diff --git a/docs/management/admin/automated-response-actions.asciidoc b/docs/management/admin/automated-response-actions.asciidoc index b1ee3c0c48..ec339f1731 100644 --- a/docs/management/admin/automated-response-actions.asciidoc +++ b/docs/management/admin/automated-response-actions.asciidoc @@ -14,13 +14,13 @@ Add {elastic-defend}'s <> to detection rules * Automated response actions require an https://www.elastic.co/pricing[Enterprise subscription]. * Hosts must have {agent} installed with the {elastic-defend} integration. * Your user role must have the ability to create detection rules and the privilege to perform <> (for example, the **Host Isolation** privilege to isolate hosts). -* You can only add automated response actions to custom query rules. +* You can only add automated response actions to <>, <>, <>, and <> type rules. -- -You can add automated response actions to a new or existing custom query rule. +To add automated response actions to a new or existing rule: . Do one of the following: -* *New rule*: On the last step of <> creation, go to the **Response Actions** section and select **{elastic-defend}**. +* *New rule*: On the last step of rule creation, go to the **Response Actions** section and select **{elastic-defend}**. * *Existing rule*: Edit the rule's settings, then go to the *Actions* tab. In the tab, select **{elastic-defend}** under the **Response Actions** section. . Select an option in the **Response action** field: