Skip to content

Commit c1b51e0

Browse files
authored
Merge branch 'master' into ml-reuse
2 parents 19090df + 9d5eefc commit c1b51e0

14 files changed

+162
-18
lines changed

docs/index.asciidoc

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,10 @@
1+
:doctype: book
2+
:siem-soln: Elastic Security
3+
:siem-app: Elastic Security app
4+
:siem-ui: Elastic Security UI
5+
:ml-dir: {stack-docs-root}/docs/en/stack/ml
6+
:sn: ServiceNow
7+
18
[[elastic-endpoint]]
29
= Elastic Endpoint Security
310

@@ -14,4 +21,9 @@ include::{asciidoc-dir}/../../shared/attributes.asciidoc[]
1421
include::sensor-full-disk-access.asciidoc[]
1522

1623
// Temporary fix of section levels
17-
include::siem/index.asciidoc[leveloffset=+1]
24+
include::siem/index.asciidoc[]
25+
26+
include::siem-apis.asciidoc[]
27+
28+
include::siem/reference/ref-index.asciidoc[]
29+

docs/siem/siem-apis.asciidoc renamed to docs/siem-apis.asciidoc

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,11 @@
11
[role="xpack"]
2-
[[siem-apis]]
3-
= SIEM APIs
2+
[[security-apis]]
3+
= Elastic Security APIs
44

55
You can use these APIs to interface with {siem-soln} features:
66

77
* <<rule-api-overview>>: Manage detection rules and signals
8+
* <<timeline-api-overview>>: Import and export timelines
89
* <<cases-api-overview>>: Open and manage cases
910

1011
Additionally, the {kib} <<actions-api-overview, Actions API>> is partially
@@ -70,8 +71,10 @@ path component to its URL.
7071
{kibana-ref}/development-basepath.html[Considerations for basePath] describes
7172
how to work with and disable the random path component.
7273

73-
include::detections/api/det-api-index.asciidoc[]
74+
include::siem/detections/api/det-api-index.asciidoc[]
7475

75-
include::cases/api/cases-api/cases-api-index.asciidoc[]
76+
include::siem/timeline/api/timeline-api-index.asciidoc[]
7677

77-
include::cases/api/actions-api/cases-actions-api-index.asciidoc[]
78+
include::siem/cases/api/cases-api/cases-api-index.asciidoc[]
79+
80+
include::siem/cases/api/actions-api/cases-actions-api-index.asciidoc[]

docs/siem/detections/api/rules-api-export.asciidoc

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,8 @@ exported rules is returned.|No, defaults to `false`.
2222
`export.ndjson`
2323
|==============================================
2424

25-
TIP: When using cURL to export rules to a file, use the `-O` and `-J` options to save the rules to the file name specified in the URL.
25+
TIP: When using cURL to export rules to a file, use the `-O` and `-J` options
26+
to save the rules to the file name specified in the URL.
2627

2728
==== Request body
2829

docs/siem/detections/machine-learning/machine-learning.asciidoc

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -76,3 +76,4 @@ NOTE: Some jobs use fields that are not ECS-compliant. These jobs are only
7676
available when you use {beats} to ship data.
7777

7878
include::{stack-docs-root}/docs/en/stack/ml/anomaly-detection/ootb-ml-jobs-siem.asciidoc[tag=siem-jobs]
79+

docs/siem/index.asciidoc

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
1-
:doctype: book
2-
:siem-soln: SIEM
3-
:siem-app: SIEM app
4-
:siem-ui: SIEM UI
5-
:ml-dir: {stack-docs-root}/docs/en/stack/ml
6-
:sn: ServiceNow
1+
// :doctype: book
2+
// :siem-soln: Elastic Security
3+
// :siem-app: Elastic Security app
4+
// :siem-ui: Elastic Security UI
5+
// :ml-dir: {stack-docs-root}/docs/en/stack/ml
6+
// :sn: ServiceNow
77

88
// Removed for merging with unified security docs
99
// = SIEM Guide
@@ -24,6 +24,6 @@ include::detections/detections-index.asciidoc[]
2424

2525
include::cases/cases-index.asciidoc[]
2626

27-
include::siem-apis.asciidoc[]
27+
// include::siem-apis.asciidoc[]
2828

29-
include::field-ref.asciidoc[]
29+
// include::reference/ref-index.asciidoc[]

docs/siem/field-ref.asciidoc renamed to docs/siem/reference/field-ref.asciidoc

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[[siem-field-reference]]
2-
[chapter, role="xpack"]
3-
= SIEM field reference guide
2+
[role="xpack"]
3+
== Elastic Security ECS field reference
44

5-
This section lists ECS fields the {siem-app} uses to display data.
5+
This section lists ECS fields Elastic Security uses to display data.
66

77
IMPORTANT: It is recommended to use {beats} to ship your data. Beat modules
88
(for example, {filebeat-ref}/filebeat-modules.html[{filebeat} modules])
128 KB
Loading
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
include::ref-intro.asciidoc[]
2+
3+
include::field-ref.asciidoc[]
4+
5+
include::timeline-schema.asciidoc[]
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
[[security-ref-intro]]
2+
[role="xpack"]
3+
= Elastic Security fields and object schemas
4+
5+
This reference section provides details on the ECS fields Elastic Security uses
6+
to display data in the UI and Elastic Security JSON object schemas:
7+
8+
* <<siem-field-reference, ECS fields the used to display data>>
9+
* <<timeline-object-schema, Timeline object schema>>
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
[[timeline-object-schema]]
2+
[role="xpack"]
3+
== Timeline schema
4+

0 commit comments

Comments
 (0)