Skip to content

Commit fb7a3fc

Browse files
Syntax fixes
1 parent 5e5fe62 commit fb7a3fc

File tree

1 file changed

+13
-15
lines changed

1 file changed

+13
-15
lines changed

solutions/security/investigate/indicators-of-compromise.md

Lines changed: 13 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -15,8 +15,6 @@ The Indicators page collects data from enabled threat intelligence feeds and pro
1515

1616
* **{{agent}}** - Install a [{{fleet}}-managed {{agent}}](https://www.elastic.co/guide/en/fleet/current/install-fleet-managed-elastic-agent.html) and ensure the agent’s status is `Healthy`. Refer to [{{fleet}} Troubleshooting](../../../troubleshoot/ingest/fleet/common-problems.md) if it isn’t.
1717
* **{{filebeat}}** - Install [{{filebeat}}](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-installation-configuration.html) version 8.x or later. Earlier {{filebeat}} versions are incompatible with ECS and will prevent indicator data from displaying in the Indicators table.
18-
19-
2018
::::
2119

2220

@@ -41,9 +39,9 @@ Install a threat intelligence integration to add indicators to the Indicators pa
4139
2. In the search bar, search for `Threat Intelligence` to get a list of threat intelligence integrations.
4240
3. Select a threat intelligence integration, then complete the integration’s guided installation.
4341

44-
::::{note}
45-
For more information about available fields, go to the [Elastic integration documentation](https://docs.elastic.co/integrations) and search for a specific threat intelligence integration.
46-
::::
42+
::::{note}
43+
For more information about available fields, go to the [Elastic integration documentation](https://docs.elastic.co/integrations) and search for a specific threat intelligence integration.
44+
::::
4745

4846
4. Return to the Indicators page in {{elastic-sec}}. Refresh the page if indicator data isn’t displaying.
4947

@@ -64,17 +62,17 @@ Learn more about an indicator by clicking **View details**, then opening the Ind
6462

6563
* **Overview**: A summary of the indicator, including the indicator’s name, the threat intelligence feed it came from, the indicator type, and additional relevant data.
6664

67-
::::{note}
68-
Some threat intelligence feeds provide [Traffic Light Protocol (TLP) markings](https://www.cisa.gov/tlp#:~:text=Introduction,shared%20with%20the%20appropriate%20audience). The `TLP Marking` and `Confidence` fields will be empty if the feed doesn’t provide that data.
69-
::::
65+
::::{note}
66+
Some threat intelligence feeds provide [Traffic Light Protocol (TLP) markings](https://www.cisa.gov/tlp#:~:text=Introduction,shared%20with%20the%20appropriate%20audience). The `TLP Marking` and `Confidence` fields will be empty if the feed doesn’t provide that data.
67+
::::
7068

7169
* **Table**: The indicator data in table format.
7270
* **JSON**: The indicator data in JSON format.
7371

74-
:::{image} ../../../images/security-indicator-details-flyout.png
75-
:alt: Shows the Indicator details flyout
76-
:class: screenshot
77-
:::
72+
:::{image} ../../../images/security-indicator-details-flyout.png
73+
:alt: Shows the Indicator details flyout
74+
:class: screenshot
75+
:::
7876

7977

8078

@@ -137,9 +135,9 @@ When you attach an indicator to a case, the indicator is added as a new comment
137135

138136
* **Overview**: A summary of the threat indicator, including its name and type, which threat intelligence feed it came from, and additional relevant data.
139137

140-
::::{note}
141-
Some threat intelligence feeds provide [Traffic Light Protocol (TLP) markings](https://www.cisa.gov/tlp#:~:text=Introduction,shared%20with%20the%20appropriate%20audience). The `TLP Marking` and `Confidence` fields will be empty if the feed doesn’t provide that data.
142-
::::
138+
::::{note}
139+
Some threat intelligence feeds provide [Traffic Light Protocol (TLP) markings](https://www.cisa.gov/tlp#:~:text=Introduction,shared%20with%20the%20appropriate%20audience). The `TLP Marking` and `Confidence` fields will be empty if the feed doesn’t provide that data.
140+
::::
143141

144142
* **Table**: The indicator data in table format.
145143
* **JSON**: The indicator data in JSON format.

0 commit comments

Comments
 (0)