-
Notifications
You must be signed in to change notification settings - Fork 206
Closed
Labels
Feature: PolicyElastic Defend integration policy and configurationElastic Defend integration policy and configurationTeam: DocsTeam: EndpointEndpoint related issuesEndpoint related issuesv8.4.0
Description
Description
New "self-healing" endpoint policy advanced setting enables automatic rollback of 5 minutes previous to any "Prevent"-related endpoint alert. Windows only. By default, this setting is NOT enabled.
Need to sufficiently warn users that this could cause data loss and should be used very carefully.
NOTE: The advanced feature may be renamed soon; currently it's windows.advanced.alerts.rollback.self_healing.enabled.
Related
Notes
- Windows only
- Confirm licensing requirements
Metadata
Metadata
Assignees
Labels
Feature: PolicyElastic Defend integration policy and configurationElastic Defend integration policy and configurationTeam: DocsTeam: EndpointEndpoint related issuesEndpoint related issuesv8.4.0
