Endpoint artifacts
Use endpoint artifacts to adapt Elastic Defend to the software, devices, and network traffic in your environment. With artifacts, you can stop false positive alerts, avoid conflicts with other security tools, store less event data in Elasticsearch, and block applications that you know are malicious.
Each artifact type changes a different part of how Elastic Endpoint handles activity on the host. Some types prevent alerts, some prevent monitoring, and some keep Elasticsearch from storing events. Before you create an artifact, check which type fits your goal.
Keep these points in mind when you create artifacts:
- Artifacts apply to all hosts by default: A new artifact applies to every host running Elastic Defend. To limit it to some hosts, assign it to specific Elastic Defend integration policies instead. Elastic Endpoint exceptions support per-policy assignment only after you opt in.
-
One page lists every artifact type: Go to the Artifacts page, then select the tab for the artifact type that you want to manage. -
Spaces control who can edit an artifact: Global artifacts appear in every space. A per-policy artifact belongs to the space where you create it, and only users in that space or with the Global artifact management privilege can edit it. To learn more, refer to the Spaces and Elastic Defend FAQ.
| Your goal | Start here |
|---|---|
| Compare the artifact types and find the one that fits your goal | Optimize Elastic Defend |
| Stop Elastic Endpoint from generating alerts for activity that you expect | Elastic Endpoint exceptions |
| Avoid conflicts with other antivirus or endpoint security software | Trusted applications |
|
|
Trusted devices |
| Keep Elasticsearch from storing high-volume or low-value endpoint events | Event filters |
| Let isolated hosts communicate with specific IP addresses | Host isolation exceptions |
| Prevent known malicious applications from running | Blocklist |
| Check how to enter file paths and other values for each exception type | Exception types and value syntax |
After you create artifacts, you can:
- Give users the Elastic Defend feature privileges they need to view or manage each artifact type.
- Review endpoint protection rules to understand the alerts that Elastic Endpoint exceptions can prevent.