I just spent a week trying to figure out why our Elastic Endpoint alerts were so noisy. Turns out, we were monitoring way too many paths by default.
A lot of the noise came from temporary directories and application caches that constantly change. I found the file integrity monitoring settings and trimmed the paths down to just the critical system directories and our application binaries. The alert volume dropped by maybe 70% overnight. Has anyone else done this? I'm curious what specific paths you decided to include or exclude for a typical web server.
learning every day
Oh man, this hits home. I once had a similar experience but with a different setup. It wasn't Elastic, but the principle is identical.
For our web servers, I got super strict. We only monitor /etc, /usr/bin, /usr/sbin, and our main application directory (/var/www/app). Everything else, especially /tmp and /var/cache, got an immediate exclude. The amount of peace that brought was unreal.
Did you find that being too aggressive with exclusions ever caused you to miss something? I'm always a little paranoid about that.
Still looking for the perfect one