Professional skills
Elastic Security for Endpoint
Investigate host-based alerts from Elastic Defend, enrich security data, and hunt threats on the endpoint.
THE BIG PICTURE
About this course
This course is built for analysts who use Elastic Security for Endpoint. It covers the components behind the Elastic Stack, Fleet, and Elastic Agent, then moves into Elastic Security and the use of visualizations, dashboards, and other parts of the Security App to triage alerts and investigate events in Timeline. Elastic notes this course as private delivery only. Contact MindClick for the delivery format, teaching language, instructor profile, duration, dates, and a written fee proposal. Elastic, Elasticsearch, and Kibana are trademarks of Elasticsearch B.V. This listing describes training and study support on those products. It is not an official Elastic course, an Elastic certification, or a claim of authorized Elastic training-partner status. Certification exams are purchased and administered by Elastic.
What you’ll learn
- Work confidently with elastic Stack overview in Elastic.
- Work confidently with security application in Elastic.
- Work confidently with elastic Defend in Elastic.
- Work confidently with elastic security enrichments in Elastic.
- Work confidently with threat hunting in Elastic.
A CLEAR PATH FORWARD
Recommended learning plan
Learn through guided exercises on an Elastic cluster, with discussion time and work you can take back to your own environment.
- Learning route
- 5 recommended days
- Practical work
- 5 guided activities
- Finish with
- A practical review
Take a look at each day. Open a section to see the topics and practical work.
Day 1Elastic Stack overview
What we’ll cover
- Elastic Stack overview
Put it into practice
Work through a guided exercise on this topic, explain your reasoning, and compare your approach with the group.
You’ll take away
A worked example with notes you can reuse at work.
Day 2Security application
What we’ll cover
- Security application
Put it into practice
Work through a guided exercise on this topic, explain your reasoning, and compare your approach with the group.
You’ll take away
A worked example with notes you can reuse at work.
Day 3Elastic Defend
What we’ll cover
- Elastic Defend
Put it into practice
Work through a guided exercise on this topic, explain your reasoning, and compare your approach with the group.
You’ll take away
A worked example with notes you can reuse at work.
Day 4Elastic security enrichments
What we’ll cover
- Elastic security enrichments
Put it into practice
Work through a guided exercise on this topic, explain your reasoning, and compare your approach with the group.
You’ll take away
A worked example with notes you can reuse at work.
Day 5Threat hunting
What we’ll cover
- Threat hunting
Put it into practice
Work through a guided exercise on this topic, explain your reasoning, and compare your approach with the group.
You’ll take away
A worked example with notes you can reuse at work.
Bring it all together
Review your worked examples with the trainer and agree the next steps for your own role.
Before you choose your learning route
Elastic, Elasticsearch, and Kibana are trademarks of Elasticsearch B.V. This listing describes training and study support on those products. It is not an official Elastic course, an Elastic certification, or a claim of authorized Elastic training-partner status. Certification exams are purchased and administered by Elastic.
Pricing
| Delivery format | Price per learner |
|---|---|
| Live online | $2,350 USD |
| Classroom | $4,500 USD |
Pricing for India is confirmed separately by an advisor and is not listed here. Singapore and Dubai are the priority classroom markets.
A listed price is not a quotation. Confirm the current fee, taxes, exam inclusion, study materials and any group rate in writing before enrolling.
Prerequisites
- Operating system knowledge for Windows and Linux: file systems and permissions, command line navigation, and the Windows registry. Networking fundamentals: common ports, protocols, and networking devices. Awareness of vulnerability and exploit methodology: reconnaissance, command and control, and persistence techniques.
Who is this course for?
- Endpoint-focused security analysts triaging host alerts.
- SOC teams deploying Elastic Defend with Fleet and Elastic Agent.
- Threat hunters enriching and correlating endpoint telemetry.
Confirmed batch starts
Dates confirmed by MindClick. These are start dates, not full course timetables. Session hours, duration, fees, instructors, language, seats and classroom venues are not yet specified.
Choose your country & month Enrollment & payment
Starts 2026-10-18
Live online · Manama, Bahrain · weekday start
Local date · Asia/Bahrain
Joining details to be suppliedStarts 2026-10-18
Live online · Cairo, Egypt · weekday start
Local date · Africa/Cairo
Joining details to be suppliedStarts 2026-10-18
Live online · Kuwait City, Kuwait · weekday start
Local date · Asia/Kuwait
Joining details to be suppliedStarts 2026-10-18
Live online · Muscat, Oman · weekday start
Local date · Asia/Muscat
Joining details to be suppliedStarts 2026-10-18
Live online · Doha, Qatar · weekday start
Local date · Asia/Qatar
Joining details to be suppliedStarts 2026-10-18
Live online · Riyadh, Saudi Arabia · weekday start
Local date · Asia/Riyadh
Joining details to be suppliedFrequently asked questions
Is this an official Elastic course?
No. This is MindClick training and study support on Elastic products. It is not an official Elastic course and MindClick does not claim Elastic training-partner status. Elastic publishes its own instructor-led courses and certification exams at elastic.co/training.
How long is the training?
Elastic lists this topic at 24 hours. MindClick confirms the actual duration, session hours, and schedule for your individual or team inquiry.
What does it cost?
Fees depend on delivery format, group size, language, and location. Request a written proposal and confirm taxes, materials, and any exam fees before enrolling.
Will this guarantee I pass the Elastic certification exam?
No. Training supports your preparation, but Elastic sets the exam objectives and pass criteria. Completing training does not guarantee certification, an exam pass, or employment.
What does this course cost?
Outside India this 5-day course is listed at USD 4,500 for classroom delivery and USD 2,350 for live online delivery, per learner. Pricing for India is confirmed separately by an advisor and is not listed here. Confirm taxes, exam fees, study materials and group rates in writing before enrolling; a listed price is not a quotation.
Where is classroom training delivered?
Singapore and Dubai are the priority classroom markets for this catalog. Classroom delivery is also available in the other listed countries, and live online delivery is available everywhere. Venues are confirmed per booking; a listed city is a training market, not an owned campus.
KEEP EXPLORING
More ways to move forward.
Related training from the course catalog.
Elasticsearch Engineer Training
Build, search, scale, and operate Elasticsearch clusters, then prepare for the Elastic Certified Engineer exam.
Data Analysis with Kibana
Analyze Elasticsearch data in Kibana, from aggregation charts to geo maps, machine learning results, and alerting.
Elastic Observability Engineer Training
Collect logs, metrics, uptime, and APM data into Elasticsearch, then analyze and act on it in Kibana.
Elastic Security for SIEM
Use Elastic Security for SIEM to triage alerts, investigate events in Timeline, and run a threat hunting capstone.