diff --git a/docs/detections/building-block-rule.asciidoc b/docs/detections/building-block-rule.asciidoc index acac04d7f4..a897539f87 100644 --- a/docs/detections/building-block-rule.asciidoc +++ b/docs/detections/building-block-rule.asciidoc @@ -10,6 +10,8 @@ in the UI. This is useful when you want: You can then use building block rules to create hidden alerts that act as a basis for an 'ordinary' rule to generate visible alerts. +TIP: Add <> to building block rules to notify you when building block alerts are generated. + [float] === Set up rules that run on alert indices