Elastic Defend

Elastic Defend (formerly Endgame) is a tool for malware prevention, detection, and response.

Asset Types Fetched

  • Devices

Before You Begin

Authentication Method

  • User Name/Password

APIs

Axonius uses the Elastic Security APIs.

Permissions

Consult with your vendor for the exact permissions to fetch the objects.

Supported From Version

Supported from Axonius version 6.0

Connecting the Adapter in Axonius

To connect the adapter in Axonius, provide the following parameters:

Required Parameters

  1. Host Name or IP Address - The hostname or IP address of the Kibana server.

  2. User Name and Password - The credentials for a user account that has permissions to fetch assets.

  3. Port - The port number of your Kibana instance.


Optional Parameters

  1. Verify SSL - Select whether to verify the SSL certificate of the server against the CA database inside of Axonius. For more details, see SSL Trust & CA Settings.

  2. HTTPS Proxy - Connect the adapter to a proxy instead of directly connecting it to the domain.

  3. HTTPS Proxy User Name - The user name to use when connecting to the value supplied in Host Name or IP Address via the value supplied in HTTPS Proxy.

  4. HTTPS Proxy Password - The password to use when connecting to the server using the HTTPS Proxy.

To learn more about common adapter connection parameters and buttons, see Adding a New Adapter Connection.

Advanced Settings

📘

Note

Advanced settings can either apply to all connections for this adapter, or to a specific connection. Refer to ​Advanced Configuration for Adapters.

Endpoint Config

  • Fetch Devices of sub type Host from Hosts(default: true) - Enable this option to fetch devices whose sub-type is Host from the Hosts endpoint.

Spaces - applies context on the following endpoints: Hosts by Space

  • Spaces - Specify which SpaceID to use for the connection.
📘

Note

To learn more about Adapter Configuration tab advanced settings, see Adapter Advanced Settings.

Version Matrix

This adapter was only tested with the versions marked as supported, but may work with other versions. Contact Axonius Support if you have a version that is not listed, which is not functioning as expected.

VersionSupportedNotes
Elastic Security APIs V1Yes

Supported From Version

Supported from Axonius version 6.0