Skip to content

Commit 64eb7e7

Browse files
author
Ben Skelker
committed
adds promoted endpoint events
1 parent 8b62604 commit 64eb7e7

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

docs/siem/detections/detection-engine-intro.asciidoc

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,12 @@ There are two special prebuilt rules you need to know about:
3030
Elastic Endpoint alerts. To receive Elastic Endpoint alerts, you must install
3131
the Endpoint agent on your hosts (BEN: see xref).
3232
+
33+
When this rule is enabled, the following Endpoint events are displayed as
34+
detection alerts:
35+
+
36+
** Malware Prevention Alert
37+
** Malware Detection Alert
38+
+
3339
NOTE: When you load the prebuilt rules, this is the only rule that is enabled
3440
by default.
3541

0 commit comments

Comments
 (0)