diff --git a/docs/detections/rules-cross-cluster-search.asciidoc b/docs/detections/rules-cross-cluster-search.asciidoc index 90c56d7e35..b6a6cf3103 100644 --- a/docs/detections/rules-cross-cluster-search.asciidoc +++ b/docs/detections/rules-cross-cluster-search.asciidoc @@ -3,6 +3,15 @@ {ref}/modules-cross-cluster-search.html[Cross-cluster search] is an {es} feature that allows one cluster (the _local_ cluster) to query data in a separate cluster (the _remote_ cluster). {elastic-sec}'s detection rules can perform a cross-cluster search to query data in remote clusters. +.Requirements +[sidebar] +-- + +* To learn about the requirements for using cross-cluster search, refer to {ref}/modules-cross-cluster-search.html[Search across clusters]. +* Using cross-cluster search for {esql} rules requires an (https://www.elastic.co/pricing)[Enterprise subscription]. + +-- + [discrete] [[set-up-ccs-rules]] === Set up cross-cluster search in detection rules