Run Attack Discovery from the Attacks view
From the Attacks view, configure which alerts to analyze, then start a manual or scheduled run. Discoveries appear in the same view next to their related alerts.
To use the Attacks view, you need:
- The Enable alerts and attacks alignment advanced setting turned on (only required for Elastic Stack 9.4).
- The Attack Discovery Workflows advanced setting turned on if you want the settings flyout with skill, query, and workflow retrieval.
- A role with the index privileges required to generate and read discoveries, and these Kibana privileges at minimum:
- Security → Attack discovery:
All - Security → Rules and Exceptions:
Read - Security → Alerts:
Read
- Security → Attack discovery:
- Open the Attacks view at Detections → Views → Attacks.
- Configure Attack Discovery settings.
- Start Attack Discovery with a manual run or a scheduled run.
- Open the Attacks view at Detections → Views → Attacks.
- Configure which alerts to analyze when you create or edit a schedule (classic schedule flyout controls).
- Schedule runs from Attacks, or manually run Attack Discovery from the Attack Discovery page.