Skip to content

[Security][Alerting]: Add docs for installing and updating prebuilt rules in air-gapped environments #4972

Merged
nastasha-solomon merged 16 commits intomainfrom
issue-4652-upgrade-airgapped-rules
Mar 2, 2026
Merged

[Security][Alerting]: Add docs for installing and updating prebuilt rules in air-gapped environments #4972
nastasha-solomon merged 16 commits intomainfrom
issue-4652-upgrade-airgapped-rules

Conversation

@nastasha-solomon
Copy link
Contributor

@nastasha-solomon nastasha-solomon commented Feb 4, 2026

Summary

This PR creates a dedicated page for installing and updating Elastic prebuilt detection rules in air-gapped environments. The following methods are covered:

  • Using a self-hosted Package Registry (recommended)
  • Manually transferring prebuilt rules using the export/import process

Fixes:

Generative AI disclosure

  1. Did you use a generative AI (GenAI) tool to assist in creating this contribution?
  • Yes
  • No

Cursor, claude-4.5-opus-high

@nastasha-solomon nastasha-solomon self-assigned this Feb 4, 2026
@github-actions
Copy link
Contributor

github-actions bot commented Feb 4, 2026

Vale Linting Results

Summary: 1 warning, 1 suggestion found

⚠️ Warnings (1)
File Line Rule Message
solutions/security/detect-and-alert/prebuilt-rules-airgapped.md 21 Elastic.Spelling 'prebundled' is a possible misspelling.
💡 Suggestions (1)
File Line Rule Message
solutions/security/detect-and-alert/prebuilt-rules-airgapped.md 209 Elastic.Wordiness Consider using 'drag' instead of 'Drag and drop'.

The Vale linter checks documentation changes against the Elastic Docs style guide.

To use Vale locally or report issues, refer to Elastic style guide for Vale.

@github-actions
Copy link
Contributor

github-actions bot commented Feb 4, 2026

@nastasha-solomon nastasha-solomon marked this pull request as ready for review February 4, 2026 04:47
@nastasha-solomon nastasha-solomon requested review from a team as code owners February 4, 2026 04:47
Copy link
Contributor

@natasha-moore-elastic natasha-moore-elastic left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left a few minor comments and suggestions, looks great overall!


::::{step} Choose your registry image

The {{package-registry}} is available as a Docker image with different tags. Choose the appropriate image based on your update strategy.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't know a lot about Elastic Package Registry, but this leaves me wondering how/where users can view all the available images that they can choose from?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@pborgonovi can you offer some guidance here?

Copy link

@pborgonovi pborgonovi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @nastasha-solomon
I reviewed the doc content and from a technical perspective it's correct. I added 2 minor notes for some extra information, if you could take a look.

@nastasha-solomon nastasha-solomon merged commit 0166fe7 into main Mar 2, 2026
8 checks passed
@nastasha-solomon nastasha-solomon deleted the issue-4652-upgrade-airgapped-rules branch March 2, 2026 23:19
nastasha-solomon added a commit that referenced this pull request Mar 3, 2026
…rules in air-gapped environments (#4972)

<!--
Thank you for contributing to the Elastic Docs! 🎉
Use this template to help us efficiently review your contribution.
-->

<!--
Describe what your PR changes or improves.
If your PR fixes an issue, link it here. If your PR does not fix an
issue, describe the reason you are making the change.
-->

This PR creates [a dedicated
page](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/4972/solutions/security/detect-and-alert/prebuilt-rules-airgapped)
for installing and updating Elastic prebuilt detection rules in
air-gapped environments. The following methods are covered:

- Using a self-hosted Package Registry (recommended)
- Manually transferring prebuilt rules using the export/import process

Fixes:
- elastic/security-docs#4652
- elastic/security-docs#2932

<!--
To help us ensure compliance with the Elastic open source and
documentation guidelines, please answer the following:
-->
1. Did you use a generative AI (GenAI) tool to assist in creating this
contribution?
- [x] Yes
- [ ] No
<!--
2. If you answered "Yes" to the previous question, please specify the
tool(s) and model(s) used (e.g., Google Gemini, OpenAI ChatGPT-4, etc.).

Tool(s) and model(s) used:
-->
Cursor, claude-4.5-opus-high

---------

Co-authored-by: natasha-moore-elastic <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants