Skip to content

[Security] Elastic Defend support for remote output and CCS - #7565

Open
natasha-moore-elastic wants to merge 3 commits into
mainfrom
issue-7220
Open

[Security] Elastic Defend support for remote output and CCS#7565
natasha-moore-elastic wants to merge 3 commits into
mainfrom
issue-7220

Conversation

@natasha-moore-elastic

Copy link
Copy Markdown
Contributor

Documents support for using Elastic Defend with a remote Elasticsearch output, available on Elastic Stack deployments starting in 9.5. When agents use a remote Elasticsearch output, their endpoint data is written to the remote cluster, and the management cluster reads it back using cross-cluster search.

Changes:

  • Adds a new how-to page for setting up Elastic Defend with a remote Elasticsearch output and cross-cluster search.
  • Updates the Fleet remote Elasticsearch output page to version-gate the previous Elastic Defend limitation and add Elastic Defend as a cross-cluster search use case.

Resolves #7220

Made with Cursor

Co-authored-by: Cursor <cursoragent@cursor.com>
@natasha-moore-elastic
natasha-moore-elastic requested review from a team as code owners July 24, 2026 11:44
@github-actions

Copy link
Copy Markdown
Contributor

Elastic Docs AI PR menu

Check the box to run an AI review for this pull request.

  • Review docs changes (docs-review). Status: not started.

Powered by GitHub Agentic Workflows and docs-actions. For more information, reach out to the docs team.

@github-actions

github-actions Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actions Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Elastic Docs Style Checker (Vale)

Summary: 1 suggestion found

💡 Suggestions (1): Optional style improvements. Apply when helpful.
File Line Rule Message
reference/fleet/remote-elasticsearch-output.md 217 Elastic.Wordiness Consider using 'sometimes' instead of 'In some cases'.

The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@florent-leborgne florent-leborgne left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM with 1 suggestion

Comment thread reference/fleet/remote-elasticsearch-output.md Outdated

@leemthompo leemthompo left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me, with one nit: the standard CCS terminology is "local (and remote) cluster" but this PR uses "management cluster" throughout (and "main cluster" once).

Don't know if it makes sense to align :)

Co-authored-by: Florent LB <florent.leborgne@elastic.co>
@natasha-moore-elastic

Copy link
Copy Markdown
Contributor Author

Looks good to me, with one nit: the standard CCS terminology is "local (and remote) cluster" but this PR uses "management cluster" throughout (and "main cluster" once).

Don't know if it makes sense to align :)

Hey @leemthompo, thanks for flagging this, I'll update the PR to use that term instead. 👍
We'll probably want to update https://www.elastic.co/docs/reference/fleet/remote-elasticsearch-output as well – this is where my PR sourced the term "management cluster" from. (cc @vishaangelova I think you might own that page?)

@szwarckonrad szwarckonrad left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question, otherwise LGTM

Comment thread reference/fleet/remote-elasticsearch-output.md
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Internal]: Document Elastic Defend support for CCS and remote output

4 participants