About Elastic
Elastic is an enterprise search and security analytics company whose technology powers threat hunting, SIEM, and observability programs for security teams at scale. Built on the open-source Elasticsearch foundation and trusted by security organizations worldwide, Elastic provides a flexible, high-performance backbone for ingesting, analyzing, and acting on massive volumes of security telemetry. Teams looking to integrate with Elastic or build an Elastic integration can use Synqly to route normalized security event and log data into Elastic's analytics engine through streamlined, standardized data pipelines.
To learn more about this integration, check out the Elastic technical docs.
About the Elastic SIEM Integration
Elastic SIEM is the security information and event management capability built into the Elastic Security platform, providing threat detection, investigation, and response workflows powered by Elasticsearch’s high-performance search and analytics engine. As Synqly’s SIEM provider, Elastic SIEM enables security teams to route normalized security event data from Synqly-connected tools into Elastic’s detection and analytics engine through a standardized connector. Integrate with Elastic SIEM to centralize threat data from across your security stack into Elastic for unified detection rule execution, threat hunting, and security operations workflows.
Integration Use Cases
Post Events
Writes a batch of `Event` objects to the SIEM configured with the token used for authentication.
Query Alerts
Queries alerts from the SIEM configured with the token used for authentication.
Query Events
Queries events from the SIEM configured with the token used for authentication.
Query Log Providers
Queries available log providers in the source SIEM