Summary
Adds a security.updateNote workflow step that updates the text of an existing note (attached to an alert, attack, or any Elasticsearch document) via the public Notes API, without disturbing the note's document association. Timeline notes are explicitly out of scope for this step.
Why this needs docs: release_note:feature adding a new named security.* workflow step, but the Security action steps reference page only documents Alert triage, Attack triage, and Detection rules step families — there is no Notes section or dedicated page for security.updateNote (or its sibling security.createNote) anywhere in the workflows docs.
Resources
Availability
| Channel |
Details |
| Stack |
v9.6.0 |
| Serverless |
Aug 24–Aug 28 |
| Feature status |
preview |
| Feature flag |
None — active by default |
Created with Docs Quest Scanner by @nastasha-solomon
Suggested edits
Security action steps > (new) Notes
- What the docs say: Alert triage / Attack triage / Detection rules are the only step families documented; no Notes family exists.
- What to add: Add a new 'Notes' step family section (with a dedicated reference page, matching the Alert triage/Attack triage/Detection rules pattern) documenting security.updateNote's note_id and text input, its preserve-document-association behavior, and that Timeline notes are out of scope. Applies from 9.6.0 and in serverless.
Summary
Adds a security.updateNote workflow step that updates the text of an existing note (attached to an alert, attack, or any Elasticsearch document) via the public Notes API, without disturbing the note's document association. Timeline notes are explicitly out of scope for this step.
Why this needs docs: release_note:feature adding a new named security.* workflow step, but the Security action steps reference page only documents Alert triage, Attack triage, and Detection rules step families — there is no Notes section or dedicated page for security.updateNote (or its sibling security.createNote) anywhere in the workflows docs.
Resources
Availability
Created with Docs Quest Scanner by @nastasha-solomon
Suggested edits
Security action steps > (new) Notes