-
Notifications
You must be signed in to change notification settings - Fork 159
Description
Description
We need to update the Endpoint section of the Security Billing Dimensions webpage to address customer confusion about billing for endpoints that use Elastic Defend integration for collection purposes only.
Background
A customer (Support case #01830843) asked: "On the pricing of the endpoint protection integration. At the moment we're using elastic defend integration for collection only purposes. Is this use included in the base price or do we need the add-on even though we won't be using AV and prevention features."
After discussion with @caitlinbetz , we've decided to update the text to clarify this point.
Page to Update
Security Billing Dimensions webpage
Current Text
"You pay based on the number of protected endpoints you configure with the Elastic Defend integration. Note that logs, events, and alerts ingested into your Security project from endpoints running Elastic Defend are billed using the Ingest and Retention pricing described above."
New Text
"You pay based on the number of protected endpoints configured with the Elastic Defend integration. Logs, events, and alerts from these endpoints are billed using the Ingest and Retention pricing. If using Elastic Defend solely for data collection (without Endpoint Essentials or Complete add-ons), endpoints are not counted towards billing. In this case, you are only billed for data ingestion and retention, and you can configure event collection/telemetry in the policy without enabling protections."
Impact
This change will help customers better understand how they are billed when using Elastic Defend integration for collection purposes only.