Skip to content

Commit 470e497

Browse files
committed
Remove statement on rule type limitations
1 parent 686800d commit 470e497

File tree

2 files changed

+0
-2
lines changed

2 files changed

+0
-2
lines changed

docs/management/admin/automated-response-actions.asciidoc

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,6 @@ Add {elastic-defend}'s <<response-actions,response actions>> to detection rules
1414
* Automated response actions require an https://www.elastic.co/pricing[Enterprise subscription].
1515
* Hosts must have {agent} installed with the {elastic-defend} integration.
1616
* Your user role must have the ability to create detection rules and the privilege to perform <<response-action-commands,specific response actions>> (for example, the **Host Isolation** privilege to isolate hosts).
17-
* You can only add automated response actions to <<create-custom-rule,custom query>>, <<create-eql-rule,event correlation (EQL)>>, <<create-new-terms-rule,new terms>>, and <<create-esql-rule,{esql}>> type rules.
1817
--
1918

2019
To add automated response actions to a new or existing rule:

docs/serverless/endpoint-response-actions/automated-response-actions.mdx

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,6 @@ Add ((elastic-defend))'s <DocLink slug="/serverless/security/response-actions">r
1515
- Automated response actions require the Endpoint Protection Complete <DocLink slug="/serverless/elasticsearch/manage-project">project feature</DocLink>.
1616
- Hosts must have ((agent)) installed with the ((elastic-defend)) integration.
1717
- Your user role must have the ability to create detection rules and the privilege to perform <DocLink slug="/serverless/security/response-actions" section="response-action-commands">specific response actions</DocLink> (for example, custom roles require the **Host Isolation** privilege to isolate hosts).
18-
- You can only add automated response actions to <DocLink slug="/serverless/security/rules-create" section="create-custom-rule">custom query</DocLink>, <DocLink slug="/serverless/security/rules-create" section="create-eql-rule">event correlation (EQL)</DocLink>, <DocLink slug="/serverless/security/rules-create" section="create-new-terms-rule">new terms</DocLink>, and <DocLink slug="/serverless/security/rules-create" section="create-esql-rule">((esql))</DocLink> type rules.
1918

2019
</DocCallOut>
2120

0 commit comments

Comments
 (0)