From b6d33733a9fe111d18ee00e3fce771439a900c18 Mon Sep 17 00:00:00 2001 From: natasha-moore-elastic Date: Tue, 30 Dec 2025 16:52:41 +0000 Subject: [PATCH 1/4] Privileged user monitoring moves to GA --- .../monitor-privileged-user-activitites.md | 4 ++-- solutions/security/advanced-entity-analytics/overview.md | 2 +- .../privileged-user-monitoring-requirements.md | 6 +++--- .../privileged-user-monitoring-setup.md | 4 ++-- .../advanced-entity-analytics/privileged-user-monitoring.md | 4 ++-- .../security/get-started/configure-advanced-settings.md | 4 ++-- solutions/security/get-started/elastic-security-ui.md | 1 + 7 files changed, 13 insertions(+), 12 deletions(-) diff --git a/solutions/security/advanced-entity-analytics/monitor-privileged-user-activitites.md b/solutions/security/advanced-entity-analytics/monitor-privileged-user-activitites.md index f398f40ed6..49a176aa4a 100644 --- a/solutions/security/advanced-entity-analytics/monitor-privileged-user-activitites.md +++ b/solutions/security/advanced-entity-analytics/monitor-privileged-user-activitites.md @@ -1,8 +1,8 @@ --- applies_to: - stack: preview 9.1 + stack: ga 9.3, preview 9.1 serverless: - security: preview + security: ga products: - id: security - id: cloud-serverless diff --git a/solutions/security/advanced-entity-analytics/overview.md b/solutions/security/advanced-entity-analytics/overview.md index 681b21d690..17081b7ab2 100644 --- a/solutions/security/advanced-entity-analytics/overview.md +++ b/solutions/security/advanced-entity-analytics/overview.md @@ -17,7 +17,7 @@ To access the page, find **Entity analytics** → **Overview** in the navigation :::{admonition} Requirements * This feature requires the appropriate [subscription](https://www.elastic.co/pricing) in {{stack}} or [project feature tier](/deploy-manage/deploy/elastic-cloud/project-settings.md) in {{serverless-short}}. -* To get access to this page, turn on the `securitySolution:enablePrivilegedUserMonitoring` [advanced setting](/solutions/security/get-started/configure-advanced-settings.md#access-privileged-user-monitoring). +* {applies_to}`serverless: removed` {applies_to}`stack: removed 9.3` To get access to this page, turn on the `securitySolution:enablePrivilegedUserMonitoring` [advanced setting](/solutions/security/get-started/configure-advanced-settings.md#access-privileged-user-monitoring). ::: diff --git a/solutions/security/advanced-entity-analytics/privileged-user-monitoring-requirements.md b/solutions/security/advanced-entity-analytics/privileged-user-monitoring-requirements.md index 71d4506108..f54fd5e53f 100644 --- a/solutions/security/advanced-entity-analytics/privileged-user-monitoring-requirements.md +++ b/solutions/security/advanced-entity-analytics/privileged-user-monitoring-requirements.md @@ -1,8 +1,8 @@ --- applies_to: - stack: preview 9.1 + stack: ga 9.3, preview 9.1 serverless: - security: preview + security: ga products: - id: security - id: cloud-serverless @@ -16,7 +16,7 @@ The privileged user monitoring feature requires: * {applies_to}`stack: ` The appropriate [subscription](https://www.elastic.co/subscriptions) * {applies_to}`serverless: ` The appropriate [feature tier](https://www.elastic.co/pricing/serverless-security) -To enable this feature, turn on the `securitySolution:enablePrivilegedUserMonitoring` [advanced setting](/solutions/security/get-started/configure-advanced-settings.md#access-privileged-user-monitoring). +{applies_to}`serverless: removed` {applies_to}`stack: removed 9.3` To enable this feature, turn on the `securitySolution:enablePrivilegedUserMonitoring` [advanced setting](/solutions/security/get-started/configure-advanced-settings.md#access-privileged-user-monitoring). To use this feature, you need: * {applies_to}`stack: ` A role with the appropriate [privileges](#privmon_privs) diff --git a/solutions/security/advanced-entity-analytics/privileged-user-monitoring-setup.md b/solutions/security/advanced-entity-analytics/privileged-user-monitoring-setup.md index d7719605ca..3b30367ac4 100644 --- a/solutions/security/advanced-entity-analytics/privileged-user-monitoring-setup.md +++ b/solutions/security/advanced-entity-analytics/privileged-user-monitoring-setup.md @@ -1,9 +1,9 @@ --- navigation_title: Set up privileged user monitoring applies_to: - stack: preview 9.1 + stack: ga 9.3, preview 9.1 serverless: - security: preview + security: ga products: - id: security - id: cloud-serverless diff --git a/solutions/security/advanced-entity-analytics/privileged-user-monitoring.md b/solutions/security/advanced-entity-analytics/privileged-user-monitoring.md index a799f8947f..e62c0ca412 100644 --- a/solutions/security/advanced-entity-analytics/privileged-user-monitoring.md +++ b/solutions/security/advanced-entity-analytics/privileged-user-monitoring.md @@ -1,8 +1,8 @@ --- applies_to: - stack: preview 9.1 + stack: ga 9.3, preview 9.1 serverless: - security: preview + security: ga products: - id: security - id: cloud-serverless diff --git a/solutions/security/get-started/configure-advanced-settings.md b/solutions/security/get-started/configure-advanced-settings.md index d3c4dc650e..77b693ceeb 100644 --- a/solutions/security/get-started/configure-advanced-settings.md +++ b/solutions/security/get-started/configure-advanced-settings.md @@ -250,8 +250,8 @@ Even when the `excludedDataTiersForRuleExecution` advanced setting is enabled, i ## Access privileged user monitoring ```yaml {applies_to} -stack: ga 9.1 -serverless: ga +stack: removed 9.3, ga 9.1 +serverless: removed ``` The `securitySolution:enablePrivilegedUserMonitoring` setting allows you to access the [Entity analytics overview page](/solutions/security/advanced-entity-analytics/overview.md) and the [privileged user monitoring](/solutions/security/advanced-entity-analytics/privileged-user-monitoring.md) feature. This setting is turned off by default. diff --git a/solutions/security/get-started/elastic-security-ui.md b/solutions/security/get-started/elastic-security-ui.md index f81131e9ef..b8b9b6da2f 100644 --- a/solutions/security/get-started/elastic-security-ui.md +++ b/solutions/security/get-started/elastic-security-ui.md @@ -154,6 +154,7 @@ serverless: ga ``` :::{admonition} Requirements +:applies_to: {"stack": removed 9.3", "serverless": "removed"} To access this section, turn on the `securitySolution:enablePrivilegedUserMonitoring` [advanced setting](/solutions/security/get-started/configure-advanced-settings.md#access-privileged-user-monitoring). ::: From c1068139abb25b78ab4754dc561001462a3e93b8 Mon Sep 17 00:00:00 2001 From: natasha-moore-elastic Date: Wed, 31 Dec 2025 09:35:09 +0000 Subject: [PATCH 2/4] add missing applies_to --- .../privileged-user-monitoring-setup.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/solutions/security/advanced-entity-analytics/privileged-user-monitoring-setup.md b/solutions/security/advanced-entity-analytics/privileged-user-monitoring-setup.md index 3b30367ac4..ef71853d35 100644 --- a/solutions/security/advanced-entity-analytics/privileged-user-monitoring-setup.md +++ b/solutions/security/advanced-entity-analytics/privileged-user-monitoring-setup.md @@ -15,7 +15,7 @@ products: To use privileged user monitoring, you must: * Have the appropriate user role or privileges -* Turn on the required advanced setting +* {applies_to}`serverless: removed` {applies_to}`stack: removed 9.3` Turn on the required advanced setting For more information, refer to [Privileged user monitoring requirements](/solutions/security/advanced-entity-analytics/privileged-user-monitoring-requirements.md). ::: From bfa9c621a1a83b2243a843a3912e58dcda7b4f15 Mon Sep 17 00:00:00 2001 From: natasha-moore-elastic Date: Mon, 5 Jan 2026 09:19:27 +0000 Subject: [PATCH 3/4] fix applies syntax --- solutions/security/get-started/elastic-security-ui.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/solutions/security/get-started/elastic-security-ui.md b/solutions/security/get-started/elastic-security-ui.md index b8b9b6da2f..2158dda4c5 100644 --- a/solutions/security/get-started/elastic-security-ui.md +++ b/solutions/security/get-started/elastic-security-ui.md @@ -154,7 +154,7 @@ serverless: ga ``` :::{admonition} Requirements -:applies_to: {"stack": removed 9.3", "serverless": "removed"} +:applies_to: {stack: removed 9.3, serverless: removed} To access this section, turn on the `securitySolution:enablePrivilegedUserMonitoring` [advanced setting](/solutions/security/get-started/configure-advanced-settings.md#access-privileged-user-monitoring). ::: From a17449b9bfe1bd02e31c54865d22bbf6caa51f17 Mon Sep 17 00:00:00 2001 From: natasha-moore-elastic Date: Tue, 6 Jan 2026 14:10:31 +0000 Subject: [PATCH 4/4] edit tags for integration support --- .../privileged-user-monitoring-setup.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/solutions/security/advanced-entity-analytics/privileged-user-monitoring-setup.md b/solutions/security/advanced-entity-analytics/privileged-user-monitoring-setup.md index ef71853d35..a5084b2a7c 100644 --- a/solutions/security/advanced-entity-analytics/privileged-user-monitoring-setup.md +++ b/solutions/security/advanced-entity-analytics/privileged-user-monitoring-setup.md @@ -28,7 +28,7 @@ Privileged users typically include accounts with elevated access rights that all You can define privileged users in the following ways: -* {applies_to}`stack: preview 9.2` {applies_to}`serverless: preview` [Add a supported integration](#privmon-integrations) with your organization’s user identities. If your environment is already ingesting data from a supported integration, the setup steps are skipped—you're taken directly to the Privileged user monitoring dashboard, where you can start [monitoring user activity](/solutions/security/advanced-entity-analytics/monitor-privileged-user-activitites.md). +* {applies_to}`stack: ga 9.3` {applies_to}`stack: preview 9.2` {applies_to}`serverless: ga` [Add a supported integration](#privmon-integrations) with your organization’s user identities. If your environment is already ingesting data from a supported integration, the setup steps are skipped—you're taken directly to the Privileged user monitoring dashboard, where you can start [monitoring user activity](/solutions/security/advanced-entity-analytics/monitor-privileged-user-activitites.md). * [Select an existing index](#privmon-index) or create a new custom index with privileged user data. * [Bulk-upload](#privmon-upload) a list of privileged users using a CSV or TXT file. * Use the Entity analytics APIs to [mark individual users as privileged]({{kib-apis}}/operation/operation-createprivmonuser) or [bulk-upload multiple privileged users]({{kib-apis}}/operation/operation-privmonbulkuploaduserscsv). @@ -37,8 +37,8 @@ To get started, find the **Privileged user monitoring** page in the navigation m ### Add a supported integration [privmon-integrations] ```yaml {applies_to} -stack: preview 9.2 -serverless: preview +stack: ga 9.3, preview 9.2 +serverless: ga ``` 1. On the **Privileged user monitoring** page, select an integration. The supported integrations are: @@ -92,7 +92,7 @@ You can use multiple data source types, such as an index and a CSV file, at the On this page, you can: -* {applies_to}`stack: preview 9.2` {applies_to}`serverless: preview` Change which integrations you're using as data sources. +* {applies_to}`stack: ga 9.3` {applies_to}`stack: preview 9.2` {applies_to}`serverless: preview` Change which integrations you're using as data sources. * View, remove, and change indices after initially defining them. * Import a new supported file with a list of privileged users.