Loading

Troubleshoot a run with AI

Use AI troubleshooting when an Attack Discovery run fails, is canceled or dismissed, or an analysis step fails. Troubleshooting only diagnoses problems. It never changes your configuration, schedules, or discoveries.

To troubleshoot a run with AI, you need:

  1. Go to DetectionsViewsAttacks.
  2. Open the Generations control center in the Attacks view header.
  3. Select a failed, canceled, or dismissed run, or a run with a failed analysis step.
  4. Start AI troubleshooting.

AI troubleshooting reviews the failed run (alert retrieval, generation, and validation), identifies what went wrong, and suggests a fix. After you identify the fix, update your Attack Discovery settings if needed, then start another manual run or wait for the next scheduled run.

From the same workflow execution details view, you can download a Markdown diagnostic report for the run. Use Download diagnostic report to save the file, or copy or inspect it first.

The report includes failure details, step timing, configuration context, and how the run was started. Share the downloaded file with Elastic Support when you open a case about a failed run.

The same diagnostic report is attached automatically when you start AI troubleshooting, so the agent has that context in the conversation.

Note

On the Attack Discovery page, after a run finishes, a details button on the success or failure banner opens the workflow execution details flyout if you have workflow-read privileges. From there, the same AI troubleshooting option and diagnostic report actions are available.