diff --git a/docs/detections/images/prebuilt-rules-update-diff.png b/docs/detections/images/prebuilt-rules-update-diff.png new file mode 100644 index 0000000000..64f0728409 Binary files /dev/null and b/docs/detections/images/prebuilt-rules-update-diff.png differ diff --git a/docs/detections/prebuilt-rules-management.asciidoc b/docs/detections/prebuilt-rules-management.asciidoc index 5900a9a5d8..8497273d44 100644 --- a/docs/detections/prebuilt-rules-management.asciidoc +++ b/docs/detections/prebuilt-rules-management.asciidoc @@ -96,12 +96,19 @@ Elastic regularly updates prebuilt rules to optimize their performance and ensur + NOTE: The *Rule Updates* tab doesn't appear if all your installed prebuilt rules are up to date. + -TIP: To examine the details of a rule's latest version before you update it, select the rule name. This opens the rule details flyout. -+ [role="screenshot"] image::images/prebuilt-rules-update.png[The Rule Updates tab on the Rules page] -. Do one of the following: +. (Optional) To examine the details of a rule's latest version before you update it, select the rule name. This opens the rule details flyout. ++ +The *Updates* tab displays a side-by-side JSON comparison of the rule's *Base version* (what you currently have installed) and the *Update* version that you can choose to install. Deleted characters are highlighted in red; added characters are highlighted in green. ++ +To accept the changes and install the updated version, select *Update*. ++ +[role="screenshot"] +image::images/prebuilt-rules-update-diff.png[Prebuilt rule comparison,75%] + +. Do one of the following to update prebuilt rules on the *Rules* page: * Update all available rules: Click *Update all*. * Update a single rule: Click *Update rule* for that rule. * Update multiple rules: Select the rules and click *Update _x_ selected rule(s)*.