Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adds new page about triaging alerts with AI Assistant #4359

Merged
merged 32 commits into from
Jan 4, 2024

Conversation

benironside
Copy link
Contributor

@benironside benironside commented Dec 1, 2023

Fixes #4358 by adding a new page that explains how AI Assistant can help triage alerts. RAG for Alerts changes are limited to the new first section "Use AI Assistant to Triage multiple alerts"

Preview: Triage alerts with Elastic AI Assistant

@benironside benironside added Feature: Elastic AI Assistant Interface for interacting with generative AIs v8.11.0 v8.12.0 labels Dec 1, 2023
@benironside benironside self-assigned this Dec 1, 2023
Copy link

github-actions bot commented Dec 1, 2023

Documentation previews:

dhru42
dhru42 previously requested changes Dec 8, 2023
Copy link
Collaborator

@dhru42 dhru42 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please make this a sub-page to the AI Assistant page

@benironside benironside marked this pull request as ready for review December 8, 2023 23:44
@benironside benironside requested a review from a team as a code owner December 8, 2023 23:44
Copy link
Contributor

@nastasha-solomon nastasha-solomon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left some suggestions for consistency and structure. Looks great as a whole!

docs/assistant/ai-alert-triage.asciidoc Outdated Show resolved Hide resolved
docs/assistant/ai-alert-triage.asciidoc Outdated Show resolved Hide resolved
docs/assistant/ai-alert-triage.asciidoc Show resolved Hide resolved
docs/assistant/ai-alert-triage.asciidoc Outdated Show resolved Hide resolved
docs/assistant/ai-alert-triage.asciidoc Outdated Show resolved Hide resolved
docs/assistant/ai-alert-triage.asciidoc Outdated Show resolved Hide resolved
docs/assistant/ai-alert-triage.asciidoc Outdated Show resolved Hide resolved
docs/assistant/ai-alert-triage.asciidoc Outdated Show resolved Hide resolved
docs/assistant/ai-alert-triage.asciidoc Outdated Show resolved Hide resolved
docs/assistant/ai-alert-triage.asciidoc Outdated Show resolved Hide resolved
@benironside benironside requested a review from a team December 13, 2023 19:57
@benironside benironside dismissed dhru42’s stale review December 13, 2023 20:02

Communicated with Dhru and incorporated his feedback 👍


When you view an alert in {elastic-sec}, details such as related documents, hosts, and users appear alongside a synopsis of the events that triggered the alert. This data provides a starting point for understanding a potential threat. AI Assistant can answer questions about this data and offer insights and actionable recommendations to remediate the issue.

To enable AI Assistant to answer questions about alerts, you need to provide alert data as context for your prompts. You can either provide multiple alerts using the <<configure-ai-assistant, knowledge base>> feature, or provide individual alerts directly.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: is it possible for the knowledge base links to jump to a KB-specific anchor? (I'm wondering if it's a quirk of the docs preview)

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes 100%. I am planning to do this but I have to merge the updates to the AI Assistant page before I can link to that section.

Copy link

@andrew-goldstein andrew-goldstein left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @benironside for this new page about triaging alerts with the assistant! 🙏
💹 Desk tested via the preview
LGTM 🚀

@benironside benironside merged commit b930aa6 into main Jan 4, 2024
4 checks passed
mergify bot pushed a commit that referenced this pull request Jan 4, 2024
* Adds new page about triaging alerts with AI Assistant

* troubleshoots ToC

* troubleshoots build error

* updates section title

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Incorporates rest of Nastasha's feedback

* save work

* updates triage page with RAG for alerts info

* fixes anchor tag

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: natasha-moore-elastic <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: natasha-moore-elastic <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

* Update docs/assistant/ai-alert-triage.asciidoc

---------

Co-authored-by: Nastasha Solomon <[email protected]>
Co-authored-by: natasha-moore-elastic <[email protected]>
(cherry picked from commit b930aa6)
mergify bot pushed a commit that referenced this pull request Jan 4, 2024
* Adds new page about triaging alerts with AI Assistant

* troubleshoots ToC

* troubleshoots build error

* updates section title

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Incorporates rest of Nastasha's feedback

* save work

* updates triage page with RAG for alerts info

* fixes anchor tag

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: natasha-moore-elastic <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: natasha-moore-elastic <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

* Update docs/assistant/ai-alert-triage.asciidoc

---------

Co-authored-by: Nastasha Solomon <[email protected]>
Co-authored-by: natasha-moore-elastic <[email protected]>
(cherry picked from commit b930aa6)
benironside added a commit that referenced this pull request Jan 4, 2024
* Adds new page about triaging alerts with AI Assistant

* troubleshoots ToC

* troubleshoots build error

* updates section title

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Incorporates rest of Nastasha's feedback

* save work

* updates triage page with RAG for alerts info

* fixes anchor tag

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: natasha-moore-elastic <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: natasha-moore-elastic <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

* Update docs/assistant/ai-alert-triage.asciidoc

---------

Co-authored-by: Nastasha Solomon <[email protected]>
Co-authored-by: natasha-moore-elastic <[email protected]>
(cherry picked from commit b930aa6)

Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
benironside added a commit that referenced this pull request Jan 9, 2024
…#4359) (#4565)

* Adds new page about triaging alerts with AI Assistant (#4359)

* Adds new page about triaging alerts with AI Assistant

* troubleshoots ToC

* troubleshoots build error

* updates section title

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: Nastasha Solomon <[email protected]>

* Incorporates rest of Nastasha's feedback

* save work

* updates triage page with RAG for alerts info

* fixes anchor tag

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: natasha-moore-elastic <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

Co-authored-by: natasha-moore-elastic <[email protected]>

* Update docs/assistant/ai-alert-triage.asciidoc

* Update docs/assistant/ai-alert-triage.asciidoc

---------

Co-authored-by: Nastasha Solomon <[email protected]>
Co-authored-by: natasha-moore-elastic <[email protected]>
(cherry picked from commit b930aa6)

* removes part from 8.11 that doesn't apply until 8.12

* fix merge conflict

---------

Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature: Elastic AI Assistant Interface for interacting with generative AIs v8.11.0 v8.12.0
Projects
Development

Successfully merging this pull request may close these issues.

[AI Assistant] New page - Triage alerts with AI Assistant
5 participants