How Elastic Infosec Optimizes Defend for Cost and Performance
ID: c338fe17-fffa-5580-bee7-37ff3ee0c991
STIX ID: report--c338fe17-fffa-5580-bee7-37ff3ee0c991
Feed Name: Elastic Security Labs
This article explains how Elastic’s InfoSec team optimized endpoint telemetry and reduced EDR costs by using ES|QL to identify noisy events, applying targeted Elastic Defend event filters, and tuning advanced policy settings (e.g., disabling MD5/SHA‑1 hashing and enabling event aggregation). By focusing on high-volume processes and paths across Mac, Windows, and Linux and fixing misconfigurations at the source, they reduced average ingest from ~48k to ~12k events per host per hour, improved cluster performance, saved substantial storage (estimated ~100TB/month), and enhanced analyst signal-to-noise without compromising detection coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
