﻿---
title: Before you begin
description: Prerequisites and initial setup tasks before creating and running detection rules.
url: https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/detect-and-alert/before-you-begin
products:
  - Elastic Cloud Serverless
  - Elastic Documentation
  - Elastic Security
applies_to:
  - Serverless Security projects: Generally available
  - Elastic Stack: Generally available
---

# Before you begin
Before you can create and run detection rules, turn on detections and make sure your users have the privileges they need. If you're new to Elastic Security detections, check out [Detection rule concepts](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/detect-and-alert/detection-rule-concepts) for an overview of how rules work.

## One-time setup

These tasks are typically completed once when you first configure detection capabilities:
- [Turn on detections](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/detect-and-alert/turn-on-detections): Enable the Detections feature for your deployment type. On Serverless, detections are on by default.
- [Detections privileges](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/detect-and-alert/detections-privileges): Give users the cluster, index, and Kibana privileges they need for detection features. When your team changes, review these privileges again in [Access control](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/manage/access-control).


## Related configuration

[Advanced data source configuration](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/detect-and-alert/advanced-data-source-configuration) covers cross-cluster search setup, data tier exclusions, and index mode settings. Revisit it when you add clusters, change data retention policies, or onboard data sources that use different index configurations.