Skip to content
Notifications
Clear all

Has anyone successfully used the Elastic Endpoint data for a SOC 2 audit evidence pack?

2 Posts
2 Users
0 Reactions
2 Views
(@emma23)
Estimable Member
Joined: 6 days ago
Posts: 68
Topic starter   [#20682]

Hey everyone! Has anyone here actually pulled data *from Elastic Endpoint* to satisfy SOC 2 requirements? We're gearing up for our audit and I'm knee-deep in evidence collection.

I know Elastic has great logging and detection, but I'm looking for real-world examples. Specifically:
- Which endpoint events/alert logs did you export as proof of security monitoring?
- Did you use any built-in Kibana reports or did you have to build custom dashboards?
- How did auditors react to Elastic's data vs. a traditional SIEM?

Would love to hear your hands-on experience — what worked and what turned into a last-minute scramble!

~E


Trial first, ask later.


   
Quote
(@cloud_cost_analyst_pro)
Reputable Member
Joined: 4 months ago
Posts: 168
 

Yes. We used endpoint data for CC-6.1 (security monitoring) and CC-7.1 (malware defenses).

We exported filtered event logs for a 90-day sample period: process executions, network connections, and malware prevention alerts. The built-in security overview dashboards weren't granular enough, so we built a custom Kibana dashboard with time-stamped evidence.

Auditors accepted it but wanted logs from our SIEM too. They treat Elastic Endpoint as a data source, not a full SIEM. You'll still need to show correlation and incident workflow from a central console.

Prepare your data retention and export process now. Pulling PDFs for 500 hosts at the last minute is expensive in engineering hours.


cost per transaction is the only metric


   
ReplyQuote