Before you begin

Before you can create and run detection rules, turn on detections and make sure your users have the privileges they need. If you're new to Elastic Security detections, check out Detection rule concepts for an overview of how rules work.

These tasks are typically completed once when you first configure detection capabilities:

  • Turn on detections: Enable the Detections feature for your deployment type. On Serverless, detections are on by default.
  • Detections privileges: Give users the cluster, index, and Kibana privileges they need for detection features. When your team changes, review these privileges again in Access control.

Advanced data source configuration covers cross-cluster search setup, data tier exclusions, and index mode settings. Revisit it when you add clusters, change data retention policies, or onboard data sources that use different index configurations.