11[role="xpack"]
22[[ootb-ml-jobs-siem]]
3- = SIEM {anomaly-detect} configurations
3+ = Security {anomaly-detect} configurations
44++++
5- <titleabbrev>SIEM </titleabbrev>
5+ <titleabbrev>Security </titleabbrev>
66++++
77
88These {anomaly-jobs} appear by default in the Anomaly Detection interface of
9- the {security-guide}/machine-learning.html[SIEM app] in {kib}. They help you
10- automatically detect file system and network anomalies on your hosts. However,
11- if you don't use Beats, you need to map your data to the ECS fields that are
12- listed for every job.
9+ the {security-guide}/machine-learning.html[Elastic Security app] in {kib}. They
10+ help you automatically detect file system and network anomalies on your hosts.
11+ However, if you don't use Beats, you need to map your data to the ECS fields
12+ that are listed for every job.
1313
1414// tag::siem-jobs[]
1515For more details, see the
@@ -18,7 +18,7 @@ https://github.com/elastic/kibana/tree/{branch}/x-pack/plugins/ml/server/models/
1818
1919[discrete]
2020[[security-auditbeat-jobs]]
21- == SIEM {auditbeat}
21+ == Security {auditbeat}
2222
2323Detect suspicious network activity and unusual processes in {auditbeat} data.
2424
@@ -224,7 +224,7 @@ Required ECS fields when not using {beats}:::
224224
225225[discrete]
226226[[security-auditbeat-authentication-jobs]]
227- == SIEM {auditbeat} authentication
227+ == Security {auditbeat} authentication
228228
229229Detect suspicious authentication events in {auditbeat} data.
230230
@@ -370,7 +370,7 @@ Required ECS fields when not using {beats}:::
370370
371371[discrete]
372372[[security-packetbeat-jobs]]
373- == SIEM {packetbeat}
373+ == Security {packetbeat}
374374
375375Detect suspicious network activity in {packetbeat} data.
376376
@@ -544,7 +544,7 @@ Required ECS fields when not using {beats}:::
544544
545545[discrete]
546546[[security-winlogbeat-jobs]]
547- == SIEM {winlogbeat}
547+ == Security {winlogbeat}
548548
549549Detect unusual processes and network activity in {winlogbeat} data.
550550
@@ -812,7 +812,7 @@ Required ECS fields when not using {beats}:::
812812
813813[discrete]
814814[[security-winlogbeat-authentication-jobs]]
815- == SIEM {winlogbeat} authentication
815+ == Security {winlogbeat} authentication
816816
817817Detect suspicious authentication events in {winlogbeat} data.
818818
0 commit comments