Skip to content

Commit c6e359d

Browse files
alaudazzirhr323
authored andcommitted
Add missing step to the "How to add non-ECS fields to Attack Discovery" procedure (elastic#3524)
Closes elastic#3504.
1 parent ef6e5cb commit c6e359d

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

solutions/security/ai/attack-discovery.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,7 @@ Attack Discovery is designed for use with alerts based on data that complies wit
5454
1. Select an alert with some of the non-ECS fields you want to analyze, and go to its details flyout. From here, use the **Ask AI Assistant** button to open AI Assistant.
5555
2. At the bottom of the chat window, the alert's information appears. Click **Edit** to open the anonymization window to this alert's fields.
5656
3. Search for and select the non-ECS fields you want Attack Discovery to analyze. Set them to **Allowed**.
57+
4. Check the `Update presets` box to add the allowed fields to the space's default anonymization settings.
5758

5859
The selected fields can now be analyzed the next time you run Attack Discovery.
5960
:::

0 commit comments

Comments
 (0)