362c459094
* [New] Multiple Machine Learning Alerts by Influencer Field This rule uses alerts data to determine when multiple different machine learning alerts involving the same influencer field are triggered. Analysts can use this to prioritize triage and response, as these entities are more likely to be more suspicious. * Update multiple_machine_learning_jobs_by_entity.toml * Update multiple_machine_learning_jobs_by_entity.toml * Update non-ecs-schema.json * Update multiple_machine_learning_jobs_by_entity.toml * Update non-ecs-schema.json