Skip to content

Conversation

ferullo
Copy link
Contributor

@ferullo ferullo commented Jul 16, 2025

This edits the Defend advanced option wording with the following primary goals:

  1. Standardizing some word choices and stylistic choices across all the options.
  2. Shortens the italics text. This is the text that also appears in Kibana tooltips. Once this PR is approved I'll open a Kibana PR to align those tool tips to the text agreed to here.

Originally we'd agreed to completely remove the italics portion on this page and make sure the Kibana tool tips were "short" with an expectation users turn to this more detailed documentation when needed. I tried, but was only as successful as what I'm proposing to merge in this PR (usually shorten the italics tool tip and always still show it on elastic.co).

Thoughts @natasha-moore-elastic @gabriellandau @roxana-gheorghe @nfritts @joe-desimone

Docs Preview as of July 28

@ferullo ferullo requested a review from a team as a code owner July 16, 2025 16:15
Copy link

github-actions bot commented Jul 16, 2025

🔍 Preview links for changed docs

Copy link
Contributor

@natasha-moore-elastic natasha-moore-elastic left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for making the edits @ferullo! The descriptions are a lot clearer, and I'm definitely in favor of making the structure more parallel.

: Added in 7.11.0.

*A supplied value will configure logging to syslog. Allowed values are `error`, `warning`, `info`, `debug`, and `trace`.*
* Write logs to syslog. Allowed values are `error`, `warning`, `info`, `debug`, and `trace`. Default: none.*
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* Write logs to syslog. Allowed values are `error`, `warning`, `info`, `debug`, and `trace`. Default: none.*
*Write logs to syslog. Allowed values are `error`, `warning`, `info`, `debug`, and `trace`. Default: none.*

: Added in 8.19.0.

*If set to `true`, file events include file origin details: file.origin_url, file.origin_referrer_url, and file.Ext.windows.zone_identifier. These fields show the details of file's Mark of the Web. Default: `true`*
*When enabled (`true`), file events include `file.origin_url`, `file.origin_referrer_url`, and `file.Ext.windows.zone_identifier. These fields show the details of file's Mark of the Web. Default: `true`*
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
*When enabled (`true`), file events include `file.origin_url`, `file.origin_referrer_url`, and `file.Ext.windows.zone_identifier. These fields show the details of file's Mark of the Web. Default: `true`*
*Include `file.origin_url`, `file.origin_referrer_url`, and `file.Ext.windows.zone_identifier` in file events. These fields show the details of file's Mark of the Web. Default: `true`*

: Added in 8.19.0.

*Controls whether Microsoft-Windows-Security-Auditing ETW provider is enabled for security events collection. Set to `false` to disable the provider. Default: `true`.*
*Controls whether Microsoft-Windows-Security-Auditing ETW provider is enabled for security events collection. Set to `false` to disable the provider. Default: `true`.*
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
*Controls whether Microsoft-Windows-Security-Auditing ETW provider is enabled for security events collection. Set to `false` to disable the provider. Default: `true`.*
*Enable the Microsoft-Windows-Security-Auditing ETW provider for security events collection. Default: `true`.*

: Added in 8.16.0.

*Controls whether malware protection is applied to dev drives. Default: `false`.*
*Control whether malware protection is applied to dev drives. Default: `false`.*
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
*Control whether malware protection is applied to dev drives. Default: `false`.*
*Apply malware protection to dev drives. Default: `false`.*

: Added in 8.15.0.

*Controls whether the kernel reports loopback network events. Default: `true`.*
*Control whether loopback network events are reported. Default: `true`.*
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
*Control whether loopback network events are reported. Default: `true`.*
*Report loopback network events. Default: `true`.*

: Added in 8.9.0.

*Controls whether malware protection is applied to network drives. Default: `true`.*
*Control whether malware protection is applied to network drives. Default: `true`.*
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
*Control whether malware protection is applied to network drives. Default: `true`.*
*Apply malware protection to network drives. Default: `true`.*

Co-authored-by: natasha-moore-elastic <[email protected]>
Copy link
Contributor Author

@ferullo ferullo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for your review! I accepted all your suggestions and added suggestions I think will address your outstanding comments.

Co-authored-by: Daniel Ferullo <[email protected]>
@natasha-moore-elastic
Copy link
Contributor

Thanks for your review! I accepted all your suggestions and added suggestions I think will address your outstanding comments.

LGTM!

@ferullo
Copy link
Contributor Author

ferullo commented Jul 30, 2025

@natasha-moore-elastic am I correct to assume it's ok for me to merge this?

@natasha-moore-elastic
Copy link
Contributor

@natasha-moore-elastic am I correct to assume it's ok for me to merge this?

@ferullo, all good on my end! I'll go ahead and merge.

@natasha-moore-elastic natasha-moore-elastic merged commit 48ee2e7 into main Jul 31, 2025
8 checks passed
@natasha-moore-elastic natasha-moore-elastic deleted the ferullo-defend-advanced-options branch July 31, 2025 08:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants