Manage Elastic Security

After you deploy Elastic Security, you return to these tasks as your environment and team change. Tune protection policies, manage exceptions, control who can use each feature, and decide which data the Elastic Security app shows.

For one-time deployment tasks, such as installing Elastic Defend or connecting your cloud accounts, refer to Set up.

Elastic Security settings apply at different levels, so a change in one place can affect more than one host or user:

  • Integration policies control protection on your hosts and workloads. Elastic Defend and Defend for Containers policies are part of Elastic Agent policies, so each change applies to every host that uses that policy.
  • Roles control what each user can view and do. Each feature has its own privileges, and you assign them to roles.
  • Spaces separate your security content. Detection rules, exceptions, alerts, Timelines, and cases in one Kibana space aren't visible in other spaces. You can also scope Elastic Defend policies, artifacts, and response actions by space.
  • Data views control which indices the Elastic Security app reads in each space.
Your goal Start here
Monitor protected endpoints, tune policies, or reduce false positives from Elastic Defend Manage Elastic Defend
Detect and block threats on Linux VMs and Kubernetes workloads at runtime Manage cloud workload protection
Give users the access they need for each feature Access control
Organize security content into spaces, or change which data the Elastic Security app shows Configure workspace settings

After you configure your environment, you can: