You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: solutions/security/ai/ease/ease-intro.md
+7-3Lines changed: 7 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,9 @@ applies_to:
6
6
---
7
7
# Elastic AI SOC Engine with {{sec-serverless}}
8
8
9
-
Elastic AI Security Operations Center (SOC) Engine (EASE) is an {{sec-serverless}} project type that provides AI-powered tools and case management to augment third-party SIEM and EDR/XDR platforms. This page describes how to create an {{sec-serverless}} EASE project, how to ingest your data, and how to use its key features.
9
+
Elastic AI SOC Engine (EASE) is an {{sec-serverless}} project type that provides cutting-edge AI-powered tools to augment your existing SIEM and EDR/XDR platforms. Because serverless deployments are quick to deploy and easy to configure, and because all the integrations that you can use to ingest data to EASE support fast and easy [agentless](/solutions/security/get-started/agentless-integrations.md) deployment, you can start getting value from EASE in minutes.
10
+
11
+
This page describes how to create an EASE project, how to ingest your data, and how to use its key features.
10
12
11
13
## Create an EASE project
12
14
@@ -21,9 +23,9 @@ To create an EASE project:
21
23
2. Click **Create serverless project**, and wait for your project to be provisioned. When it's ready, open it.
22
24
23
25
24
-
## Ingest your SOC data
26
+
## Ingest your SIEM and EDR/XDR data
25
27
26
-
To ingest your SOC data:
28
+
To ingest third-party security data:
27
29
28
30
1. Go to the **Configurations** page using the navigation menu or the [global search field](/explore-analyze/find-and-organize/find-apps-and-objects.md).
29
31
@@ -48,6 +50,8 @@ EASE provides a set of capabilities designed to help make the most of each secur
48
50
:alt: Attack Discovery detail view
49
51
:::
50
52
53
+
You can [schedule](/solutions/security/ai/attack-discovery.md#schedule-discoveries) Attack Discovery to run automatically, and notify you of any discoveries via a range of connectors such as Slack, Teams, PagerDuty, or email.
54
+
51
55
-**[AI Assistant](/solutions/security/ai/ai-assistant.md)**: An LLM-powered virtual assistant specialized for digital security; it helps with data analysis, alert investigation, incident response, and {{esql}} query generation. You can add custom background knowledge and data to its [knowledge base](/solutions/security/ai/ai-assistant-knowledge-base.md) and use natural language to ask for its assistance with your SOC operations.
52
56
53
57
-**[Cases](/solutions/security/investigate/cases.md)**: Helps you track and share related information about security issues. Track key investigation details and collect alerts in a central location.
0 commit comments