Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
43 commits
Select commit Hold shift + click to select a range
27fa465
found a few more spots to update
yctercero Nov 11, 2025
778dcb9
forgot that the docs will go out to both ECH and serverless
yctercero Nov 11, 2025
334f0a2
fixing formatting
yctercero Nov 11, 2025
b1ebe09
Merge branch 'main' into update_rbac_docs
yctercero Nov 11, 2025
c7e29ac
Apply suggestions from code review
benironside Nov 13, 2025
37cb097
Clarify RBAC privileges for Attack Discovery
yctercero Nov 19, 2025
a7f7720
Merge branch 'main' into update_rbac_docs
nastasha-solomon Nov 25, 2025
d11d81f
Merge branch 'main' into update_rbac_docs
nastasha-solomon Nov 25, 2025
8614753
Merge branch 'main' into update_rbac_docs
nastasha-solomon Nov 25, 2025
3a510c7
Merge branch 'main' into update_rbac_docs
nastasha-solomon Nov 26, 2025
95b4657
Update solutions/security/detect-and-alert/detections-requirements.md
nastasha-solomon Dec 12, 2025
d18ad5f
Update solutions/security/detect-and-alert/detections-requirements.md
yctercero Dec 12, 2025
e4a37c1
Update solutions/security/detect-and-alert/detections-requirements.md
yctercero Dec 12, 2025
bfe96e1
Update solutions/security/investigate/notes.md
yctercero Dec 12, 2025
7321ec7
Update solutions/security/investigate/timeline.md
yctercero Dec 12, 2025
5c4f663
Merge branch 'main' of github.com:elastic/docs-content into update_rb…
yctercero Dec 13, 2025
379f918
Removing non detections info from detections requirements
yctercero Dec 13, 2025
e1a35b3
Fixed formatting
yctercero Dec 13, 2025
466392d
Merge branch 'main' into update_rbac_docs
nastasha-solomon Dec 15, 2025
e2a567c
Update solutions/security/detect-and-alert/detections-requirements.md
nastasha-solomon Dec 15, 2025
bc6281a
Update solutions/security/detect-and-alert/detections-requirements.md
nastasha-solomon Dec 15, 2025
31d19f6
Update solutions/security/detect-and-alert/detections-requirements.md
nastasha-solomon Dec 15, 2025
11daada
Update solutions/security/detect-and-alert/detections-requirements.md
nastasha-solomon Dec 15, 2025
858c36b
Update solutions/security/detect-and-alert/detections-requirements.md
nastasha-solomon Dec 15, 2025
ec3e42e
Update solutions/security/detect-and-alert/detections-requirements.md
nastasha-solomon Dec 15, 2025
daf9198
Update solutions/security/detect-and-alert/detections-requirements.md
nastasha-solomon Dec 15, 2025
f872496
tags
nastasha-solomon Dec 15, 2025
afe3d5a
moving content to applies to switch tab
nastasha-solomon Dec 15, 2025
d160f56
plz work
nastasha-solomon Dec 15, 2025
23fea71
Merge branch 'main' into update_rbac_docs
nastasha-solomon Dec 16, 2025
d690a9d
attack discovery privs
nastasha-solomon Dec 16, 2025
a60b69d
Merge branch 'update_rbac_docs' of https://github.com/yctercero/docs-…
nastasha-solomon Dec 16, 2025
6120251
Re-added images
nastasha-solomon Dec 16, 2025
8ec99d4
Revisions and links
nastasha-solomon Dec 16, 2025
6f947f6
Removed req for rule privs
nastasha-solomon Dec 16, 2025
4bda5db
Removed notes about other SIEM features
nastasha-solomon Dec 16, 2025
13ec788
Removed extra spaces
nastasha-solomon Dec 16, 2025
0638265
Merge branch 'main' into update_rbac_docs
nastasha-solomon Dec 16, 2025
594f0a0
Update solutions/security/ai/attack-discovery.md
nastasha-solomon Dec 16, 2025
6d82e66
Update solutions/security/get-started/automatic-migration.md
nastasha-solomon Dec 16, 2025
4ae4c20
Merge branch 'main' into update_rbac_docs
nastasha-solomon Dec 16, 2025
6c86913
Merge branch 'main' into update_rbac_docs
nastasha-solomon Dec 16, 2025
7c0ea07
Merge branch 'main' into update_rbac_docs
nastasha-solomon Dec 17, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
42 changes: 40 additions & 2 deletions solutions/security/ai/attack-discovery.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,18 +22,56 @@

## Role-based access control (RBAC) for Attack Discovery [attack-discovery-rbac]

You need the `Attack Discovery: All` privilege to use Attack Discovery.
To use Attack Discovery, your role needs specific privileges.

::::{applies-switch}

:::{applies-item} { "stack": "ga 9.0" }

Ensure your role has `All` [{{kib}} privileges](../../../deploy-manage/users-roles/cluster-or-deployment-auth/kibana-role-management.md) for the **Security > Attack Discover** {{kib}} feature.

![attack-discovery-rbac](/solutions/images/security-attck-disc-rbac.png)

{applies_to}`stack: ga 9.1` Your role must also have the following privileges:
:::

:::{applies-item} { "stack": "ga 9.1"}

Ensure your role has:

* `All` [{{kib}} privileges](../../../deploy-manage/users-roles/cluster-or-deployment-auth/kibana-role-management.md) for the **Security > Attack Discover** {{kib}} feature.

![attack-discovery-rbac](/solutions/images/security-attck-disc-rbac.png)

* The appropriate [index privileges](../../../deploy-manage/users-roles/cluster-or-deployment-auth/kibana-role-management.md#adding_index_privileges), based on what you want to do with Attack Discovery alerts:

| Action | Indices | {{es}} privileges |
|---------|---------|--------------------------|
| Read Attack Discovery alerts | - `.alerts-security.attack.discovery.alerts-<space-id>`<br>- `.internal.alerts-security.attack.discovery.alerts-<space-id>`<br> - `.adhoc.alerts-security.attack.discovery.alerts-<space-id>`<br>- `.internal.adhoc.alerts-security.attack.discovery.alerts-<space-id>`| `read` and `view_index_metadata` |
| Read and modify Attack Discovery alerts. This includes:<br>- Generating discovery alerts manually<br>- Generating discovery alerts using schedules<br>- Sharing manually created alerts with other users<br>- Updating a discovery's status |- `.alerts-security.attack.discovery.alerts-<space-id>`<br>- `.internal.alerts-security.attack.discovery.alerts-<space-id>`<br>- `.adhoc.alerts-security.attack.discovery.alerts-<space-id>`<br>- `.internal.adhoc.alerts-security.attack.discovery.alerts-<space-id>`| `read`, `view_index_metadata`, `write`, and `maintenance`|

:::

:::{applies-item} { "stack": "ga 9.3", "serverless": "ga" }

Ensure your role has:

* `All` [{{kib}} privileges](../../../deploy-manage/users-roles/cluster-or-deployment-auth/kibana-role-management.md) for the **Security > Attack Discover** {{kib}} feature and at least `Read` privileges for the **Security > Rules** {{kib}} feature.

![attack-discovery-rules-rbac](/solutions/images/attack-discovery-rules-rbac.png "elasticsearch =60%x60%")

* The appropriate [index privileges](../../../deploy-manage/users-roles/cluster-or-deployment-auth/kibana-role-management.md#adding_index_privileges), based on what you want to do with Attack Discovery alerts:

| Action | Indices | {{es}} privileges |
|---------|---------|--------------------------|
| Read Attack Discovery alerts | - `.alerts-security.attack.discovery.alerts-<space-id>`<br>- `.internal.alerts-security.attack.discovery.alerts-<space-id>`<br> - `.adhoc.alerts-security.attack.discovery.alerts-<space-id>`<br>- `.internal.adhoc.alerts-security.attack.discovery.alerts-<space-id>`| `read` and `view_index_metadata` |
| Read and modify Attack Discovery alerts. This includes:<br>- Generating discovery alerts manually<br>- Generating discovery alerts using schedules<br>- Sharing manually created alerts with other users<br>- Updating a discovery's status |- `.alerts-security.attack.discovery.alerts-<space-id>`<br>- `.internal.alerts-security.attack.discovery.alerts-<space-id>`<br>- `.adhoc.alerts-security.attack.discovery.alerts-<space-id>`<br>- `.internal.adhoc.alerts-security.attack.discovery.alerts-<space-id>`| `read`, `view_index_metadata`, `write`, and `maintenance`|

:::

::::


## Set up Attack Discovery

Check notice on line 74 in solutions/security/ai/attack-discovery.md

View workflow job for this annotation

GitHub Actions / preview / vale

Elastic.Capitalization: 'Set up Attack Discovery' should use sentence-style capitalization.

By default, Attack Discovery analyzes up to 100 alerts from the last 24 hours, but you can customize how many and which alerts it analyzes using the settings menu. To open it, click the settings icon next to the **Run** button.

Expand Down
Loading
Loading