Trusted applications: behavioral detection behavior#5090
Trusted applications: behavioral detection behavior#5090benironside wants to merge 6 commits intomainfrom
Conversation
Vale Linting ResultsSummary: 1 suggestion found 💡 Suggestions (1)
The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
🔍 Preview links for changed docs |
| :::{applies-item} { stack: ga 9.2+, serverless: ga } | ||
| Trusted applications are not monitored for malicious behavior, which improves performance. |
There was a problem hiding this comment.
We changed this in 9.2.5, but 9.2.4 still uses the old behavior. Can we clarify this?
There was a problem hiding this comment.
We normally document the latest minor version, with the assumption that if people are on a given minor version, they're probably on the latest patch. Does that work in this case?
There was a problem hiding this comment.
We normally document the latest minor version, with the assumption that if people are on a given minor version, they're probably on the latest patch.
Is that documented anywhere for users? A user on 9.2.4 going to the 9.2 docs could easily think that the documented behavior applies to them.
Summary
Fixes #4842 — in v9.2+ and serverless, behavioral detections no longer apply to trusted applications. This improves performance.
This PR updates two pages related to this functionality.
Thanks!
Generative AI disclosure