Skip to content

Update the ML requirements in the prebuilt rules reference page #1264

Open
@sodhikirti07

Description

@sodhikirti07

Description

The prebuilt rules reference page lacks some of the necessary requirements for running ML-based prebuilt rules. To prevent any confusion, it should include the same requirements outlined in the Machine learning jobs and rules requirements page.

The requirements should be something like below:

To run and create machine learning rules in serverless, you need the appropriate user role. In Elastic Stack, you need all of these:

  • The appropriate license
  • There must be at least one machine learning node in your cluster
  • The machine_learning_admin user role

Additionally, to configure alert suppression for machine learning rules, your role needs the following index privilege:

Related Issue:

Metadata

Metadata

Labels

Team:SecurityIssues owned by the Security Docs Team

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions