M ManySignal
MS
EL
Integration

Elastic Integration

Elastic Security alerts and ECS-normalised logs into the AI triage pipeline.

What this integration does

Elastic meets agentic SOC

Elastic Security (formerly SIEM + Endpoint) is a popular open-source-rooted security stack. ManySignal connects to Elasticsearch and Kibana via the Elasticsearch REST API and Elastic Security API, pulling detection rule alerts, ECS-normalised events, and case data, then enriching and triaging them with AI before routing verdicts back to Elastic cases.

Elastic Security detection rule alert ingestion

Raw ECS-normalised event search via Elasticsearch Query DSL

Elastic Security case creation and status sync

Data collected

  • Elastic Security detection alerts
  • ECS-normalised log events from all data sources
  • Elastic Security cases and comments
  • Fleet agent and endpoint metadata

Actions supported

  • Create Elastic Security case
  • Add comment to Elastic case with AI verdict
  • Isolate Elastic Endpoint agent
  • Close Elastic Security alert
  • Run Elasticsearch query for contextual investigation

Getting started

Set up in minutes

  1. 1

    Create an Elasticsearch API key

  2. 2

    Configure the connector

  3. 3

    Set alert polling scope

  4. 4

    Enable endpoint response (optional)

Elastic Integration: frequently asked questions

Does this work with the open-source Elasticsearch stack?

The alert ingestion integration requires Elastic Security, which is available under the Elastic licence (not Apache 2.0). Raw event search works with any Elasticsearch cluster using the standard API.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.