Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Serverless] [Attack discovery] twin PR for AI IA and AD note update #5512

Merged
merged 11 commits into from
Jul 8, 2024
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
slug: /serverless/security/ai-for-security
title: AI for security
description: Learn about Elastic's native AI security tools.
tags: [ 'serverless', 'security', 'overview', 'LLM', 'artificial intelligence' ]
status: in review
---
You can use Elastic Security’s built-in AI tools to speed up your work and augment your team’s capabilities. The pages in this section describe <DocLink slug="docs/serverless/AI-for-security/ai-assistant.mdx"/>, which answers questions and enhances your workflows throughout Elastic Security, and <DocLink slug="/serverless/security/attack-discovery"/>, which speeds up the triage process by finding patterns and identifying attacks spanning multiple alerts.
benironside marked this conversation as resolved.
Show resolved Hide resolved
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,13 @@ While Attack discovery is compatible with many different models, our testing fou

3. Once you've selected a connector, click **Generate** to start the analysis.

It may take from a few seconds up to several minutes to generate discoveries, depending on the number of alerts and the model you selected. Note that Attack discovery is in technical preview and will only analyze opened and acknowleged alerts from the past 24 hours.
It may take from a few seconds up to several minutes to generate discoveries, depending on the number of alerts and the model you selected.

<DocCallOut title="Important">
Attack discovery is in technical preview and will only analyze opened and acknowleged alerts from the past 24 hours. By default it only analyzes up to 20 alerts within this timeframe, but you can expand this up to 100 by going to **AI Assistant → Settings (<DocIcon type="gear" title="settings icon"/>) → Knowledge Base** and updating the **Alerts** setting.
</DocCallOut>

![AI Assistant knowledge base menu](../images/ai-assistant/assistant-kb-menu.png)


<DocCallOut title="Important">
Expand Down
Loading