elastic / security-docs

Elastic Security Documentation
Other
69 stars 183 forks source link

Elastic Security Assistant overview (docs for 8.8.1) #3420

Closed jmikell821 closed 1 year ago

jmikell821 commented 1 year ago

Related issues/PRs:

User Story

Iris, Elastic Security's AI assistant, integrates generative AI and large language models (LLMs) into the workflows of Elastic Security users. Incorporating Generative AI into Elastic Security vastly improves our threat response capability, productivity, and performance, empowering our security teams. The addition saves time on routine tasks, decreases threat resolution time, and heightens workflow efficiency and outcomes.

As a Security Analyst... (note that some of these features are not 100% mature yet)

Prerequisites

This functionality has been introduced behind the assistantEnabled feature flag. Customers need to add this configuration to their kibana.yml or Kibana Cloud User Settings configuration to enable:

xpack.securitySolution.enableExperimental: ['assistantEnabled']

Notes

nastasha-solomon commented 1 year ago

Some additional details I noted down from today's meeting with James: