Company
Date Published
Author
Aaron Jewitt
Word count
1042
Language
-
Hacker News points
None

Summary

Elastic's Infosec Detections and Analytics team, known as Customer Zero, outlines procedures for configuring the Elastic Security app and Machine Learning jobs to utilize Cross Cluster Search (CCS) effectively. The process involves adjusting the Security app's index patterns to incorporate CCS and modifying the built-in detection rules to use CCS patterns via duplication and bulk editing. For Machine Learning, datafeeds must be updated to adopt CCS patterns, a task requiring API access since it cannot be done directly through the UI. The post emphasizes ensuring all clusters are updated to version 7.14 or newer to support Elastic Query Language with CCS and provides guidance on managing and tracking rules through version updates. The team concludes by hinting at future updates on their ongoing use of Elastic products for security.