Manage Elastic Defend
After deploying Elastic Defend, you can manage your protected endpoints, tune policies, and create exceptions to reduce false positives — all from within Elastic Security. These management tools give you centralized control over endpoint protection across your environment.
Elastic Security provides dedicated pages for each management area. Find them in the navigation menu or by using the global search field. Use them to monitor endpoint health, adjust protection policies, and define exceptions that keep Elastic Defend running smoothly alongside your existing software and workflows.
| Your goal | Start here |
|---|---|
| View and monitor protected endpoints | Endpoints |
| Adjust protection settings or event collection | Policies → Configure an integration policy |
| Reduce false positives from known software | Trusted applications → Event filters |
| Suppress false positive Elastic Endpoint alerts | Elastic Endpoint exceptions |
| Block known malicious applications | Blocklist |
| Understand different Elastic Endpoint configuration settings | Optimize Elastic Defend |
| Diagnose problems with Elastic Defend | Automatic troubleshooting → Troubleshoot Elastic Defend |
| Prevent users from removing Elastic Agent, or remove it from a host | Prevent Elastic Agent uninstallation → Uninstall Elastic Agent |
The Endpoints page shows every host running Elastic Defend, including its status, policy assignment, and operating system. Use it to verify that endpoints are healthy, check which policy each host is using, and drill into individual endpoint details.
The Policies page lists all Elastic Defend integration policies. From here, you can open a policy to adjust its protection levels, event collection settings, and advanced options.
To configure those settings, refer to Configure an integration policy for Elastic Defend. To change a specific part of a policy, refer to:
- Configure updates for protection artifacts: Control how Elastic Defend receives the latest threat detections, malware models, and other protection artifacts.
- Configure Linux file system monitoring: Set which file systems Elastic Defend monitors on Linux hosts.
- Create an Elastic Defend policy using the API: Create and customize a policy without the UI.
- Configure offline endpoints and air-gapped environments: Keep protection artifacts up to date on hosts that can't reach Elastic's servers.
Endpoint artifacts let you tailor Elastic Defend behavior to your environment, reducing noise without weakening protection. They include trusted applications, trusted devices, event filters, host isolation exceptions, blocklist entries, and Elastic Endpoint exceptions. Each type changes a different behavior, so compare them in Optimize Elastic Defend before you create one.
Elastic Defend includes built-in protection features and prebuilt detection rules that help secure your endpoints and prevent tampering.
- Endpoint protection rules: Prebuilt detection rules that help you manage and respond to alerts generated by Elastic Endpoint, including rules for malware, ransomware, memory threats, and malicious behavior.
- Elastic Endpoint self-protection: Built-in tamper protection that prevents users and attackers from interfering with Elastic Endpoint functionality.
- Allowlist Elastic Endpoint in third-party antivirus apps: Add Elastic Endpoint's digital signatures and file paths to your antivirus software's allowlist to prevent conflicts.
- Configure self-healing rollback for Windows endpoints: Erase attack artifacts that a malicious process deployed before Elastic Defend detected it.
Use these tools to diagnose issues, reduce resource usage, and understand how Elastic Defend collects event data.
- Automatic troubleshooting: Identify and resolve common issues that could prevent Elastic Defend from working as intended, including policy response errors and third-party antivirus conflicts.
- Event capture and Elastic Defend: Understand how Elastic Defend collects, aggregates, and deduplicates system event data to balance threat detection with storage and performance overhead.
- Troubleshoot Elastic Defend: Resolve common issues such as Elastic Agent connectivity problems, policy failures, and malware prevention errors.
- Turn off diagnostic data for Elastic Defend: Stop Elastic Defend from streaming the diagnostic data Elastic uses to tune protection features.
- Configure data volume: Change how much data Elastic Endpoint processes and ingests, and understand the effect on storage and CPU usage.
- Prevent Elastic Agent uninstallation: Turn on agent tamper protection so users can't bypass or turn off endpoint protection.
- Uninstall Elastic Agent: Remove Elastic Agent from a host.
- Configure endpoint protection with Elastic Defend: Install Elastic Defend and set up integration policies.
- Endpoint response actions: Isolate hosts, run commands, and take other response actions on protected endpoints.