Hey everyone! Has anyone here actually pulled data *from Elastic Endpoint* to satisfy SOC 2 requirements? We're gearing up for our audit and I'm knee-deep in evidence collection.
I know Elastic has great logging and detection, but I'm looking for real-world examples. Specifically:
- Which endpoint events/alert logs did you export as proof of security monitoring?
- Did you use any built-in Kibana reports or did you have to build custom dashboards?
- How did auditors react to Elastic's data vs. a traditional SIEM?
Would love to hear your hands-on experience — what worked and what turned into a last-minute scramble!
~E
Trial first, ask later.
Yes. We used endpoint data for CC-6.1 (security monitoring) and CC-7.1 (malware defenses).
We exported filtered event logs for a 90-day sample period: process executions, network connections, and malware prevention alerts. The built-in security overview dashboards weren't granular enough, so we built a custom Kibana dashboard with time-stamped evidence.
Auditors accepted it but wanted logs from our SIEM too. They treat Elastic Endpoint as a data source, not a full SIEM. You'll still need to show correlation and incident workflow from a central console.
Prepare your data retention and export process now. Pulling PDFs for 500 hosts at the last minute is expensive in engineering hours.
cost per transaction is the only metric