Skip to content

Commit 0f33d13

Browse files
natasha-moore-elasticnaemono
authored andcommitted
[Security] Advanced setting for ES|QL risk scoring (elastic#3525)
Resolves elastic#3418 by documenting the Security advanced setting for turning off ES|QL-based risk scoring. Preview: [Turn off ES|QL-based risk scoring](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/3525/solutions/security/get-started/configure-advanced-settings#turn-off-esql-based-risk-scoring)
1 parent 3afd8d6 commit 0f33d13

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

solutions/security/get-started/configure-advanced-settings.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -252,3 +252,9 @@ serverless: ga
252252

253253
The `securitySolution:enablePrivilegedUserMonitoring` setting allows you to access the [Entity analytics overview page](/solutions/security/advanced-entity-analytics/overview.md) and the [privileged user monitoring](/solutions/security/advanced-entity-analytics/privileged-user-monitoring.md) feature. This setting is turned off by default.
254254

255+
## Turn off {{esql}}-based risk scoring
256+
```yaml {applies_to}
257+
stack: ga 9.2
258+
serverless: ga
259+
```
260+
By default, [entity risk scoring](/solutions/security/advanced-entity-analytics/entity-risk-scoring.md) calculations are based on {{esql}} queries. Turn off `securitySolution:enableEsqlRiskScoring` to use scripted metrics instead.

0 commit comments

Comments
 (0)