Elastic defend - network events - icmp traffic

Hi,

I have installed only elastic defend. i similated few requests,

under network events i could see logs ( connection attempted, connection accepted, disconnect received)

but for icmp simulation like ping execution, i couldn't see log entry under network events (but i could see process entry for this from machine which initiates ping request).

does elastic defend tap all the network activity(including icmp)? if yes, is it enabled by default? or need to enable it manually?