Skip to content
Merged
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions docs/detections/rules-cross-cluster-search.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,12 @@

{ref}/modules-cross-cluster-search.html[Cross-cluster search] is an {es} feature that allows one cluster (the _local_ cluster) to query data in a separate cluster (the _remote_ cluster). {elastic-sec}'s detection rules can perform a cross-cluster search to query data in remote clusters.

.Requirements
[sidebar]
--
Using cross-cluster search for {esql} rules requires an https://www.elastic.co/pricing[Enterprise subscription]. Refer to {ref}/modules-cross-cluster-search.html[Search across clusters] to learn more about cross-cluster search requirements.
--

[discrete]
[[set-up-ccs-rules]]
=== Set up cross-cluster search in detection rules
Expand Down