Fixed Price Deliverable
Defend Accelerator: Detect and Prevent
Detect
Overview
A fixed-price, time-boxed implementation engagement to deploy a foundational Elastic Defend solution providing endpoint protection and visibility for threat prevention, detection, and investigation on endpoints, for existing Elastic SIEM customers extending their deployment to include Elastic Defend. This engagement covers one (1) cluster only — Elastic Cloud Hosted (ECH), Serverless, or self-managed (up to ten (10) nodes) — on an existing Elastic SIEM deployment. Any additional clusters, deployments, environments, or expanded scope are expressly out of scope unless otherwise agreed in a mutually executed Order Form (change order).
Scope
- Conduct discovery, finalize up to five (5) in-scope endpoint/server policy types (within the Elastic support matrix), define high-level data fields and event types for monitoring, develop an Elastic Agent deployment strategy and baseline policy structure, and select initial prebuilt Elastic Defend detection rules.
- Create a base agent policy in Fleet (to be cloned for each policy type), review core Elastic Security app and RBAC configuration, and finalize the list of detection rules to be activated.
- Configure and onboard agents for all five (5) Elastic Defend policy types, activate preselected detection rules in Kibana, and perform tuning, event filtering, and advanced rule/exception management.
- Conduct a knowledge transfer workshop, provide documentation and a final report, and transfer engagement assets to the customer.
Out of scope
This engagement does not include:
- Configuration or onboarding of endpoint/server policy types beyond the five (5) defined in Scope, or of device types outside the Elastic support matrix (https://www.elastic.co/support/matrix)
- Configuration, deployment, or licensing of Elastic SIEM itself; this engagement assumes an existing Elastic SIEM deployment is already in place
- Custom detection rule development beyond activation and tuning of prebuilt Elastic Defend rule content
- Configuration or testing of automated response actions (available under the Prevent tier)
- Threat hunting, incident response, or SOAR/case management configuration
- Evaluation, configuration, or integration of additional clusters, deployments, or environments
- Deployments or cluster sizing exceeding ten (10) nodes (self-managed)
- Project management beyond internal Elastic delivery coordination
- Ongoing support, operational ownership, or post-engagement remediation assistance unless separately purchased
Any work outside the scope above requires a mutually executed Order Form (change order) and may result in additional fees, revised assumptions, and schedule changes.
Engagement timeline
- Scheduled to commence approximately 6–8 weeks after purchase, subject to resource availability and Customer readiness
- Delivered by an Elastic Consultant or a certified partner resource under Elastic oversight
- Unless otherwise agreed in writing, the services will be delivered remotely
- Delivery is expected to occur over contiguous business days or contiguous calendar weeks, as scheduled by Elastic
- If delivery is delayed, interrupted, or rescheduled due to Customer availability, access issues, environment readiness, or other Customer dependencies, Elastic may reassign resources, adjust the schedule, or require an Order Form (change order)
- Time scheduled for the engagement that cannot be used due to Customer delay, unavailability, failure to meet dependencies, or inability to provide required access will count against the total consulting days
Fixed-price conditions and assumptions
The fixed price is based on the following assumptions and conditions:
- Customer provides all required access, credentials, documentation, and relevant architectural information before the kickoff call
- Customer designates a single point of contact and ensures appropriate technical stakeholders are available and responsive throughout the engagement
- Customer has an existing, accessible, and operational Elastic SIEM deployment in place prior to kickoff
- The target cluster (ECH, Serverless, or self-managed) is accessible, operational, and ready for configuration at the start of the engagement
- Customer objectives, priorities, and endpoint/server policy requirements are defined and agreed before kickoff
- The engagement is limited to configuration of up to five (5) endpoint/server policy types within the Elastic support matrix
- The engagement is limited to the configuration of one (1) cluster only, up to ten (10) nodes for self-managed deployments
- No material changes to scope, target environment, architecture, or objectives are introduced after kickoff
- Elastic's configuration and recommendations depend on the completeness, accuracy, and timeliness of the information and data provided by Customer or made available from the target environment during the engagement
If any of the above assumptions are not met, Elastic may adjust the schedule, limit the services performed to fit the fixed-price scope, or require an Order Form (change order).
Deliverables
- Five (5) device-specific policies (within the Elastic support matrix)
- Policy tuning for the five (5) device-specific policies (trusted applications, event filters, etc.)
- Elastic Defend detection rule tuning for the five (5) device-specific policies
- One (1) final report
- Engagement documentation
- One (1) knowledge transfer workshop
Completion
The engagement will be considered to have reached Completion upon delivery of the five (5) device-specific policies, policy tuning, detection rule tuning, the final report, and Elastic's delivery or making available of the knowledge transfer workshop. The engagement may also be deemed to have reached Completion if Customer delays, is unavailable, fails to meet required dependencies, or is otherwise unable to participate after Elastic has made commercially reasonable efforts to schedule and deliver the services within the agreed scope. Completion is not conditioned on Customer's participation in, use of, or response to any deliverable or session.
General terms
Capitalized terms used but not defined in this package description have the meanings given to them in the Order Form, the applicable Service Description, or the Elastic Services Agreement.
No formal Customer signoff and no milestone or deliverable acceptance process applies to this fixed-price Services Package. Each Service is deemed accepted upon Completion.
"Completion" means, with respect to a Service, the point at which Elastic has performed the activities within the scope of this Services Package, including (where applicable) delivery of any written report, materials, or knowledge transfer session described in this package's scope, or the expiry of the time-boxed engagement period for this package, whichever occurs first. Completion does not require Customer signoff or acceptance of any deliverable.
Customer is solely responsible for the backup, maintenance, and security of its environment, systems, and data. Elastic is not responsible for any configuration changes, data loss, downtime, or other impact to Customer's environment arising from or in connection with the Service.
This engagement delivers a configured Elastic Defend solution, including endpoint policy configuration, detection rule tuning, and a final report, within the defined fixed-price scope. Elastic does not guarantee any specific performance, cost, operational, or business outcome beyond the deliverables defined above. Customer remains solely responsible for ongoing operations, configuration changes made outside the engagement scope, and all post-engagement activities related to its environment.
Prevent
Overview
A fixed-price, time-boxed implementation engagement to deploy a foundational Elastic Defend solution providing endpoint protection and visibility for threat prevention, detection, and investigation on endpoints, for existing Elastic SIEM customers extending their deployment to include Elastic Defend. This engagement covers one (1) cluster only — Elastic Cloud Hosted (ECH), Serverless, or self-managed (up to ten (10) nodes) — on an existing Elastic SIEM deployment. Any additional clusters, deployments, environments, or expanded scope are expressly out of scope unless otherwise agreed in a mutually executed Order Form (change order).
Scope
- Conduct discovery, finalize up to five (5) in-scope endpoint/server policy types (within the Elastic support matrix), define high-level data fields and event types for monitoring, develop an Elastic Agent deployment strategy and baseline policy structure, and select initial prebuilt Elastic Defend detection rules.
- Create a base agent policy in Fleet (to be cloned for each policy type), review core Elastic Security app and RBAC configuration, and finalize the list of detection rules to be activated.
- Sequentially configure and onboard agents for all five (5) Elastic Defend policy types, activate and tune detection rules for each, conduct global rule tuning, manage exceptions and trusted applications, and configure/test automated response actions.
- Conduct a knowledge transfer workshop, provide documentation and a final report, and transfer engagement assets to the customer.
Out of scope
This engagement does not include:
- Configuration or onboarding of endpoint/server policy types beyond the five (5) defined in Scope, or of device types outside the Elastic support matrix (https://www.elastic.co/support/matrix)
- Configuration, deployment, or licensing of Elastic SIEM itself; this engagement assumes an existing Elastic SIEM deployment is already in place
- Custom detection rule development beyond activation, tuning, and automated response action configuration of prebuilt Elastic Defend rule content
- Threat hunting, incident response, or SOAR/case management configuration
- Evaluation, configuration, or integration of additional clusters, deployments, or environments
- Deployments or cluster sizing exceeding ten (10) nodes (self-managed)
- Project management beyond internal Elastic delivery coordination
- Ongoing support, operational ownership, or post-engagement remediation assistance unless separately purchased
Any work outside the scope above requires a mutually executed Order Form (change order) and may result in additional fees, revised assumptions, and schedule changes.
Engagement timeline
- Scheduled to commence approximately 6–8 weeks after purchase, subject to resource availability and Customer readiness
- Delivered by an Elastic Consultant or a certified partner resource under Elastic oversight
- Unless otherwise agreed in writing, the services will be delivered remotely
- Delivery is expected to occur over contiguous business days or contiguous calendar weeks, as scheduled by Elastic
- If delivery is delayed, interrupted, or rescheduled due to Customer availability, access issues, environment readiness, or other Customer dependencies, Elastic may reassign resources, adjust the schedule, or require an Order Form (change order)
- Time scheduled for the engagement that cannot be used due to Customer delay, unavailability, failure to meet dependencies, or inability to provide required access will count against the total consulting days
Fixed-price conditions and assumptions
The fixed price is based on the following assumptions and conditions:
- Customer provides all required access, credentials, documentation, and relevant architectural information before the kickoff call
- Customer designates a single point of contact and ensures appropriate technical stakeholders are available and responsive throughout the engagement
- Customer has an existing, accessible, and operational Elastic SIEM deployment in place prior to kickoff
- The target cluster (ECH, Serverless, or self-managed) is accessible, operational, and ready for configuration at the start of the engagement
- Customer objectives, priorities, and endpoint/server policy requirements are defined and agreed before kickoff
- The engagement is limited to configuration of up to five (5) endpoint/server policy types within the Elastic support matrix
- The engagement is limited to the configuration of one (1) cluster only, up to ten (10) nodes for self-managed deployments
- No material changes to scope, target environment, architecture, or objectives are introduced after kickoff
- Elastic's configuration and recommendations depend on the completeness, accuracy, and timeliness of the information and data provided by Customer or made available from the target environment during the engagement
If any of the above assumptions are not met, Elastic may adjust the schedule, limit the services performed to fit the fixed-price scope, or require an Order Form (change order).
Deliverables
- Five (5) device-specific policies (within the Elastic support matrix)
- Policy tuning for the five (5) device-specific policies (trusted applications, event filters, etc.)
- Elastic Defend detection rule tuning for the five (5) device-specific policies
- Configured and tested automated response actions
- One (1) final report
- Engagement documentation
- One (1) knowledge transfer workshop
Completion
The engagement will be considered to have reached Completion upon delivery of the five (5) device-specific policies, policy tuning, detection rule tuning, configured automated response actions, the final report, and Elastic's delivery or making available of the knowledge transfer workshop. The engagement may also be deemed to have reached Completion if Customer delays, is unavailable, fails to meet required dependencies, or is otherwise unable to participate after Elastic has made commercially reasonable efforts to schedule and deliver the services within the agreed scope. Completion is not conditioned on Customer's participation in, use of, or response to any deliverable or session.
General terms
Capitalized terms used but not defined in this package description have the meanings given to them in the Order Form, the applicable Service Description, or the Elastic Services Agreement.
No formal Customer signoff and no milestone or deliverable acceptance process applies to this fixed-price Services Package. Each Service is deemed accepted upon Completion.
"Completion" means, with respect to a Service, the point at which Elastic has performed the activities within the scope of this Services Package, including (where applicable) delivery of any written report, materials, or knowledge transfer session described in this package's scope, or the expiry of the time-boxed engagement period for this package, whichever occurs first. Completion does not require Customer signoff or acceptance of any deliverable.
Customer is solely responsible for the backup, maintenance, and security of its environment, systems, and data. Elastic is not responsible for any configuration changes, data loss, downtime, or other impact to Customer's environment arising from or in connection with the Service.
This engagement delivers a configured Elastic Defend solution, including endpoint policy configuration, detection rule tuning, automated response action configuration, and a final report, within the defined fixed-price scope. Elastic does not guarantee any specific performance, cost, operational, or business outcome beyond the deliverables defined above. Customer remains solely responsible for ongoing operations, configuration changes made outside the engagement scope, and all post-engagement activities related to its environment.