# Elastic Defend Service Enhancement

**URL:** https://discuss.elastic.co/t/elastic-defend-service-enhancement/389619
**Category:** Endpoint Security
**Created:** [August 14, 2026, 12:12pm UTC](https://discuss.elastic.co/t/elastic-defend-service-enhancement/389619 "2026-08-14T12:12:57Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Shailesk](https://avatars.discourse-cdn.com/v4/letter/s/58956e/32.png) [@Shailesk](https://discuss.elastic.co/u/Shailesk)
#### Post date: [August 14, 2026, 12:12pm UTC](https://discuss.elastic.co/t/elastic-defend-service-enhancement/389619/1 "2026-08-14T12:12:57Z")

</div>

\*"Elastic Defend scan response action should include scan statistics in the response payload: files scanned count, threats detected count, and scan duration breakdown."  
\*  
Reference the field path where it should appear:

EndpointActions.data.output.content.files\_scanned  
EndpointActions.data.output.content.threats\_found

Reason: We need to collect evidence as how many files were scanned by Elastic defend.  
how many threats detected per host.  
How much time it took to complete the OnDemand scan.

---

<div class="post-metadata">

### Author: ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)
#### Post date: [August 28, 2026, 8:52pm UTC](https://discuss.elastic.co/t/elastic-defend-service-enhancement/389619/2 "2026-08-28T20:52:54Z")

</div>

I think an enhancement request issue here have a better visibility (as is queryable) [Issues · elastic/endpoint · GitHub](https://github.com/elastic/endpoint/issues)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 25, 2026, 8:53pm UTC](https://discuss.elastic.co/t/elastic-defend-service-enhancement/389619/3 "2026-09-25T20:53:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
