Skip to content

[Elastic Defend] Align Integration docs with Elastic Defend Policy #522

@nicpenning

Description

@nicpenning

I noticed that in the Integration Documentation for Elastic Defend, there appears to be a discrepancy between the events that can be enabled by the policy versus what is provided in the integration.

For example, I would expect to see where does Driver and DLL Load events exist in the integration field docs. Another is the DNS events, even though I can assume they live in Network

https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html#event-collection
image

https://docs.elastic.co/en/integrations/endpoint#logs
image

Current:

Defend Policy Event Collection:
DLL and Driver Load Not in integration docs
DNS Not in integration docs
File
Network
Process
Registry
Security

Defend Integration Field Docs:
Alerts* Assumed from detect/prevent capabilities
File
Library Maybe DLL and Driver Load but unclear
Network
Process
Registry
Security

Expectation:

Defend Integration Field Docs:
Alerts
DLL and Driver Load*
DNS*
File
Library*** Remove? Or rename to DLL and Driver Load / sync with terminology from Elastic Defend?
Network
Process
Registry
Security

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions