Manually run Attack Discovery from the Attacks view
Manually run Attack Discovery when you want to analyze the current alert selection right away, for example after you change settings or during an active investigation. Discoveries from a manual run appear in the Attacks table alongside scheduled discoveries.
To manually run Attack Discovery from the Attacks view:
- Go to Detections → Views → Attacks.
- Select Settings next to Run to open the Attack discovery settings flyout.
- Configure Attack Discovery settings. Under Generation, confirm an LLM connector is selected. If you don't already have one, refer to Configure access to LLMs.
- Start the run. Select Save and run in the flyout, or close the flyout and select Run. A notification confirms that generation has started.
Analysis can take from a few seconds to several minutes, depending on the number of alerts and the model. Open Generations in the Attacks view header to watch progress.
When the run finishes, refresh the Attacks view to see new discoveries in the same table as scheduled discoveries (labeled as manually generated). If the run fails, troubleshoot it with AI. Select Run again anytime to start another analysis with the current alert selection. To run Attack Discovery automatically at intervals, schedule a run.
Attack Discovery uses the same data anonymization settings as Elastic AI Assistant. Configure which alert fields are sent to the LLM, and which are obfuscated, in the Elastic AI Assistant settings. Consider the privacy policies of third-party LLMs before sending them sensitive data.
Start manual runs from the Attack Discovery page. Use the Attacks page for triage, or schedule a run for recurring analysis.