Elastic medium stable kql

Endpoint Security (Elastic Defend)

Generates a detection alert each time an Elastic Defend alert is received. Enabling this rule allows you to immediately begin investigating your Endpoint alerts.

View Source

Detection Logic

event.kind:alert and event.module:(endpoint and not endgame)

Field Validations

Loading…

Comments (0)

Loading comments...