Manage Elastic Defend

After deploying Elastic Defend, you can manage your protected endpoints, tune policies, and create exceptions to reduce false positives — all from within Elastic Security. These management tools give you centralized control over endpoint protection across your environment.

Elastic Security provides dedicated pages for each management area. Find them in the navigation menu or by using the global search field. Use them to monitor endpoint health, adjust protection policies, and define exceptions that keep Elastic Defend running smoothly alongside your existing software and workflows.

Your goal Start here
View and monitor protected endpoints Endpoints
Adjust protection settings or event collection Policies → Configure an integration policy
Reduce false positives from known software Trusted applications → Event filters
Suppress false positive Elastic Endpoint alerts Elastic Endpoint exceptions
Block known malicious applications Blocklist
Understand different Elastic Endpoint configuration settings Optimize Elastic Defend
Diagnose problems with Elastic Defend Automatic troubleshooting → Troubleshoot Elastic Defend
Prevent users from removing Elastic Agent, or remove it from a host Prevent Elastic Agent uninstallation → Uninstall Elastic Agent

The Endpoints page shows every host running Elastic Defend, including its status, policy assignment, and operating system. Use it to verify that endpoints are healthy, check which policy each host is using, and drill into individual endpoint details.

The Policies page lists all Elastic Defend integration policies. From here, you can open a policy to adjust its protection levels, event collection settings, and advanced options.

To configure those settings, refer to Configure an integration policy for Elastic Defend. To change a specific part of a policy, refer to:

Endpoint artifacts let you tailor Elastic Defend behavior to your environment, reducing noise without weakening protection. They include trusted applications, trusted devices, event filters, host isolation exceptions, blocklist entries, and Elastic Endpoint exceptions. Each type changes a different behavior, so compare them in Optimize Elastic Defend before you create one.

Elastic Defend includes built-in protection features and prebuilt detection rules that help secure your endpoints and prevent tampering.

Use these tools to diagnose issues, reduce resource usage, and understand how Elastic Defend collects event data.

  • Automatic troubleshooting: Identify and resolve common issues that could prevent Elastic Defend from working as intended, including policy response errors and third-party antivirus conflicts.
  • Event capture and Elastic Defend: Understand how Elastic Defend collects, aggregates, and deduplicates system event data to balance threat detection with storage and performance overhead.
  • Troubleshoot Elastic Defend: Resolve common issues such as Elastic Agent connectivity problems, policy failures, and malware prevention errors.
  • Turn off diagnostic data for Elastic Defend: Stop Elastic Defend from streaming the diagnostic data Elastic uses to tune protection features.
  • Configure data volume: Change how much data Elastic Endpoint processes and ingests, and understand the effect on storage and CPU usage.