# Elastic Defend - Is default logging on the endpoint enough?

**URL:** <https://discuss.elastic.co/t/elastic-defend-is-default-logging-on-the-endpoint-enough/346296>\
**Category:** Elastic Security\
**Created:** [November 2, 2023, 1:44pm UTC](https://discuss.elastic.co/t/elastic-defend-is-default-logging-on-the-endpoint-enough/346296 "2023-11-02T13:44:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![h49nakxs](https://avatars.discourse-cdn.com/v4/letter/h/e68b1a/32.png) [@h49nakxs](https://discuss.elastic.co/u/h49nakxs)\
**Post date:** [November 2, 2023, 1:44pm UTC](https://discuss.elastic.co/t/elastic-defend-is-default-logging-on-the-endpoint-enough/346296/1 "2023-11-02T13:44:10Z")

</div>

Hello,

If I use "Elastic Defend" integration, will all the Elastic Security detection rules get enough information to be triggered or do I need to enhance the logging on the endpoints (for example with Sysmon on Windows and auditd on Linux) ?

My question specifically apply to endpoints using Windows or Linux.

Thanks !

---

<div class="post-metadata">

**Author:** ![Jonhnathan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonhnathan/32/98445_2.png) [@Jonhnathan](https://discuss.elastic.co/u/Jonhnathan)\
**Post date:** [November 3, 2023, 2:48pm UTC](https://discuss.elastic.co/t/elastic-defend-is-default-logging-on-the-endpoint-enough/346296/2 "2023-11-03T14:48:02Z")

</div>

Hey @h49nakxs,

Our Detection rules use different data sources, some exclusively use Defend, others Auditbeat or Sysmon, but this must be checked in a per rule basis to evaluate whether or not is beneficial for you (and also possible performance-wise) collect additional data.

Generally, to know which data sources are needed to trigger the rule, you can refer to:

- Data Source Tags
  - Such as "Data Source: Elastic Endgame", "Data Source: Elastic Defend", "Data Source: Sysmon Only", etc

- Related Integrations
  - E.g. windows, auditd\_manager, elastic defend, etc

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/2/b2d7440a4b0a769b06d6c326a6c10720b048d512.png)

We are also [working](https://github.com/elastic/detection-rules/pull/3256) in setup guides that could answer this question in a per rule basis. These can be accessed in the Setup section of the rule details:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/c/cc721f422dc88c314ad8e90d044c3d795848bba6.png)

---

<div class="post-metadata">

**Author:** ![h49nakxs](https://avatars.discourse-cdn.com/v4/letter/h/e68b1a/32.png) [@h49nakxs](https://discuss.elastic.co/u/h49nakxs)\
**Post date:** [November 14, 2023, 9:27am UTC](https://discuss.elastic.co/t/elastic-defend-is-default-logging-on-the-endpoint-enough/346296/3 "2023-11-14T09:27:54Z")

</div>

Hello,

Thanks a lot for your reply !

Would you say that the data source list is exhaustive for every rule ?

Because this is not the impression I have. For example, the rule :

> <https://github.com/elastic/detection-rules/blob/main/rules/linux/defense_evasion_clear_kernel_ring_buffer.toml>

seems pretty feasible with data coming from auditbeat, even if it's not listed in the data source.

Most importantly, what are your criteria to include / exclude data source ? For example, is there a list of fields that are exclusive to one or the other data source ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2023, 9:28am UTC](https://discuss.elastic.co/t/elastic-defend-is-default-logging-on-the-endpoint-enough/346296/4 "2023-12-12T09:28:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
