Skip to content

[Security] Response Actions History privilege required for response console output - #7860

Open
natasha-moore-elastic wants to merge 2 commits into
mainfrom
issue-7275
Open

[Security] Response Actions History privilege required for response console output#7860
natasha-moore-elastic wants to merge 2 commits into
mainfrom
issue-7275

Conversation

@natasha-moore-elastic

Copy link
Copy Markdown
Contributor

Documents that Response Actions History (at least Read) is required to view command output and status in the response console, in addition to the relevant response-action privilege.

Resolves #7275

Made with Cursor

…onsole output

Co-authored-by: Cursor <cursoragent@cursor.com>
@natasha-moore-elastic
natasha-moore-elastic requested a review from a team as a code owner August 7, 2026 15:21
@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Elastic Docs AI PR menu

Check the box to run an AI review for this pull request.

  • Review docs changes (docs-review). Status: not started.

Powered by GitHub Agentic Workflows and docs-actions. For more information, reach out to the docs team.

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@paul-tavares paul-tavares left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left a suggestion (optional).

Thanks for getting this out


These are required to perform actions both in the response console and in other areas of the {{security-app}} (such as isolating a host from a detection alert).
* Users must have the appropriate user role or privileges for at least one response action to access the response console.
* In addition to the privilege for each response action, users need at least **Read** access to the **Response Actions History** [privilege](/solutions/security/configure-elastic-defend/elastic-defend-feature-privileges.md) to view command output and status in the response console. Without it, running a response action in the console can return an error even when the user has privileges for that action.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For the last sentence here, which is also used in the elastic-defend-feature-privileges.md, I would suggest this:

Suggested change
* In addition to the privilege for each response action, users need at least **Read** access to the **Response Actions History** [privilege](/solutions/security/configure-elastic-defend/elastic-defend-feature-privileges.md) to view command output and status in the response console. Without it, running a response action in the console can return an error even when the user has privileges for that action.
* In addition to the privilege for each response action, users need at least **Read** access to the **Response Actions History** [privilege](/solutions/security/configure-elastic-defend/elastic-defend-feature-privileges.md) to view command output and status in the response console. Without it, running a response action in the console will create the action request, but the user will be unable to monitor its completion and will not be able to view its results.

| **{{elastic-defend}} Policy Management** | Access the [Policies](/solutions/security/manage-elastic-defend/policies.md) page and {{elastic-defend}} integration policies to configure protections, event collection, and advanced policy features. |
| **{{elastic-defend}} Scripts Management** {applies_to}`stack: ga 9.4+` {applies_to}`serverless: ga` | Access the [script library](/solutions/security/endpoint-response-actions/script-library.md) to upload and manage scripts for {{elastic-defend}} `runscript` response actions. |
| **Response Actions History** | Access the [response actions history](/solutions/security/endpoint-response-actions/response-actions-history.md) for endpoints. |
| **Response Actions History** | Access the [response actions history](/solutions/security/endpoint-response-actions/response-actions-history.md) for endpoints.<br><br>Also required (at least **Read**) to view command output and status in the [response console](/solutions/security/endpoint-response-actions.md). Grant this privilege whenever you grant any response-action privilege (such as **Host Isolation**, **Process Operations**, and so on). If this privilege is **None**, running a response action in the console can return an error even when the user has privileges for that action. |

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
| **Response Actions History** | Access the [response actions history](/solutions/security/endpoint-response-actions/response-actions-history.md) for endpoints.<br><br>Also required (at least **Read**) to view command output and status in the [response console](/solutions/security/endpoint-response-actions.md). Grant this privilege whenever you grant any response-action privilege (such as **Host Isolation**, **Process Operations**, and so on). If this privilege is **None**, running a response action in the console can return an error even when the user has privileges for that action. |
| **Response Actions History** | Access the [response actions history](/solutions/security/endpoint-response-actions/response-actions-history.md) for endpoints.<br><br>Also requires (at least **Read**) to view command output and status in the [response console](/solutions/security/endpoint-response-actions.md). Grant this privilege whenever you grant any response-action privilege (such as **Host Isolation**, **Process Operations**, and so on). If this privilege is **None**, running a response action in the console can return an error even when the user has privileges for that action. |

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security] Document Response Actions History privilege dependency for running response actions

3 participants