diff --git a/docs/cases/indicators-of-compromise.asciidoc b/docs/cases/indicators-of-compromise.asciidoc index 368d69be4f..850571477c 100644 --- a/docs/cases/indicators-of-compromise.asciidoc +++ b/docs/cases/indicators-of-compromise.asciidoc @@ -1,7 +1,7 @@ [[indicators-of-compromise]] = Indicators of compromise -The Indicators page (*Intelligence -> Indicators*) collects data from enabled threat intelligence feeds and provides a centralized view of indicators, also known as indicators of compromise (IoCs). This topic helps you set up the Indicators page and explains how to work with IoCs. +The Indicators page collects data from enabled threat intelligence feeds and provides a centralized view of indicators, also known as indicators of compromise (IoCs). This topic helps you set up the Indicators page and explains how to work with IoCs. .Requirements [sidebar] @@ -31,7 +31,8 @@ Install a threat intelligence integration to add indicators to the Indicators pa . Choose one of the following: * From the {security-app} main menu, go to *Intelligence* -> *Indicators* -> *Add Integrations*. -* From the {kib} main menu, click *Add integrations*. In the search bar, search for `Threat Intelligence` to get a list of threat intelligence integrations. +* From the {kib} main menu, click *Add integrations*. +. In the search bar, search for `Threat Intelligence` to get a list of threat intelligence integrations. . Select a threat intelligence integration, then complete the integration's guided installation. + NOTE: For more information about available fields, go to the https://docs.elastic.co/integrations[Elastic integration documentation] and search for a specific threat intelligence integration.