Conversation
🔍 Preview links for changed docs |
✅ Vale Linting ResultsNo issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
| :screenshot: | ||
| ::: | ||
|
|
||
| ### Retention [siem-readiness-retention] |
There was a problem hiding this comment.
We should add that for Serverless, ILMs do not exist, its DSL only
| :screenshot: | ||
| ::: | ||
|
|
||
| ### Continuity [siem-readiness-continuity] |
There was a problem hiding this comment.
We might need to mention that the stats for ingested docs and thus also failure rates are missing in serverless
|
|
||
| The Quality pillar answers: *Is your data ECS-compatible?* Schema errors can prevent rules, dashboards, and other features from working correctly. | ||
|
|
||
| It checks your indices for [Elastic Common Schema (ECS)](ecs://reference/ecs-event.md) compatibility issues and missing fields. It groups indices by data category (such as Endpoint, Identity, Network, and Cloud), and each category shows: |
There was a problem hiding this comment.
Application/SaaS is the 5th category of data, please mention it in here and also describe the 5 categories under Data coverage section. @benironside
SIEM Readiness Page — Required PrivilegesKibana Privileges
Elasticsearch Index PrivilegesThese must be granted on the relevant indices (
Elasticsearch Cluster Privileges
Per-Tab Breakdown
Notes
|
Dismissing Smriti's review since I incorporated her request and she validated it over Slack/
Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Summary
Documents the new SIEM Readiness launchpad feature in Elastic Sec. Fixes #5513
Generative AI disclosure