Skip to content

Commit

Permalink
Update docs/serverless/rules/rules-ui-create.mdx
Browse files Browse the repository at this point in the history
  • Loading branch information
nastasha-solomon authored Jul 16, 2024
1 parent a8dce84 commit 4d7fd6d
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion docs/serverless/rules/rules-ui-create.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -575,7 +575,7 @@ When configuring an ((esql)) rule's **<DocLink slug="/serverless/security/rules-
false-positive alerts.

1. **MITRE ATT&CK<sup>TM</sup> threats** (optional): Add relevant [MITRE](https://attack.mitre.org/) framework tactics, techniques, and subtechniques.
1. **Custom highlighted fields** (optional): Specify highlighted fields for personalized alert investigation flows. You can choose any fields that are available in the you selected for the rule's data source.
1. **Custom highlighted fields** (optional): Specify highlighted fields for unique alert investigation flows. You can choose any fields that are available in the you selected for the rule's data source.

After you create the rule, you can find all custom highlighted fields in the About section of the rule details page. If the rule has alerts, you can find custom highlighted fields in the <DocLink slug="/serverless/security/view-alert-details" section="investigation">Highlighted fields</DocLink> section of the alert details flyout.

Expand Down

0 comments on commit 4d7fd6d

Please sign in to comment.