# Dec 7th, 2024: \[EN\] Add a threat intelligence PDF as custom knowledge for the AI Assistant in less than 5 minutes

**URL:** <https://discuss.elastic.co/t/dec-7th-2024-en-add-a-threat-intelligence-pdf-as-custom-knowledge-for-the-ai-assistant-in-less-than-5-minutes/371322>\
**Category:** Advent Calendar\
**Created:** [December 7, 2024, 8:00am UTC](https://discuss.elastic.co/t/dec-7th-2024-en-add-a-threat-intelligence-pdf-as-custom-knowledge-for-the-ai-assistant-in-less-than-5-minutes/371322 "2024-12-07T08:00:33Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [December 7, 2024, 8:00am UTC](https://discuss.elastic.co/t/dec-7th-2024-en-add-a-threat-intelligence-pdf-as-custom-knowledge-for-the-ai-assistant-in-less-than-5-minutes/371322/1 "2024-12-07T08:00:33Z")

</div>

Security operations teams often maintain repositories of threat intelligence reports that contain a wealth of knowledge from the vendor producing the report. The challenge, however, is that the content of these reports typically sits in PDFs, making it difficult to retrieve and reference relevant information from the report during an incident or investigation or leverage any indicators of compromise (IoCs) for threat hunting. With the ability to use these reports as knowledge within the Elastic AI Assistant, this dynamic changes entirely.

Let’s use the [Elastic Global Threat Report for 2024](https://www.elastic.co/resources/security/report/global-threat-report) as an example.

**Step 1. Enabling and setting up the knowledge base**  
This is a very simple step that takes care of some of the prerequisites necessary for the knowledge base content to be used by [Elastic AI Assistant](https://www.elastic.co/security/ai). It’s a single button in the assistant management settings. The process only takes a few minutes to complete.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/0/80cd50734a42484a54d240054bb82fffe1929d15.png)

**Step 2. Uploading the PDF**  
Once the knowledge base setup is complete, we can proceed to upload the PDF. To do this, we can use the integration titled **Upload a file** from the Integrations page.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/9/49dddfeb232137c114ab884d7ab64ff8d9a4140e.jpeg)

You can select the PDF from the next screen.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/a/0a0b51e5f9f8f8cb648573e0bf9871f7d800d9d7.jpeg)

Click **Import** when prompted.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/4/047beaa9fa2e21289f98ebb8cd9c3e99e93dbce1.jpeg)

For the next step, we will need to pivot to the **Advanced** tab. Once uploaded, this PDF will live in its own index, so feel free to name the index accordingly. There is no need to create a data view.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/0/c0060b55846d78f8f4ef0ec3a7ad04f9c307b8f3.png)

There is one last step before clicking on the import button. We need to add a semantic text field. This allows the assistant to retrieve the correct information from the report.

Click on **Add additional field** and then **Add semantic text field**.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/7/37e2bee3af3bb9719a964217069fc9a7a610b37f.png)

You can leave the default settings that appear after clicking **Add semantic text field**.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bbe872b0f736e38e6700ce102919a464e2c8aed9.png)

You can now click on **Import**.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/a/aae75b8fc871020382447e7017cc97000d1adfe1.png)

When the file is imported successfully, you should see the following status:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/d/bdbdd6ad78e1505cb30fd1fe96a507d90f649976.png)

_It’s important to note that while we used the File Upload user interface to add this PDF, it’s possible to automate this functionality as part of any ingest process using the_ [_attachment processor_](https://www.elastic.co/guide/en/elasticsearch/reference/current/attachment.html)_._

**Step 3. Adding the PDF index as custom knowledge**  
Returning to the AI Settings page, select **New** to add a new knowledge entry, and then select **Index** from the list.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/e/2ec933e468f8e0ce24b50c3db174e365f4532f66.png)

You’ll then be asked to select the index that was just created (“global-threat-report-kb” in our example), the semantic text field we just created (content), and a description of how and when the assistant should use this knowledge. This should be a simple sentence description of what the data is and when and how it should be queried. You can also set the relevant permissions for this knowledge entry from this view. When ready, hit **Save**.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/2/a2240ae879d45e4b644585b571c5a33e26ddfe2e.jpeg)

Once added, you should see the new knowledge entry in the list:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/c/8c8fab995663f18e652883256b69a419927ee0d7.png)

The threat report is now available as knowledge and is ready to be used by the assistant.

**Comparing the results**  
If we compare results from the assistant before and after we add the knowledge base entry, we can see a clear difference.

**Before** the knowledge was added:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/a/da07b4bc0c38e932a4b973f8fc857e78ad70327a.jpeg)

**After** the knowledge was added:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2d8935c2668d3fbad9fba14178da0e0432a7a98e.jpeg)

Our PDF went from being an idle bit of important — yet hard-to-use — information to being immediately accessible to our security operations team. The great thing about knowledge sources is that the Elastic AI Assistant is able to use a combination of them, depending on the questions asked. Remember that the Elastic AI Assistant can also ingest 500 of your latest alerts as knowledge by default, which allows for a powerful combination of questions that can be asked.

This one example clearly highlights the usefulness of having custom knowledge sources available to the assistant. And as we highlighted earlier, there are many other scenarios and examples of where custom knowledge sources can be useful.

For more information on how to add different types of knowledge sources, you can refer to our [detailed documentation](https://www.elastic.co/guide/en/security/current/ai-assistant-knowledge-base.html).
