Skip to content

Commit 708f300

Browse files
benironsidemergify[bot]
authored andcommitted
[8.16] AI usecase updates (#6076)
* ESS and Serverless AI usecase updates * fixes reference to number of alerts * tweaks image size (cherry picked from commit 21b9b46) # Conflicts: # docs/serverless/AI-for-security/ai-assistant-alert-triage.asciidoc # docs/serverless/AI-for-security/ai-assistant-esql-queries.asciidoc # docs/serverless/AI-for-security/images/attck-disc-11-alerts-disc.png # docs/serverless/AI-for-security/images/attck-disc-translate-japanese.png # docs/serverless/AI-for-security/usecase-attack-disc-ai-assistant-incident-reporting.asciidoc # docs/serverless/images/ai-assistant-alert-triage/ai-triage-add-to-case.png
1 parent ce07f4c commit 708f300

16 files changed

+160
-11
lines changed
493 KB
Loading
219 KB
Loading
352 KB
Loading
-12.1 MB
Binary file not shown.
4 MB
Loading
-64.6 KB
Loading

docs/AI-for-security/usecase-alert-triage.asciidoc

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,14 @@ Elastic AI Assistant can help you enhance and streamline your alert triage workf
44

55
When you view an alert in {elastic-sec}, details such as related documents, hosts, and users appear alongside a synopsis of the events that triggered the alert. This data provides a starting point for understanding a potential threat. AI Assistant can answer questions about this data and offer insights and actionable recommendations to remediate the issue.
66

7-
To enable AI Assistant to answer questions about alerts, you need to provide alert data as context for your prompts. You can either provide multiple alerts using the <<ai-assistant-knowledge-base, knowledge base>> feature, or provide individual alerts directly.
7+
To enable AI Assistant to answer questions about alerts, you need to provide alert data as context for your prompts. You can either provide multiple alerts using the <<ai-assistant-knowledge-base, Knowledge Base>> feature, or provide individual alerts directly.
88

99
[[ai-assistant-triage-alerts-knowledge-base]]
1010
[discrete]
1111
== Use AI Assistant to triage multiple alerts
12-
Enable the <<configure-ai-assistant, knowledge base>> **Alerts** setting to send AI Assistant data for up to 100 alerts as context for each of your prompts. With this setting enabled, you can ask AI Assistant questions such as "How many alerts are present in my environment?", "What are my most urgent alerts?", "Which alerts should I triage first?", "Do any of the alerts in my environment indicate data exfiltration from a Windows machine?", and more.
12+
Enable the <<ai-assistant-knowledge-base, Knowledge Base>> **Alerts** setting to send AI Assistant data for up to 500 alerts as context for each of your prompts. With this setting enabled, you can ask AI Assistant questions such as "How many alerts are present in my environment?", "What are my most urgent alerts?", "Which alerts should I triage first?", "Do any of the alerts in my environment indicate data exfiltration from a Windows machine?", and more.
1313

14-
For more information, refer to <<ai-assistant-knowledge-base, knowledge base>>.
14+
For more information, refer to <<ai-assistant-knowledge-base, Knowledge Base>>.
1515

1616
For a demo of AI Assistant's alert triage capabilities, refer to the following video.
1717
=======
@@ -42,7 +42,7 @@ NOTE: For more information about selecting which fields to send, and to learn ab
4242
+
4343
. (Optional) Click a quick prompt to use it as a starting point for your query, for example **Alert summarization**. Improve the quality of AI Assistant's response by customizing the prompt and adding detail.
4444
+
45-
Once youve submitted your query, AI Assistant will process the information and provide a detailed response. Depending on your prompt and the alert data that you included, its response can include a thorough analysis of the alert that highlights key elements such as the nature of the potential threat, potential impact, and suggested response actions.
45+
Once you've submitted your query, AI Assistant will process the information and provide a detailed response. Depending on your prompt and the alert data that you included, its response can include a thorough analysis of the alert that highlights key elements such as the nature of the potential threat, potential impact, and suggested response actions.
4646
+
4747
. (Optional) Ask AI Assistant follow-up questions, provide additional information for further analysis, and request clarification. The response is not a static report.
4848

docs/AI-for-security/usecase-attack-discovery-ai-assistant-incident-reporting.asciidoc

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ Attack discovery can detect a wide range of threats by finding relationships amo
2323

2424
image::images/attck-disc-11-alerts-disc.png[An Attack discovery card showing an attack with 11 related alerts,90%]
2525

26-
In the example above, Attack discovery found connections between nine alerts, and used them to identify and describe an attack chain.
26+
In the example above, Attack discovery found connections between thirteen alerts, and used them to identify and describe an attack chain.
2727

2828
After Attack discovery outlines your threat landscape, use Elastic AI Assistant to quickly analyze a threat in detail.
2929

@@ -33,7 +33,7 @@ After Attack discovery outlines your threat landscape, use Elastic AI Assistant
3333

3434
From a discovery on the Attack discovery page, click **View in AI Assistant** to start a chat that includes the discovery as context.
3535

36-
image::images/attck-disc-remediate-sodinokibi.gif[A dialogue with AI Assistant that has the attack discovery as context,90%]
36+
image::images/attck-disc-remediate-threat.gif[A dialogue with AI Assistant that has the attack discovery as context,90%]
3737

3838
AI Assistant can quickly compile essential data and provide suggestions to help you generate an incident report and plan an effective response. You can ask it to provide relevant data or answer questions, such as “How can I remediate this threat?” or “What {esql} query would isolate actions taken by this user?”
3939

docs/AI-for-security/usecase-esql-queries.asciidoc

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -6,11 +6,7 @@
66
:frontmatter-tags-content-type: [guide]
77
:frontmatter-tags-user-goals: [get-started]
88

9-
Elastic AI Assistant can help you learn about and leverage the Elasticsearch Query Language ({esql}).
10-
11-
With AI Assistant's <<ai-assistant-knowledge-base, {esql} knowledge base>> enabled, AI Assistant benefits from specialized training data that enables it to answer questions related to {esql} at an expert level.
12-
13-
AI Assistant can help with {esql} in many ways, including:
9+
Elastic AI Assistant can help you learn about and leverage the Elasticsearch Query Language ({esql}) in many ways, including:
1410

1511
* **Education and training**: AI Assistant can serve as a powerful {esql} learning tool. Ask it for examples, explanations of complex queries, and best practices.
1612
* **Writing new queries**: Prompt AI Assistant to provide a query that accomplishes a particular task, and it will generate a query matching your description. For example: "Write a query to identify documents with `curl.exe` usage and calculate the sum of `destination.bytes`" or "What query would return all user logins to [a host] in the last six hours?"
Lines changed: 67 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,67 @@
1+
[[security-triage-alerts-with-elastic-ai-assistant]]
2+
= Triage alerts
3+
4+
// :description: Elastic AI Assistant can help you enhance and streamline your alert triage workflows.
5+
// :keywords: security, overview, get-started
6+
7+
Elastic AI Assistant can help you enhance and streamline your alert triage workflows by assessing multiple recent alerts in your environment, and helping you interpret an alert and its context.
8+
9+
When you view an alert in {elastic-sec}, details such as related documents, hosts, and users appear alongside a synopsis of the events that triggered the alert. This data provides a starting point for understanding a potential threat. AI Assistant can answer questions about this data and offer insights and actionable recommendations to remediate the issue.
10+
11+
To enable AI Assistant to answer questions about alerts, you need to provide alert data as context for your prompts. You can either provide multiple alerts using the <<ai-assistant-knowledge-base, Knowledge Base>> feature, or provide individual alerts directly.
12+
13+
[[ai-assistant-triage-alerts-knowledge-base]]
14+
[discrete]
15+
== Use AI Assistant to triage multiple alerts
16+
Enable the <<ai-assistant-knowledge-base, Knowledge Base>> **Alerts** setting to send AI Assistant data for up to 500 alerts as context for each of your prompts. With this setting enabled, you can ask AI Assistant questions such as "How many alerts are present in my environment?", "What are my most urgent alerts?", "Which alerts should I triage first?", "Do any of the alerts in my environment indicate data exfiltration from a Windows machine?", and more.
17+
18+
For more information, refer to <<ai-assistant-knowledge-base, Knowledge Base>>.
19+
20+
For a demo of AI Assistant's alert triage capabilities, refer to the following video.
21+
=======
22+
++++
23+
<script type="text/javascript" async src="https://play.vidyard.com/embed/v4.js"></script>
24+
<img
25+
style="width: 100%; margin: auto; display: block;"
26+
class="vidyard-player-embed"
27+
src="https://play.vidyard.com/v2dQtzmm6SoTFYc7dJzq7m.jpg"
28+
data-uuid="v2dQtzmm6SoTFYc7dJzq7m"
29+
data-v="4"
30+
data-type="inline"
31+
/>
32+
</br>
33+
++++
34+
=======
35+
36+
[discrete]
37+
[[use-ai-assistant-to-triage-an-alert]]
38+
== Use AI Assistant to triage a specific alert
39+
40+
Once you have chosen an alert to investigate:
41+
42+
. Click its **View details** button from the Alerts table.
43+
. In the alert details flyout, click **Chat** to launch the AI assistant. Data related to the selected alert is automatically added to the prompt.
44+
. Click **Alert (from summary)** to view which alert fields will be shared with AI Assistant.
45+
+
46+
NOTE: For more information about selecting which fields to send, and to learn about anonymizing your data, refer to <<security-ai-assistant, AI Assistant>>.
47+
+
48+
. (Optional) Click a quick prompt to use it as a starting point for your query, for example **Alert summarization**. Improve the quality of AI Assistant's response by customizing the prompt and adding detail.
49+
+
50+
Once you've submitted your query, AI Assistant will process the information and provide a detailed response. Depending on your prompt and the alert data that you included, its response can include a thorough analysis of the alert that highlights key elements such as the nature of the potential threat, potential impact, and suggested response actions.
51+
+
52+
. (Optional) Ask AI Assistant follow-up questions, provide additional information for further analysis, and request clarification. The response is not a static report.
53+
54+
[discrete]
55+
[[generate-triage-reports]]
56+
== Generate triage reports
57+
58+
Elastic AI Assistant can streamline the documentation and report generation process by providing clear records of security incidents, their scope and impact, and your remediation efforts. You can use AI Assistant to create summaries or reports for stakeholders that include key event details, findings, and diagrams. Once the AI Assistant has finished analyzing one or more alerts, you can generate reports by using prompts such as:
59+
60+
* “Generate a detailed report about this incident, including timeline, impact analysis, and response actions. Also, include a diagram of events.”
61+
* “Generate a summary of this incident/alert and include diagrams of events.”
62+
* “Provide more details on the mitigation strategies used.”
63+
64+
After you review the report, click **Add to existing case** at the top of AI Assistant's response. This allows you to save a record of the report and make it available to your team.
65+
66+
[role="screenshot"]
67+
image::images/ai-assistant-alert-triage/ai-triage-add-to-case.png[An AI Assistant dialogue with the add to existing case button highlighted]

0 commit comments

Comments
 (0)