Skip to content

Update existing notes from a workflow step #8162

Description

@nastasha-solomon

Summary

Adds a security.updateNote workflow step that updates the text of an existing note (attached to an alert, attack, or any Elasticsearch document) via the public Notes API, without disturbing the note's document association. Timeline notes are explicitly out of scope for this step.

Why this needs docs: release_note:feature adding a new named security.* workflow step, but the Security action steps reference page only documents Alert triage, Attack triage, and Detection rules step families — there is no Notes section or dedicated page for security.updateNote (or its sibling security.createNote) anywhere in the workflows docs.

Resources

Availability

Channel Details
Stack v9.6.0
Serverless Aug 24–Aug 28
Feature status preview
Feature flag None — active by default

Created with Docs Quest Scanner by @nastasha-solomon

Suggested edits

Security action steps > (new) Notes

  • What the docs say: Alert triage / Attack triage / Detection rules are the only step families documented; no Notes family exists.
  • What to add: Add a new 'Notes' step family section (with a dedicated reference page, matching the Alert triage/Attack triage/Detection rules pattern) documenting security.updateNote's note_id and text input, its preserve-document-association behavior, and that Timeline notes are out of scope. Applies from 9.6.0 and in serverless.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Team:SKIIssues owned by the SKI Docs Team

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions