From e387c7cdcd32fa976eb13e9cfeb2a45cb0543c68 Mon Sep 17 00:00:00 2001 From: Benjamin Ironside Goldstein Date: Tue, 30 Sep 2025 15:46:54 -0700 Subject: [PATCH] Automatic import step --- solutions/security/get-started/automatic-migration.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/solutions/security/get-started/automatic-migration.md b/solutions/security/get-started/automatic-migration.md index 59231e455f..fc3bf7699c 100644 --- a/solutions/security/get-started/automatic-migration.md +++ b/solutions/security/get-started/automatic-migration.md @@ -56,7 +56,7 @@ You can ingest your data before migrating your rules, or migrate your rules firs 6. After you upload your Splunk rules, Automatic Migration will detect whether they use any Splunk macros or lookups. If so, follow the instructions which appear to export and upload them. Alternatively, you can complete this step later — however, until you upload them, some of your migrated rules will have a `partially translated` status. If you upload them now, you don't have to wait on the page for them to be processed — a notification will appear when processing is complete. -7. Click **Translate** to start the rule translation process. You don't need to stay on this page. A notification will appear when the process is complete. A name for this migration is automatically created. If necessary, use the **More actions** ({icon}`boxes_vertical`) button to rename or pause the migration. +7. Click **Translate** to start the rule translation process. A name for this migration is automatically created, and you can track its progress on this page. The **More actions** ({icon}`boxes_vertical`) button lets you rename or pause the migration. ::::{image} /solutions/images/security-siem-migration-rule-status-more-actions.png :alt: The rule migration status view @@ -64,6 +64,9 @@ You can ingest your data before migrating your rules, or migrate your rules firs :screenshot: :::: + You don't need to stay on this page. A notification will appear when the migration is complete. + + 8. Use the **Add SIEM data with Integrations** section to set up data ingestion from third-party sources. If at least one rule migration has completed, the **Recommended** tab shows integrations that provide the data needed by your translated rules. These include both Elastic-managed integrations and any applicable custom creations you made using [automatic import](/solutions/security/get-started/automatic-import.md). ::::{image} /solutions/images/security-siem-migration-integrations-panel.png