<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint &amp;amp; Elastic DB in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-amp-Elastic-DB/m-p/151709#M5799</link>
    <description>&lt;P&gt;Hello everyone!&lt;BR /&gt;&lt;BR /&gt;We've been aware of the possibility to push raw forensic data to an ELK stack for a little while now (through a sales representative meeting), but I've been unable to find any documentation on the topic.&lt;/P&gt;&lt;P&gt;Has anyone actually implemented this and do you find it at all useful?&lt;BR /&gt;We manage a number of environments and a good number of them use On-Prem Endpoint servers meaning we lack access to Threat Hunting. Being able to pipe these datasets into a database would potentially be a very good stopgap measure between something more official on the EDR front for On-Prem managed devices.&lt;/P&gt;&lt;P&gt;I ask because in the E86.50 agent release notes this functionality is explicitly mentioned.&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk179044" target="_blank" rel="noopener"&gt;Enterprise Endpoint Security E86.50 Windows Clients (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%" cellspacing="2" cellpadding="4"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;AHTP-24628&lt;/TD&gt;&lt;TD&gt;Forensics data can now be sent from the Endpoint's client computer directly to a local Elastic DB.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Fri, 24 Jun 2022 10:16:17 GMT</pubDate>
    <dc:creator>Swiftyyyy</dc:creator>
    <dc:date>2022-06-24T10:16:17Z</dc:date>
    <item>
      <title>Endpoint &amp; Elastic DB</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-amp-Elastic-DB/m-p/151709#M5799</link>
      <description>&lt;P&gt;Hello everyone!&lt;BR /&gt;&lt;BR /&gt;We've been aware of the possibility to push raw forensic data to an ELK stack for a little while now (through a sales representative meeting), but I've been unable to find any documentation on the topic.&lt;/P&gt;&lt;P&gt;Has anyone actually implemented this and do you find it at all useful?&lt;BR /&gt;We manage a number of environments and a good number of them use On-Prem Endpoint servers meaning we lack access to Threat Hunting. Being able to pipe these datasets into a database would potentially be a very good stopgap measure between something more official on the EDR front for On-Prem managed devices.&lt;/P&gt;&lt;P&gt;I ask because in the E86.50 agent release notes this functionality is explicitly mentioned.&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk179044" target="_blank" rel="noopener"&gt;Enterprise Endpoint Security E86.50 Windows Clients (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%" cellspacing="2" cellpadding="4"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;AHTP-24628&lt;/TD&gt;&lt;TD&gt;Forensics data can now be sent from the Endpoint's client computer directly to a local Elastic DB.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Fri, 24 Jun 2022 10:16:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-amp-Elastic-DB/m-p/151709#M5799</guid>
      <dc:creator>Swiftyyyy</dc:creator>
      <dc:date>2022-06-24T10:16:17Z</dc:date>
    </item>
  </channel>
</rss>

