[Docs][SIEM] 7.6 updates (#56844)
* adds detections description * 7.6 updated and screenshots
BIN
docs/siem/images/detections-ui.png
Normal file
After Width: | Height: | Size: 303 KiB |
Before Width: | Height: | Size: 150 KiB After Width: | Height: | Size: 410 KiB |
Before Width: | Height: | Size: 406 KiB After Width: | Height: | Size: 710 KiB |
Before Width: | Height: | Size: 109 KiB After Width: | Height: | Size: 501 KiB |
|
@ -33,6 +33,23 @@ investigation.
|
|||
[role="screenshot"]
|
||||
image::siem/images/network-ui.png[]
|
||||
|
||||
[float]
|
||||
[[detections-ui]]
|
||||
=== Detections
|
||||
|
||||
The Detections feature automatically searches for threats and creates
|
||||
signals when they are detected. Signal detection rules define the conditions
|
||||
for creating signals. The SIEM app comes with prebuilt rules that search for
|
||||
suspicious activity on your network and hosts. Additionally, you can
|
||||
create your own rules.
|
||||
|
||||
See {siem-guide}/detection-engine-overview.html[Detections] in the SIEM
|
||||
Guide for information on managing detection rules and signals via the UI
|
||||
or the Detections API.
|
||||
|
||||
[role="screenshot"]
|
||||
image::siem/images/detections-ui.png[]
|
||||
|
||||
[float]
|
||||
[[timelines-ui]]
|
||||
=== Timeline
|
||||
|
|