Large File Storage (Export Function)
- Dominant language
- No language data
- Stars
- 6
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
Elastic is extending endpoint response actions to support exporting large files (including forensic artifacts and collected files) directly to customer-managed remote storage, such as Azure Blob Storage.
**Value proposition**
Elastic is built for detection, investigation, and response, not for long-term file storage. When analysts collect large forensic artifacts from endpoints, storing them inside the platform creates operational overhead and conflicts with how security teams manage evidence retention. By routing large artifact exports directly to customer-owned remote storage, analysts can collect what they need at scale, while keeping evidence in the right place: their own infrastructure, governed by their own data retention and compliance policies.
**Expected outcome**
- Analysts can export large files and forensic artifacts from endpoints directly to a configured remote storage target (e.g. Azure Blob Storage) during live response
- Storage credentials and configuration are securely managed within the platform
- All export operations are logged and auditable in Kibana's Response Actions History
**Key user stories / use cases**
**As a** Security Analyst / Incident Responder,
**I want to** export forensic artifacts from endpoints directly to my organization's remote storage during a live response,
**so that** I can collect large files without cluttering the platform and ensure evidence lands in the right place for long-term retention.
**As a** SOC Engineer,
**I want to** configure a trusted remote storage destination for file exports,
**so that** evidence is stored securely and in compliance with my organization's data retention and compliance policies.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.