-
Notifications
You must be signed in to change notification settings - Fork 18
Description
I noticed that in the Integration Documentation for Elastic Defend, there appears to be a discrepancy between the events that can be enabled by the policy versus what is provided in the integration.
For example, I would expect to see where does Driver and DLL Load events exist in the integration field docs. Another is the DNS events, even though I can assume they live in Network
https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html#event-collection

https://docs.elastic.co/en/integrations/endpoint#logs

Current:
Defend Policy Event Collection:
DLL and Driver Load Not in integration docs
DNS Not in integration docs
File
Network
Process
Registry
Security
Defend Integration Field Docs:
Alerts* Assumed from detect/prevent capabilities
File
Library Maybe DLL and Driver Load but unclear
Network
Process
Registry
Security
Expectation:
Defend Integration Field Docs:
Alerts
DLL and Driver Load*
DNS*
File
Library*** Remove? Or rename to DLL and Driver Load / sync with terminology from Elastic Defend?
Network
Process
Registry
Security