Loading

Manually run Attack Discovery from the Attacks view

Manually run Attack Discovery when you want to analyze the current alert selection right away, for example after you change settings or during an active investigation. Discoveries from a manual run appear in the Attacks table alongside scheduled discoveries.

To manually run Attack Discovery from the Attacks view:

  1. Go to DetectionsViewsAttacks.
  2. Configure Attack Discovery settings in Settings next to Run, and confirm an LLM connector is selected. You can start analysis from the flyout with Save and run, or close the flyout and continue with the next step.
  3. Select Run. A notification confirms that generation has started.

Analysis can take from a few seconds to several minutes, depending on the number of alerts and the model. Open Generations in the Attacks view header to watch progress. When the run finishes, refresh the Attacks view to see new discoveries in the same table as scheduled discoveries (labeled as manually generated). Select Run again anytime to start another analysis with the current alert selection.

Note

Attack Discovery uses the same data anonymization settings as Elastic AI Assistant. Configure which alert fields are sent to the LLM, and which are obfuscated, in the Elastic AI Assistant settings. Consider the privacy policies of third-party LLMs before sending them sensitive data.

After the run finishes, manage discoveries from the Attacks view. If the run fails, troubleshoot it with AI. To run Attack Discovery automatically at intervals, schedule a run.

Start manual runs from the Attack Discovery page. Use the Attacks page for triage, or schedule a run for recurring analysis.