Skip to content
Merged
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 1 addition & 3 deletions docs/detections/detection-engine-intro.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -68,13 +68,12 @@ To make sure you can access Detections and manage rules, see
Cold tier is a {ref}/data-tiers.html[data tier] that holds time series data that is accessed only occasionally. In {stack} version >=7.11.0, {es-sec} supports cold tier data for the following {es} indices:

* Index patterns specified in `securitySolution:defaultIndex`
* Index patterns specified in the definitions of detection rules, except for indicator match rules
* Index patterns specified in the definitions of detection rules
* Index patterns specified in the data sources selector on various {es-sec-app} pages

{es-sec} does *NOT* support cold tier data for the following {es} indices:

* Index patterns controlled by {elastic-sec}, including alerts and list indices
* Index patterns specified in indicator match rules

Using cold tier data for unsupported indices may result in detection rule timeouts and overall performance degradation.

Expand All @@ -87,7 +86,6 @@ Indicator match rules provide a powerful capability to search your security data
In addition, the following support restrictions are in place:

* {es-sec} does not support the use of frozen tier data with indicator match rules.
* The use of cross-cluster search with indicator match rules is not supported.
* Indicator match rules with an additional look-back time value greater than 24 hours are not supported.

[float]
Expand Down