Endpoint artifacts

Use endpoint artifacts to adapt Elastic Defend to the software, devices, and network traffic in your environment. With artifacts, you can stop false positive alerts, avoid conflicts with other security tools, store less event data in Elasticsearch, and block applications that you know are malicious.

Each artifact type changes a different part of how Elastic Endpoint handles activity on the host. Some types prevent alerts, some prevent monitoring, and some keep Elasticsearch from storing events. Before you create an artifact, check which type fits your goal.

Keep these points in mind when you create artifacts:

  • Artifacts apply to all hosts by default: A new artifact applies to every host running Elastic Defend. To limit it to some hosts, assign it to specific Elastic Defend integration policies instead. Elastic Endpoint exceptions support per-policy assignment only after you opt in.
  • One page lists every artifact type: Go to the Artifacts page, then select the tab for the artifact type that you want to manage.
  • Spaces control who can edit an artifact: Global artifacts appear in every space. A per-policy artifact belongs to the space where you create it, and only users in that space or with the Global artifact management privilege can edit it. To learn more, refer to the Spaces and Elastic Defend FAQ.
Your goal Start here
Compare the artifact types and find the one that fits your goal Optimize Elastic Defend
Stop Elastic Endpoint from generating alerts for activity that you expect Elastic Endpoint exceptions
Avoid conflicts with other antivirus or endpoint security software Trusted applications
Allow specific USB storage devices to connect to protected hosts Trusted devices
Keep Elasticsearch from storing high-volume or low-value endpoint events Event filters
Let isolated hosts communicate with specific IP addresses Host isolation exceptions
Prevent known malicious applications from running Blocklist
Check how to enter file paths and other values for each exception type Exception types and value syntax

After you create artifacts, you can: