# Elastic Defend integration: Is there a way to identify if an alert is caused due to prevention or detection?

**URL:** <https://discuss.elastic.co/t/elastic-defend-integration-is-there-a-way-to-identify-if-an-alert-is-caused-due-to-prevention-or-detection/354179>\
**Category:** Elastic Security\
**Created:** [February 27, 2024, 6:43am UTC](https://discuss.elastic.co/t/elastic-defend-integration-is-there-a-way-to-identify-if-an-alert-is-caused-due-to-prevention-or-detection/354179 "2024-02-27T06:43:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Krishna\_Teja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krishna_teja/32/104976_2.png) [@Krishna\_Teja](https://discuss.elastic.co/u/Krishna_Teja)\
**Post date:** [February 27, 2024, 6:43am UTC](https://discuss.elastic.co/t/elastic-defend-integration-is-there-a-way-to-identify-if-an-alert-is-caused-due-to-prevention-or-detection/354179/1 "2024-02-27T06:43:21Z")

</div>

Hi

I'm using Endpoint Defend integration on a few agents. I want to know if an alert created was due to detection or prevention so I can trigger actions based on the status. Is there a way to identify the same?

Also, can someone provide me some ways to trigger a few prevention and detection style alerts for elastic defend for testing. I was able to get prevention alerts by running an application but am unable to get any detection alerts.

Attached screenshots of Elastic Defend setttings.

Regards  
Krishna

 ![defend-settings-1](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0ec46d7efde5eebef5acc76505ad7e1241c6fb75.png)  
 ![defend-settings-2](https://us1.discourse-cdn.com/elastic/original/3X/2/1/2143db885fc7e1e32e201c53a8c22c18063cb71b.png)

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [February 27, 2024, 3:49pm UTC](https://discuss.elastic.co/t/elastic-defend-integration-is-there-a-way-to-identify-if-an-alert-is-caused-due-to-prevention-or-detection/354179/2 "2024-02-27T15:49:44Z")

</div>

Hi @Krishna_Teja

The easiest way to determine prevention from detection alerts is to look for the word "Detection" or "Prevention" in the top level `message` field. Will that work for you?

You can trigger benign alerts by making sure Malware protection is enabled then saving the EICAR file to the computer. (You can download EICAR from this page [https://www.eicar.org/download-anti-malware-testfile/](https://www.eicar.org/download-anti-malware-testfile/)). EICAR is a standard antivirus testing file. I recommend downloading `EICAR.TXT` from that website.

I hope that helps.

---

<div class="post-metadata">

**Author:** ![Krishna\_Teja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krishna_teja/32/104976_2.png) [@Krishna\_Teja](https://discuss.elastic.co/u/Krishna_Teja)\
**Post date:** [February 27, 2024, 5:19pm UTC](https://discuss.elastic.co/t/elastic-defend-integration-is-there-a-way-to-identify-if-an-alert-is-caused-due-to-prevention-or-detection/354179/3 "2024-02-27T17:19:07Z")

</div>

Hello Ferullo

Thanks for sharing the details. This is really helpful. I'll check with the file.

Regards  
Krishna

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 26, 2024, 5:19pm UTC](https://discuss.elastic.co/t/elastic-defend-integration-is-there-a-way-to-identify-if-an-alert-is-caused-due-to-prevention-or-detection/354179/4 "2024-03-26T17:19:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
