Skip to content

Change LogsDB "Not Supported" message to "Caution" message as soon as three "how to check" sections are available. #6526

Open
@MikePaquette

Description

@MikePaquette

What can we change to make the docs better?

Related Issues

The change proposed here should follow the change suggested in #6518.
In other words, #6518 should be implemented as soon as possible. Even though this issue would essentially replace the "not supported" message, we need to friendlier "not supported" message asap.

What can we change to make the docs better?

Current docs are creating confusion with customers and Elastic field personnel. Want to remove the "not recommeded" status as soon as we can document for users how to determine when it's safe to enable LogsDB.

Doc URL

Doc URL: https://www.elastic.co/guide/en/security/8.17/detections-logsdb-index-mode-impact.html
Github issue link(s)/Other resources: None

Customers and Elastic field personnel have expressed confusion about the current "not supported" statement with regards to logsdb index mode, and have asked us to provide some clarification regarding new deployments vs. existing deployments.

We want to change the "not supported" language to "caution" language as soon as we can provide the three

As a short-term solution, we should replace the current text with something like:

Logsdb index mode is fully supported, and is recommended for all Elastic Security deployments. Users with existing Elastic Security deployments are advised to fully understand and accept the documented changes to detection alert documents, runtime fields, and rule actions (see below), and ensure that their deployment has sufficient excess hot data tier CPU  capacity to support the LogsDB ingest/indexing process.  Enabling LogsDB without sufficient excess hot data tier CPU capacity may result in data ingestion backups and/or security detection rule timeouts and errors.

* 	How to determine whether your hot tier CPU has enough headroom to enable LogsDB
* 	How to check for rule actions that are accessing _source
* 	Checking runtime fields that may be affected by LogsDB

Doc URL

Doc URL: https://www.elastic.co/guide/en/security/8.17/detections-logsdb-index-mode-impact.html

Which documentation set needs improvement?

ESS and serverless

Software version

Any version where LogsDB impact statement docs are included.

Metadata

Metadata

Labels

Docset: ESSIssues that apply to docs in the Stack releaseDocset: ServerlessIssues for Serverless SecurityPriority: HighIssues that are time-sensitive and/or are of high customer importanceTeam: Detection EngineblockedAn issue that's currently blocked because it’s pending info or action from stakeholders.suggestionSuggestions to improve documentationv8.17.0v8.18.0v9.0.0

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions