This article explains how to connect Elastic Endpoint Security to Workbench.

Step 1: Enable console access

This procedure creates a user account for Expel that keeps the Expel activity separate from other activity on the Elastic Endpoint Security console.


Expel secures all login information our SOC analysts need about your devices in a MFA password product. Access to this login information is protected using our internal MFA processes. To learn more about the IP addresses all Expel traffic comes from, go here.

  1. Navigate to Administration icon on the left, click Users tab, and click Create New User.

  2. For First name add Expel.

    • For Last name type Admin.

    • For Username type Expel.

    • For User Role select Admin.


      You can select LEVEL 3 access here, although Expel can't view security policies for the device to advise on best practices and configuration. Detection remains unaffected.

    • Create a Password for Expel.

  3. Click Create User.


After console access is established for Workbench, the remaining onboarding steps for this technology can also be performed by Expel. Reach out to your engagement manager if you want us to help.

Step 2: Configure the technology in Workbench

  1. In a new browser tab, log into

  2. On the console page, navigate to Settings and click Security Devices.

  3. At the upper right of the page, select Add Security Device.

  4. Search for and select Endgame.

    Screen Shot 2021-03-05 at 10.45.12 AM.png
  5. Select Cloud or On-prem.

    Screen Shot 2021-07-16 at 5.13.06 PM.png
    • Select the assembler from the list. (On-prem only)

    • For Name, type the host name of the Elastic Endpoint Security device.

    • For Location, type the geographic location of the appliance.

    • For Username, type Expel from Step 1.

    • For Password, type the password used in Step 1.

    • For Server address, type the management/console IP address of the device to be connected through https. For example:

    • For File unzip password, type the password to unzip the acquired file. If you don't type a password here, the default Endgame password is used.

    • For Acknowledge alerts, select yes to mark Endgame alerts as viewed after Workbench processes them.

    • For Dismiss alerts, select yes to mark Endgame alerts as dismissed after Workbench processes them.

  6. You can provide console access now or set it up later. Use the instructions below to set it up later.


This article was accurate at the time of writing, but changes happen. If you find the instructions are outdated, leave a description in the comment field below and let us know!