Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[REQUEST]: 8.18: Document new Connector for Microsoft Defender for Endpoint (in Tech. Preview) #249

Open
paul-tavares opened this issue Jan 2, 2025 · 3 comments
Assignees

Comments

@paul-tavares
Copy link

paul-tavares commented Jan 2, 2025

Description

Description

Add documentation for new Microsoft Defender for Endpoint connector. This new connector will (at this time) be in Tech. Preview, but that could change by the time we enable it (currently hidden behind a feature flag.

When

Looking to make this connector available with v8.18 / v9.0.
It may be enabled for serverless prior to these release dates.

Resources

Implementation PR: elastic/kibana#203183

Note that this connector is an EDR only connector. The EDR sub-privileges implementation is being done here and that PR may have impacts to how you word the documentation for this new connector (as well as the existing SentinelOne + Crowdstrike connectors)

Relates to elastic/kibana#207136

Which documentation set does this change impact?

Elastic On-Prem and Cloud (all)

Feature differences

From the connector's standpoint, all is the same.

See below for screen capture of required data for creating the connector:

Image

The data required closely mirrors the same data required to set the Fleet Microsoft Defender for Endpoint integration - screen capture of the input fields in fleet:

Image

What release is this request related to?

8.18, 9.0

Collaboration model

The documentation team

Point of contact.

Main contact:

Stakeholders:

??

@paul-tavares
Copy link
Author

@caitlinbetz ,

Can you confirm: are we planning on GA'ing the Microsoft Defender ++ Crowdstrike ++ SentinelOne functionality in 8.18/9.0?

Also - my guess is that we'll need to do this first for Serverless , so at some point here soon we'll need to discuss the timing and the target serverless release so that we can all get sync'd up.

@lcawl lcawl changed the title [REQUEST]: Document new Connector for Microsoft Defender for Endpoint (in Tech. Preview) [REQUEST]: 8.18: Document new Connector for Microsoft Defender for Endpoint (in Tech. Preview) Jan 2, 2025
@paul-tavares
Copy link
Author

cc/ @dasansol92

Including David on here as he will be coordinating the release of this feature to serverless

@caitlinbetz
Copy link

@paul-tavares Yes, we want to these connectors in GA in 8.18

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants