diff --git a/solutions/security/detect-and-alert/cross-cluster-search-detection-rules.md b/solutions/security/detect-and-alert/cross-cluster-search-detection-rules.md index 118adcb571..0d0c27c774 100644 --- a/solutions/security/detect-and-alert/cross-cluster-search-detection-rules.md +++ b/solutions/security/detect-and-alert/cross-cluster-search-detection-rules.md @@ -1,6 +1,9 @@ --- mapped_pages: - https://www.elastic.co/guide/en/security/current/rules-cross-cluster-search.html + +applies: + stack: ga all --- # Cross-cluster search and detection rules [rules-cross-cluster-search] @@ -12,6 +15,8 @@ mapped_pages: This section explains the general process for setting up cross-cluster search in detection rules. For specific instructions on each part of the process, refer to the linked documentation. +% The list items under step 1 require versioning. Guidance on versioning is pending, so revisit this later. + 1. On the local cluster, establish trust and set up a connection to the remote cluster, using one of the following methods. With either method, note the unique name that you give to the remote cluster, because you’ll need to use it throughout this process. * [Add remote clusters using API key authentication](../../../deploy-manage/remote-clusters/remote-clusters-api-key.md) — Clusters must be on {{stack}} version 8.14 or later.