diff --git a/docs/detections/images/install-prebuilt-rules.png b/docs/detections/images/install-prebuilt-rules.png new file mode 100644 index 0000000000..21c3a2cf77 Binary files /dev/null and b/docs/detections/images/install-prebuilt-rules.png differ diff --git a/docs/detections/images/install-prebuilt-settings.png b/docs/detections/images/install-prebuilt-settings.png new file mode 100644 index 0000000000..8c7fd7047c Binary files /dev/null and b/docs/detections/images/install-prebuilt-settings.png differ diff --git a/docs/detections/rules-ui-manage.asciidoc b/docs/detections/rules-ui-manage.asciidoc index ade7ae1f9f..6c820f4010 100644 --- a/docs/detections/rules-ui-manage.asciidoc +++ b/docs/detections/rules-ui-manage.asciidoc @@ -6,6 +6,8 @@ On the Detection rules page, you can: * <> * <> +* <> +* <> * <> * <> @@ -56,13 +58,16 @@ To download the latest version of prebuilt rules: . In {kib}, go to *Fleet > Integrations*. . Search for "Prebuilt Security Detection Rules." -. Select the integration, then click *Add Prebuilt Security Detection Rules*. The integration configuration page is displayed. -. (Optional) If you have an {agent} enrolled and have created an agent policy you want to assign to this integration, select it from the drop-down. -. Configure the integration settings by entering a name and optional description. -. Click *Save integration* in the lower right corner. - +. Select the integration, then select the *Settings* tab. The integration settings page is displayed. ++ +[role="screenshot"] +image::images/install-prebuilt-settings.png[] ++ +. Click *Install Prebuilt Security Detection Rules assets*. +. Click *Install Prebuilt Security Detection Rules* to confirm the installation. ++ [role="screenshot"] -image::images/prebuilt-integration.png[] +image::images/install-prebuilt-rules.png[] [float] [[manage-rules-ui]]