elastic / elastic/docs-content

[Security][DE] Addition of API to initialize the security solution

Open
#7,546 1 comment 0 reactions 1 assignee Claimed by @nastasha-solomon View on GitHub
Team:SKI
Dominant language
No language data
Stars
47
Forks
261
Avg merge
3d 12h
Merged PRs (30d)
116

Description

# Summary
The endpoint was added in https://github.com/elastic/kibana/pull/258891 for 9.4 and its API docs have bee added in https://github.com/elastic/kibana/pull/279526

Today we are [instructing](https://www.elastic.co/docs/solutions/security/detect-and-alert/turn-on-detections) users to navigate to the Detection rules (SIEM) page to "turn on detections" The page. The instructions are unclear on the fact that the user navigating there needed to have the right privileges to initialize the security solution. With the new endpoint, it is no longer necessary that someone with elevated privileges navigate to the detections page. Now anybody going there should trigger the initialization if it has not happened yet.

Therefore it is unclear if we should even have that "Turn on detections" section at all.

One caveat though, for MSNPs or API only users, we might want them to call the endpoint with all the available flows in order to trigger the initialization of the security solution before doing anything with rules and alerts.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.