DOCS-1548 - Mobot, Example Prompts, AI/ML FAQ | GA docs - #6897
Conversation
Replace the Query Agent/Knowledge Agent selection UI with the unified single-field conversational interface from the Mobot preview, merged with the existing GA doc's deeper technical content (sample queries, chart-type rules, RBAC notes, audit query, FAQ). Adds unstructured log support without required Field Extraction Rules, and clarifies that data questions are scoped to log data only. Delete mobot-preview.md now that its content lives in mobot.md, with a redirect to preserve the old URL. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Consolidate the Query Agent/Knowledge Agent-era structure into the unified interface: split Getting started into a fast path plus a separate "How Mobot responds" behavior section, merge the three Example workflow H2s into one, split "Working with Mobot" into log-specific and general-conversation sections, and reorganize Example prompts to match the product's own in-UI taxonomy (General, Security, Observability, Administration) instead of a persona split. Restore "At a glance" after over-trimming removed it along with "Who benefits from Mobot" - the persona list survives in the intro, but the quick-facts summary has GEO citation value the intro doesn't replace. Fix an orphaned RAG/dashboard-aware-translations reference in FAQ by reintroducing the concept in Key capabilities. Fix chart-type rules using raw enum casing (MAP, SVP, TABL/E) instead of the UI's Title Case names. Standardize "log data question" / "how-to question" terminology throughout, replacing several inconsistent variants. Drop a stale claim tying Example prompts' categories to the current welcome-screen UI, which will drift out of accuracy at the next UI update. Add sales-deck and in-product sample prompts as commented-out content under their matching categories, pending a product decision on which to publish. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Updated the description to emphasize troubleshooting and plain-language questions.
Document the Share with specific users and roles, See who has access, and Get sharable URL options in the Share Conversation dialog, not just the URL-copy shortcut. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…st Agent doc Flag the Example questions section for replacement with a link to Mobot's Example Prompts (Security analyst) section once #6897 merges, to avoid duplicating prompt content across docs. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…nd add Query/Knowledge Agent rename FAQ Add a Cloud SIEM insight entry point to Getting started, add an FAQ explaining the Query Agent/Knowledge Agent renames without overclaiming unreleased monitor/dashboard creation, flag paused Monitor Creation work for later, update the Mobot card on the search index page with the new icon and GA-focused blurb, and refresh the site announcement bar copy for Mobot GA. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
… Analyst framing Add the Aug 3 Search release note for Mobot GA. In mobot.md: remove the AI-addendum requirement (no longer required at GA), add the 10-prompt/ user/day limit (At a glance + FAQ), add a Cloud SIEM investigations capability that hands off from the SOC Analyst Agent (launched from an insight), fix the description, and use "plain language". Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ocumentation into DOCS-1548-mobot-ga
…guage) Add the prompt definition, daily-limit reset behavior, and higher-limit request path to the prompt-limit FAQ; add a non-English language FAQ; and state the 60-day conversation retention window. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… opt-out - Add Create and manage content section (conversational monitors, dashboards, playbooks) with known limitations - Add Memories subsection and reconcile the "no memory across sessions" limitation; add memory privacy note - Add FAQs for cost, AI addendum, Summary Agent, and non-deterministic answers; expand prompt-limit FAQ (Org ID, banner, UTC reset with Pacific example) - Document self-serve opt-out via Feature Management (with screenshot) - Clarify how to open the My Conversations panel - Release note: add content-creation capability bullet - Leave TODO markers for PM-pending items (memory scope/UI/RBAC, AI features toggle coupling) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
# Conflicts: # docs/search/index.md # docs/search/mobot.md # static/img/search/mobot/open-in-log-search.png
…docs Rename triage to investigate and capitalize SOC Analyst Agent per Oren's review, remove launch-promo language, and update AI Verdict screenshots and copy to match the redesigned insight UI. Also apply Twisa's Mobot feedback: add a Use cases section, resequence Key capabilities, rename "workflow(s)" to "conversation(s)" throughout, dedupe the Get Started instructions, and add a homepage screenshot to the intro. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ocumentation into DOCS-1548-mobot-ga
|
@tp-sl — status on the rest of your Mobot feedback:
Still open — Audit Mobot queries section: the doc currently filters on |
|
@orensh81 — separately from the fixes above, I've got 4 open questions blocking publish on the SOC Analyst Agent doc that need your confirmation:
OS--> Needs to be an admin to see it.
OS-->Yes it is on the UI
OS--> Yes we are shipping a banner warning.
All 4 are marked with TODO comments in the doc source if you want to see them in context. |
…d training resources Answer Oren's 4 outstanding TODOs (permissions defaults, Volume & Overage toggle, capacity banner, audit query) and Twisa's audit log query updates across the AI/ML FAQ, Mobot, and audit-event-index docs. Add the "Using Mobot for Log Analysis" microlesson, hide Conversational Playbooks pending its conditional-GO rollout, and fix leftover triage/promo language in the AI/ML FAQ doc for consistency with the rest of the GA copy. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ublish SOC Analyst Agent doesn't ship until August 3, but this branch bundled its GA content in from an earlier merge. Revert soc-analyst-agent.md, the CSE hub cards, and both screenshots to main's current Public Preview state; remove the Aug 3 release note; and restore insight-summary.md (deleted on the assumption SOC GA would absorb it same-day) along with its sidebar entry and redirect removal, since Insight Summary is still a live, separate feature until SOC actually absorbs it. ai-machine-learning.md keeps its GA-framed SOC Analyst Agent content per PM sign-off (comfortable with early FAQ wording), but retains the Summary Agent section and drops the "absorbed into SOC Analyst Agent" FAQ claim, since that absorption hasn't happened yet. On Aug 3, that file needs a small follow-up: remove the Summary Agent section and restore the absorption FAQ bullet. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The FedRAMP FAQ claims SOC Analyst Agent is available in FED deployments, which isn't confirmed until Aug 3. Hide it alongside the other SOC Analyst Agent GA content already deferred in this file. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…lish A broader audit (prompted by seeing these still listed in the PR) found 13 more static/img/cse images tied to the SOC Analyst Agent GA rewrite that the first split pass missed, since soc-analyst-agent.md's reverted text still referenced the same filenames as main but with different (GA-era) bytes, or referenced GA-only images that don't exist in main at all. Revert the former to main's content, delete the latter, and restore the Public-Preview-era images main still expects. Also revert a stale cross-reference in the Dec 31 2025 release note that had been repointed from insight-summary to soc-analyst-agent. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…urce Point the Mobot announcement banner at the CDN-hosted image instead of a baseUrl-relative path so it renders correctly in production.
mafsumo
left a comment
There was a problem hiding this comment.
Review for Mobot, sample prompt and AI FAQ
…iew, training links - Align AI/ML FAQ wording with legal-approved copy (opt-out framing, third-party access, training-data answer link). - Single-source duplicated legal FAQ answers in the Mobot doc instead of keeping a second copy in sync. - Apply Mark's review: reworded intro line, fixed Academy training links and Wistia iframe ID, moved how-to prompts to the top of the example prompts page, and hid the Self-paced course link pending next week's launch.
Co-authored-by: mafsumo <166030078+mafsumo@users.noreply.github.com>
Co-authored-by: mafsumo <166030078+mafsumo@users.noreply.github.com>
…ocumentation into DOCS-1548-mobot-ga
Purpose of this pull request
This pull request moves Mobot from Preview to GA, and updates the shared Dojo AI FAQ doc to match. Includes the Aug 3 release notes for Mobot.
Note: SOC Analyst Agent GA was originally bundled into this branch, but its release date (Aug 3) diverged from Mobot's (today), so that content has been split out to #6971, targeting
maindirectly for Aug 3. Mobot release notes pulled out as well and will go out with MCP server reelase notes 7/30.Mobot (
docs/search/mobot/)mobot.mdintomobot/index.md+mobot/mobot-example-prompts.md, with a new "Use cases" section, resequenced "Key capabilities," and a homepage screenshot added per review feedback.mobot-preview.mdnow that its content lives inmobot/index.md, with a 301 redirect added tocid-redirects.json.docusaurus.config.js) and homepage/search landing card blurbs (docs/get-started/index.md,docs/search/index.md) to reflect the new positioning.blog-service/2026-08-03-search.md.AI/ML FAQ (
docs/get-started/ai-machine-learning.md)insight-summary.md) stay live, and the FedRAMP availability FAQ (which names the SOC Analyst Agent) stays hidden, since neither is accurate until SOC Analyst Agent actually GAs on DOCS-1565 - SOC Analyst Agent GA - Docs and release notes #6971. That PR includes the follow-up to remove Summary Agent and un-hide the FedRAMP FAQ once it merges.Select the type of change
Ticket (if applicable)
https://sumologic.atlassian.net/browse/DOCS-1548
https://sumologic.atlassian.net/browse/DOCS-1770
SOC Analyst Agent GA tracked separately in #6971 (https://sumologic.atlassian.net/browse/DOCS-1565).