elastic / elastic/endpoint-package

[Elastic Defend] Align Integration docs with Elastic Defend Policy

Open
#522 3 comments 1 reaction 0 assignees View on GitHub
Dominant language
Python
Stars
33
Forks
20
Avg merge
2d 16h
Merged PRs (30d)
5

Description

I noticed that in the Integration Documentation for Elastic Defend, there appears to be a discrepancy between the events that can be enabled by the policy versus what is provided in the integration.

For example, I would expect to see where does `Driver and DLL Load` events exist in the integration field docs. Another is the `DNS` events, even though I can assume they live in `Network`

https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html#event-collection
![image](https://github.com/elastic/integrations/assets/5582679/a1c8e570-5497-42d5-aa0a-c486b587eca2)

https://docs.elastic.co/en/integrations/endpoint#logs
![image](https://github.com/elastic/integrations/assets/5582679/f76f1f7e-4dea-4bec-94a1-024f0b22c89a)

## Current:
Defend Policy Event Collection:
**DLL and Driver Load** Not in integration docs
**DNS** Not in integration docs
File
Network
Process
Registry
Security

Defend Integration Field Docs:
Alerts* Assumed from detect/prevent capabilities
File
**Library** Maybe DLL and Driver Load but unclear
Network
Process
Registry
Security

## Expectation:
Defend Integration Field Docs:
Alerts
DLL and Driver Load*
DNS*
File
Library*** Remove? Or rename to DLL and Driver Load / sync with terminology from Elastic Defend?
Network
Process
Registry
Security

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.