Description
What: "The How to add non-ECS fields to Attack Discovery
callout in the Set up Attack Discovery documentation is missing an Update presets
step, which is required to achieve the task.
When: This feature is in production
Why: Users cannot add additional fields to their anonymization settings without this step.
Consider adding something like:
4. Check the `Update presets` box to add the Allowed fields to the space's default Anonymization settings.
Resources
The documentation is published to https://www.elastic.co/docs/solutions/security/ai/attack-discovery#set-up-attack-discovery
Which documentation set does this change impact?
Elastic On-Prem and Cloud (all)
Feature differences
The feature is identical in all deployment methods.
What release is this request related to?
9.2
Serverless release
This feature is already in production
Collaboration model
The documentation team
Point of contact.
Main contact: @jamesspi
Stakeholders: CC: @andrew-goldstein