I am using trial version.I have installed filebeat,auditbeat,winlogbeat agent on target systems. The prebuilt jobs which i can use are
- siem-api-rare_process_linux_ecs
- siem-api-rare_process_windows_ecs
3.siem-api-suspicious_login_activity_ecs
but from elasticsearch reference I should use all of these https://www.elastic.co/guide/en/siem/guide/7.x/prebuilt-ml-jobs.html
why can I use only these 3 jobs? Does it because license type?