Skip to content

Commit

Permalink
Prebuilt rule customization - per-field rule diffs (classic ESS) (#4871
Browse files Browse the repository at this point in the history
…) (#4873)

* Update prebuilt-rules-update-diff.png

* Update prebuilt-rules-management.asciidoc

* Update docs/detections/prebuilt-rules-management.asciidoc

(cherry picked from commit daf5aba)

Co-authored-by: Joe Peeples <[email protected]>
  • Loading branch information
mergify[bot] and joepeeples authored Mar 5, 2024
1 parent 537a440 commit 1e0f67a
Show file tree
Hide file tree
Showing 2 changed files with 1 addition and 1 deletion.
Binary file modified docs/detections/images/prebuilt-rules-update-diff.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
2 changes: 1 addition & 1 deletion docs/detections/prebuilt-rules-management.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -101,7 +101,7 @@ image::images/prebuilt-rules-update.png[The Rule Updates tab on the Rules page]

. (Optional) To examine the details of a rule's latest version before you update it, select the rule name. This opens the rule details flyout.
+
The *Updates* tab displays a side-by-side JSON comparison of the rule's *Base version* (what you currently have installed) and the *Update* version that you can choose to install. Deleted characters are highlighted in red; added characters are highlighted in green.
Select the *Updates* tab to view rule changes field by field, or the *JSON view* tab to view changes for the entire rule in JSON format. Both tabs display side-by-side comparisons of the *Current rule* (what you currently have installed) and the *Elastic update* version (what you can choose to install). Deleted characters are highlighted in red; added characters are highlighted in green.
+
To accept the changes and install the updated version, select *Update*.
+
Expand Down

0 comments on commit 1e0f67a

Please sign in to comment.