Skip to content
Merged
Changes from 4 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions docs/detections/rules-cross-cluster-search.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,15 @@

{ref}/modules-cross-cluster-search.html[Cross-cluster search] is an {es} feature that allows one cluster (the _local_ cluster) to query data in a separate cluster (the _remote_ cluster). {elastic-sec}'s detection rules can perform a cross-cluster search to query data in remote clusters.

.Requirements
[sidebar]
--

* To learn about the requirements for using cross-cluster search, refer to {ref}/modules-cross-cluster-search.html[Search across clusters].
* Using cross-cluster search for {esql} rules requires an [Enterprise subscription](https://www.elastic.co/pricing).

--

[discrete]
[[set-up-ccs-rules]]
=== Set up cross-cluster search in detection rules
Expand Down