading to {{stack}} version 8.11 or newer, refer to [Upgrade to the latest risk engine](/solutions/security/advanced-entity-analytics/turn-on-risk-scoring-engine.md#upgrade-risk-engine).
48
37
49
38
::::
50
39
@@ -63,6 +52,9 @@ You can also choose to include `Closed` alerts in risk scoring calculations and
63
52
64
53
65
54
## Upgrade to the latest risk engine [upgrade-risk-engine]
55
+
```yaml {applies_to}
56
+
stack:
57
+
```
66
58
67
59
If you upgraded to 8.11 from an earlier {{stack}} version, and you have the original risk engine installed, you can upgrade to the latest risk engine. You will be prompted to upgrade in places where risk score data exists, such as:
0 commit comments