Skip to content

[Elastic Defend] Align Integration docs with Elastic Defend Policy #522

@nicpenning

Description

@nicpenning

I noticed that in the Integration Documentation for Elastic Defend, there appears to be a discrepancy between the events that can be enabled by the policy versus what is provided in the integration.

For example, I would expect to see where does Driver and DLL Load events exist in the integration field docs. Another is the DNS events, even though I can assume they live in Network

https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html#event-collection
image

https://docs.elastic.co/en/integrations/endpoint#logs
image

Current:

Defend Policy Event Collection:
DLL and Driver Load Not in integration docs
DNS Not in integration docs
File
Network
Process
Registry
Security

Defend Integration Field Docs:
Alerts* Assumed from detect/prevent capabilities
File
Library Maybe DLL and Driver Load but unclear
Network
Process
Registry
Security

Expectation:

Defend Integration Field Docs:
Alerts
DLL and Driver Load*
DNS*
File
Library*** Remove? Or rename to DLL and Driver Load / sync with terminology from Elastic Defend?
Network
Process
Registry
Security

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions