Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 1 addition & 3 deletions docs/detections/detection-engine-intro.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -68,13 +68,12 @@ To make sure you can access Detections and manage rules, see
Cold tier is a {ref}/data-tiers.html[data tier] that holds time series data that is accessed only occasionally. In {stack} version >=7.11.0, {es-sec} supports cold tier data for the following {es} indices:

* Index patterns specified in `securitySolution:defaultIndex`
* Index patterns specified in the definitions of detection rules, except for indicator match rules
* Index patterns specified in the definitions of detection rules
* Index patterns specified in the data sources selector on various {es-sec-app} pages

{es-sec} does *NOT* support cold tier data for the following {es} indices:

* Index patterns controlled by {elastic-sec}, including alerts and list indices
* Index patterns specified in indicator match rules

Using cold tier data for unsupported indices may result in detection rule timeouts and overall performance degradation.

Expand All @@ -87,7 +86,6 @@ Indicator match rules provide a powerful capability to search your security data
In addition, the following support restrictions are in place:

* {es-sec} does not support the use of frozen tier data with indicator match rules.
* The use of cross-cluster search with indicator match rules is not supported.
* Indicator match rules with an additional look-back time value greater than 24 hours are not supported.

[float]
Expand Down