Set up Elastic Security

Deploy the Elastic Security protections that cover your hosts, cloud accounts, and Kubernetes clusters. You do these tasks once for each feature, when you first turn it on.

After setup, each feature sends its data to Elastic Security, where you can review alerts, findings, and risk scores. To tune policies, manage exceptions, and control access after deployment, refer to Manage.

Each protection covers a different part of your environment, so the features you set up depend on what you run:

  • Elastic Defend: Protects Windows, macOS, and Linux hosts, including Linux VMs in the cloud. It runs on Elastic Agent, which you install on each host. It can detect or block malware, ransomware, and malicious behavior.
  • Cloud security: Checks your cloud accounts and Kubernetes clusters against security best practices, lists your cloud assets, and scans your AWS EC2 Linux workloads for known vulnerabilities.
  • Defend for Containers: Detects, and can block, unexpected behavior inside running Kubernetes containers.
Your goal Start here
Protect hosts from malware, ransomware, and malicious behavior Configure endpoint protection with Elastic Defend
Check your cloud accounts and Kubernetes clusters for misconfigurations and vulnerabilities Set up cloud security
Protect Kubernetes workloads at runtime Get started with Defend for Containers for Kubernetes
Check what you need for entity risk scoring, asset criticality, and the entity store Entity analytics requirements
Check what you need to run machine learning jobs and rules Machine learning job and rule requirements

After you set up your protections, you can: