Skip to content

[Internal]: Building block rule actions #2334

@yctercero

Description

@yctercero

Description

The Detection Engine team was pinged about customer confusion on whether building block rules (BBRs) generate notifications. It seemed to me that by allowing users to add notifications for BBRs, it was understood as available functionality, but can also recognize the confusion. ChatGPT also thought notifications weren't configurable with BBRs 😄

I'm linking the docs - unsure of the most natural place to mention notifications.

Resources

Docs: https://www.elastic.co/docs/solutions/security/detect-and-alert/about-building-block-rules

Slack convo: https://elastic.slack.com/archives/C056TQ5J81Y/p1753219164916039

Which documentation set does this change impact?

Elastic On-Prem and Cloud (all)

Feature differences

NA

What release is this request related to?

9.2, 9.1, 8.19

Serverless release

Anytime

Collaboration model

The documentation team

Point of contact.

Main contact: @yctercero

Stakeholders: @approksiu

Metadata

Metadata

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions