# Elastic Security

**URL:** https://discuss.elastic.co/c/security/83.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [About the Elastic Security category](https://discuss.elastic.co/t/about-the-elastic-security-category/235256)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 0\
**Last updated:** [June 2, 2020, 12:08am UTC](https://discuss.elastic.co/t/about-the-elastic-security-category/235256 "2020-06-02T00:08:50Z")

</div>

Unified protection, from the creators of the Elastic Stack Integrate free and open SIEM, and endpoint, to prevent, detect, and respond to threats.

---

## [Sharing my rule update experience on Elastic Security Serverless](https://discuss.elastic.co/t/sharing-my-rule-update-experience-on-elastic-security-serverless/389853)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 13\
**Last updated:** [September 25, 2026, 12:27pm UTC](https://discuss.elastic.co/t/sharing-my-rule-update-experience-on-elastic-security-serverless/389853 "2026-09-25T12:27:47Z")

</div>

Hello, Just sharing my experience updating Elastic prebuilt Security rules after being away for about 1.5 months. When I logged back in, I had roughly 1,200 rule updates waiting. That is fine in itself - I clicked Upda…

---

## [Elastic defend (Automatic Response Action Isnt Working )](https://discuss.elastic.co/t/elastic-defend-automatic-response-action-isnt-working/390597)

<div class="topic-metadata">

**Author:** [@jatin3101](https://discuss.elastic.co/u/jatin3101)\
**Replies:** 1\
**Last updated:** [September 25, 2026, 9:17am UTC](https://discuss.elastic.co/t/elastic-defend-automatic-response-action-isnt-working/390597 "2026-09-25T09:17:29Z")

</div>

Hi , i came across this problem that my response action arent working & somehad the same issue but their was solved and i dont undertsand how detection rule- firewall disabled issue- want to run a script for enablin…

---

## [Integration with omega-scan](https://discuss.elastic.co/t/integration-with-omega-scan/390677)

<div class="topic-metadata">

**Author:** [@wessorh](https://discuss.elastic.co/u/wessorh)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:07am UTC](https://discuss.elastic.co/t/integration-with-omega-scan/390677 "2026-09-25T08:07:24Z")

</div>

I'm interested in testing a opensource sample scanner called omega-scan and am looking for documentation on what capabilities there are for calling 3rd party file scanners. A pointer would be greatly appreciated.

---

## [RFC: Disable automatic refresh in event analyzer](https://discuss.elastic.co/t/rfc-disable-automatic-refresh-in-event-analyzer/390600)

<div class="topic-metadata">

**Author:** [@michael-a](https://discuss.elastic.co/u/michael-a)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 8:35am UTC](https://discuss.elastic.co/t/rfc-disable-automatic-refresh-in-event-analyzer/390600 "2026-09-23T08:35:03Z")

</div>

When analyzing events from detections/alerts with automatic refresh, the analyze view automatically refresh too which isn't necessarily what one wants. Therefore it would be better if the automatic refresh either would t…

---

## [DNS Activity Data from Elastic Defend](https://discuss.elastic.co/t/dns-activity-data-from-elastic-defend/390171)

<div class="topic-metadata">

**Author:** [@RalphDibney](https://discuss.elastic.co/u/RalphDibney)\
**Replies:** 7\
**Last updated:** [September 10, 2026, 8:58am UTC](https://discuss.elastic.co/t/dns-activity-data-from-elastic-defend/390171 "2026-09-10T08:58:51Z")

</div>

Hey Elastic Community, after realizing that our Elastic Defend DNS data collected in our Windows machines has some data missing, we found some threads here in the community about it: Missing DNS requests on Windows mac…

---

## [Can Elastic Defend Event Collection interfere with software installation?](https://discuss.elastic.co/t/can-elastic-defend-event-collection-interfere-with-software-installation/389935)

<div class="topic-metadata">

**Author:** [@marrc.rousseau](https://discuss.elastic.co/u/marrc.rousseau)\
**Replies:** 5\
**Last updated:** [September 9, 2026, 4:43pm UTC](https://discuss.elastic.co/t/can-elastic-defend-event-collection-interfere-with-software-installation/389935 "2026-09-09T16:43:35Z")

</div>

Hello, I have a Windows server on which Elastic Defend is enabled, but only the Event Collection component is active. Nothing else is enabled — no malware protection, no ransomware protection, etc... The sole purpose i…

---

## [Elastic Defend Service Enhancement](https://discuss.elastic.co/t/elastic-defend-service-enhancement/389619)

<div class="topic-metadata">

**Author:** [@Shailesk](https://discuss.elastic.co/u/Shailesk)\
**Replies:** 1\
**Last updated:** [August 28, 2026, 8:52pm UTC](https://discuss.elastic.co/t/elastic-defend-service-enhancement/389619 "2026-08-28T20:52:54Z")

</div>

\*"Elastic Defend scan response action should include scan statistics in the response payload: files scanned count, threats detected count, and scan duration breakdown." \* Reference the field path where it should appear…

---

## [Prevent to create global exceptions for space user](https://discuss.elastic.co/t/prevent-to-create-global-exceptions-for-space-user/389911)

<div class="topic-metadata">

**Author:** [@adamsmesher](https://discuss.elastic.co/u/adamsmesher)\
**Replies:** 1\
**Last updated:** [August 25, 2026, 12:30pm UTC](https://discuss.elastic.co/t/prevent-to-create-global-exceptions-for-space-user/389911 "2026-08-25T12:30:02Z")

</div>

Any ability to prevent users from another space from creating "global" exceptions? Goal is to add permissions to add endpoint exceptions only for policies which related only to specific space.

---

## [False Positive](https://discuss.elastic.co/t/false-positive/389749)

<div class="topic-metadata">

**Author:** [@jedikeeper](https://discuss.elastic.co/u/jedikeeper)\
**Replies:** 7\
**Last updated:** [August 24, 2026, 9:49pm UTC](https://discuss.elastic.co/t/false-positive/389749 "2026-08-24T21:49:27Z")

</div>

Hello, I understand that false positives require manual analysis by malware engineers, and that you will only take action if the False Positive is officially confirmed to be 100% safe. However, please understand that en…

---

## [Process Tree Analyzer from custom space issue](https://discuss.elastic.co/t/process-tree-analyzer-from-custom-space-issue/389894)

<div class="topic-metadata">

**Author:** [@adamsmesher](https://discuss.elastic.co/u/adamsmesher)\
**Replies:** 0\
**Last updated:** [August 24, 2026, 4:48pm UTC](https://discuss.elastic.co/t/process-tree-analyzer-from-custom-space-issue/389894 "2026-08-24T16:48:23Z")

</div>

The /api/endpoint/resolver/tree endpoint crashes when queried from within a custom Kibana Space (like sandbox), pointing to a backend routing or permissions bug. stack version - 9.5.1 /s/sandbox/api/endpoint/resolver/…

---

## [Device control enabled without license](https://discuss.elastic.co/t/device-control-enabled-without-license/388399)

<div class="topic-metadata">

**Author:** [@jumpingrock](https://discuss.elastic.co/u/jumpingrock)\
**Replies:** 4\
**Last updated:** [August 19, 2026, 4:40pm UTC](https://discuss.elastic.co/t/device-control-enabled-without-license/388399 "2026-08-19T16:40:30Z")

</div>

My stack is running on 9.4.3. It was a fresh install to that version. I have created a fleet policy with Elastic Defend. Where device control would be, I have this warning Device Control Upgrade to Elastic Enterpris…

---

## [Auditd Logs 3.24.1 - "Use auditd parser" fails on Elastic 9.3.3 with Missing helper: semverSatisfies](https://discuss.elastic.co/t/auditd-logs-3-24-1-use-auditd-parser-fails-on-elastic-9-3-3-with-missing-helper-semversatisfies/389780)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [August 19, 2026, 2:20pm UTC](https://discuss.elastic.co/t/auditd-logs-3-24-1-use-auditd-parser-fails-on-elastic-9-3-3-with-missing-helper-semversatisfies/389780 "2026-08-19T14:20:03Z")

</div>

Hi all, We are testing the latest Auditd Logs integration, version 3.24.1, on an Elastic Stack running 9.3.3. The integration now has the experimental option: Use auditd parser (experimental) The description sounds…

---

## [Multiple Machine Learning Alerts by Influencer Field failing Unknown column \[job\_id\]](https://discuss.elastic.co/t/multiple-machine-learning-alerts-by-influencer-field-failing-unknown-column-job-id/389743)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [August 18, 2026, 7:29am UTC](https://discuss.elastic.co/t/multiple-machine-learning-alerts-by-influencer-field-failing-unknown-column-job-id/389743 "2026-08-18T07:29:47Z")

</div>

Hello, I am seeing the prebuilt rule Multiple Machine Learning Alerts by Influencer Field fail with: verification\_exception Unknown column \[job\_id\] Unknown column \[influencers.influencer\_field\_name\] Unknown column \[inf…

---

## [.../config/certs/ca/ca.crt : file does not exist](https://discuss.elastic.co/t/config-certs-ca-ca-crt-file-does-not-exist/389678)

<div class="topic-metadata">

**Author:** [@rik](https://discuss.elastic.co/u/rik)\
**Replies:** 2\
**Last updated:** [August 16, 2026, 5:37pm UTC](https://discuss.elastic.co/t/config-certs-ca-ca-crt-file-does-not-exist/389678 "2026-08-16T17:37:39Z")

</div>

I think I've followed the instructions here Install Elasticsearch with Docker | Elastic Docs and produced a docker-compose.yml file (attached below) that's right. But when I try docker compose up i get these errors: {"…

---

## [Elastic Partition Problem](https://discuss.elastic.co/t/elastic-partition-problem/388924)

<div class="topic-metadata">

**Author:** [@jatin3101](https://discuss.elastic.co/u/jatin3101)\
**Replies:** 2\
**Last updated:** [July 31, 2026, 4:32pm UTC](https://discuss.elastic.co/t/elastic-partition-problem/388924 "2026-07-31T16:32:03Z")

</div>

Just came across a prolem from the start i was installing elastic(Elasticsearch-kibana-logstash) via packge mangers either apt or deb packages (DPKG) so the storage is handled by them only but in splunk we used to make…

---

## [Secops-es-benchmark: an open benchmark for AI security agents on real Elasticsearch telemetry](https://discuss.elastic.co/t/secops-es-benchmark-an-open-benchmark-for-ai-security-agents-on-real-elasticsearch-telemetry/388910)

<div class="topic-metadata">

**Author:** [@azmatjan139](https://discuss.elastic.co/u/azmatjan139)\
**Replies:** 0\
**Last updated:** [July 30, 2026, 4:13pm UTC](https://discuss.elastic.co/t/secops-es-benchmark-an-open-benchmark-for-ai-security-agents-on-real-elasticsearch-telemetry/388910 "2026-07-30T16:13:07Z")

</div>

secops-es-benchmark: an open benchmark for AI agents that investigate breaches in Elasticsearch Real, labeled attack telemetry in Elasticsearch — measure your own agent against ground truth. Today I'm open-sourcing seco…

---

## [Sizing Guide](https://discuss.elastic.co/t/sizing-guide/388811)

<div class="topic-metadata">

**Author:** [@jatin3101](https://discuss.elastic.co/u/jatin3101)\
**Replies:** 1\
**Last updated:** [July 27, 2026, 12:07pm UTC](https://discuss.elastic.co/t/sizing-guide/388811 "2026-07-27T12:07:42Z")

</div>

I need an official documentation or any official way suggesting a rough log consumption estimate Gb/day for list of data sources --like i have list which include firewall - count 10 - eps?-byte size? switch - count 5 -…

---

## [Adding Tags to Elastic Endpoint Security Prebuilt rule](https://discuss.elastic.co/t/adding-tags-to-elastic-endpoint-security-prebuilt-rule/388799)

<div class="topic-metadata">

**Author:** [@Harry123](https://discuss.elastic.co/u/Harry123)\
**Replies:** 0\
**Last updated:** [July 26, 2026, 3:50pm UTC](https://discuss.elastic.co/t/adding-tags-to-elastic-endpoint-security-prebuilt-rule/388799 "2026-07-26T15:50:22Z")

</div>

I have a question regarding elastic's endpoint security rule which has sub rules in it when you enable it. Like for example the malware detection alert. I want to put a tag on one of its sub rule but in the rules I canno…

---

## [Feedback for ransomware correlation using Elastic](https://discuss.elastic.co/t/feedback-for-ransomware-correlation-using-elastic/388311)

<div class="topic-metadata">

**Author:** [@After\_Marsupial\_3531](https://discuss.elastic.co/u/After_Marsupial_3531)\
**Replies:** 3\
**Last updated:** [July 13, 2026, 4:40pm UTC](https://discuss.elastic.co/t/feedback-for-ransomware-correlation-using-elastic/388311 "2026-07-13T16:40:28Z")

</div>

Hello everyone, I'm currently working on an Alert/workflow that aims to proactively trigger when a ransomware pattern is detected. Our SOC uses Elastic Security as both the SIEM and EDR. To build it, I started from rea…

---

## [Managing Ammunition Link Inventory Data with Search and Analytics Systems](https://discuss.elastic.co/t/managing-ammunition-link-inventory-data-with-search-and-analytics-systems/387712)

<div class="topic-metadata">

**Author:** [@gamerlook](https://discuss.elastic.co/u/gamerlook)\
**Replies:** 0\
**Last updated:** [July 7, 2026, 2:03pm UTC](https://discuss.elastic.co/t/managing-ammunition-link-inventory-data-with-search-and-analytics-systems/387712 "2026-07-07T14:03:56Z")

</div>

Hello everyone, I am exploring how large technical inventories can be organized and searched efficiently using modern data platforms. In industries where components such as ammunition links, connectors, or mechanical pa…

---

## [Endpoint does not show up in Asset management page](https://discuss.elastic.co/t/endpoint-does-not-show-up-in-asset-management-page/387505)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 3\
**Last updated:** [July 3, 2026, 6:51pm UTC](https://discuss.elastic.co/t/endpoint-does-not-show-up-in-asset-management-page/387505 "2026-07-03T18:51:03Z")

</div>

Hello, I have a deployment on Elastic Cloud for tests and I'm doing a test with Elastic Defend. I have a policy that has Elastic Defend configured with 1 agent enrolled with healthy status. But when I go into Asset…

---

## [Optimizing Incident Triaging via Kibana Case Integration](https://discuss.elastic.co/t/optimizing-incident-triaging-via-kibana-case-integration/387480)

<div class="topic-metadata">

**Author:** [@reports](https://discuss.elastic.co/u/reports)\
**Replies:** 0\
**Last updated:** [July 2, 2026, 3:03pm UTC](https://discuss.elastic.co/t/optimizing-incident-triaging-via-kibana-case-integration/387480 "2026-07-02T15:03:22Z")

</div>

I have created security rules in Kibana and integrated the Cases action to enable auto-generated cases. Initially, I faced a limitation where I couldn't customize the case payload to extract critical alert details. This …

---

## [Defend for Containers (D4C) integration with OPENSHIFT](https://discuss.elastic.co/t/defend-for-containers-d4c-integration-with-openshift/387268)

<div class="topic-metadata">

**Author:** [@Mohamed\_Nada](https://discuss.elastic.co/u/Mohamed_Nada)\
**Replies:** 1\
**Last updated:** [June 30, 2026, 1:31pm UTC](https://discuss.elastic.co/t/defend-for-containers-d4c-integration-with-openshift/387268 "2026-06-30T13:31:40Z")

</div>

I am looking for some insight into a hard kernel verifier rejection we are hitting with the Defend for Containers (D4C) integration. The Activity & Purpose We are deploying Elastic Agent (9.4.2) via Fleet on an OpenShif…

---

## [Defend for containers integration failed on OpenShift environment](https://discuss.elastic.co/t/defend-for-containers-integration-failed-on-openshift-environment/387356)

<div class="topic-metadata">

**Author:** [@Mohamed\_Nada](https://discuss.elastic.co/u/Mohamed_Nada)\
**Replies:** 1\
**Last updated:** [June 27, 2026, 2:08am UTC](https://discuss.elastic.co/t/defend-for-containers-integration-failed-on-openshift-environment/387356 "2026-06-27T02:08:21Z")

</div>

kernel verifier rejection we are hitting with the Defend for Containers (D4C) integration. We are deploying Elastic Agent (9.4.2) via Fleet on an OpenShift cluster to utilize eBPF-based container runtime security and ac…

---

## [Trying to calculate MTTD (Mean Time To Detect)](https://discuss.elastic.co/t/trying-to-calculate-mttd-mean-time-to-detect/384517)

<div class="topic-metadata">

**Author:** [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Replies:** 4\
**Last updated:** [June 18, 2026, 12:00pm UTC](https://discuss.elastic.co/t/trying-to-calculate-mttd-mean-time-to-detect/384517 "2026-06-18T12:00:58Z")

</div>

Hello all, I have been trying to calculate the MTTD, which consists of the difference between the case creation date and the first update of the case. However, when updating the case, the updated\_at field gets updated a…

---

## [Custom App with authentication log](https://discuss.elastic.co/t/custom-app-with-authentication-log/386871)

<div class="topic-metadata">

**Author:** [@william.cheang](https://discuss.elastic.co/u/william.cheang)\
**Replies:** 8\
**Last updated:** [June 18, 2026, 3:29am UTC](https://discuss.elastic.co/t/custom-app-with-authentication-log/386871 "2026-06-18T03:29:12Z")

</div>

I have custom app with authentication log(consist of login success or failure activities, and logout activities), can I ingest these log directly into log.system.auth-\* ? After ingest direct to log.system.auth-\*, will t…

---

## [Cannot create Exception for Rule "Persistence via Extensible Firmware Modification"](https://discuss.elastic.co/t/cannot-create-exception-for-rule-persistence-via-extensible-firmware-modification/386795)

<div class="topic-metadata">

**Author:** [@RalphDibney](https://discuss.elastic.co/u/RalphDibney)\
**Replies:** 2\
**Last updated:** [June 15, 2026, 1:35pm UTC](https://discuss.elastic.co/t/cannot-create-exception-for-rule-persistence-via-extensible-firmware-modification/386795 "2026-06-15T13:35:28Z")

</div>

The Defend Rule "Malicious Behavior Prevention Alert: Persistence via Extensible Firmware Modification" gets triggered in our environment. The behavior is explainable and unproblematic, so we wanted to create an endpoint…

---

## [Feedback on the Security Solution Dashboard Experience](https://discuss.elastic.co/t/feedback-on-the-security-solution-dashboard-experience/386721)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 6\
**Last updated:** [June 15, 2026, 8:25am UTC](https://discuss.elastic.co/t/feedback-on-the-security-solution-dashboard-experience/386721 "2026-06-15T08:25:50Z")

</div>

Hello, I would like to share some feedback regarding the Security Solution dashboard experience in Kibana. While I appreciate the effort to provide a dedicated Security-focused dashboard experience, many users in our en…

---

## [False Positive Report — 4K\_Render\_Automation.exe — Malicious (high Confidence)](https://discuss.elastic.co/t/false-positive-report-4k-render-automation-exe-malicious-high-confidence/386586)

<div class="topic-metadata">

**Author:** [@Qu\_c\_Chau](https://discuss.elastic.co/u/Qu_c_Chau)\
**Replies:** 4\
**Last updated:** [June 4, 2026, 2:23pm UTC](https://discuss.elastic.co/t/false-positive-report-4k-render-automation-exe-malicious-high-confidence/386586 "2026-06-04T14:23:14Z")

</div>

Reporting a false positive for Elastic's malware detection engine. File: 4K\_Render\_Automation.exe SHA256: 8e8ab81e34a69221ff50b5b94f033cc31969cc39214efd0346f06a48957b991f Detection: Malicious (high Confidence) VT lin…

[Next page](https://discuss.elastic.co/c/security/83.md?page=1)
