Skip to content

[Request] Attack Discovery Alert Filtering #363

Closed
@dhru42

Description

@dhru42

Description

What: We're introducing the ability for users to select which alerts are included as context to LLMs via Attack Discovery

Why: Currently users can only select the number of alerts that are sent as context to LLMs (slider between 50-500) where we would send the most recent alerts. Now, users can control which alerts get sent as well as the time window (previously fixed to Last 24hrs). This makes attack discovery usable for past alerts and find coorelations between specific alerts.

Background & resources

Which documentation set does this change impact?

ESS and serverless

ESS release

8.18

Serverless release

TBD

Feature differences

n.a

API docs impact

TBD

Prerequisites, privileges, feature flags

TBD

Metadata

Metadata

Assignees

Labels

Team:SecurityIssues owned by the Security Docs Team

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions