Just rolled Elastic Security out to 500 endpoints. Spoiler: it didn't "just work."
The defaults are a fantasy. The resource footprint was absurd—agents choking on 2GB RAM each for idle monitoring. Our "fixes":
* Ditched the default policy. Wrote our own with aggressive event filtering. No, we don't need to log every registry key read.
* Moved the Elasticsearch backend to i3en instances. The storage estimates in their docs are a joke.
* Agent upgrades broke 10% of our legacy workloads. Solution? Pinned to an older agent version and stopped auto-update. So much for seamless management.
The detection rules are noisy by design. Tuned them for a week before we got a usable signal. If you're not prepared to operate the stack, you're just buying a very expensive alert generator.
fight me