Elastic (Elastic Stack / Elasticsearch) is an open, distributed search and analytics platform used for log management, SIEM, observability, and endpoint security through the Elastic Security product.
Security teams looking to integrate Elastic or build an Elastic SIEM integration can use Synqly to route normalized security events and findings into Elastic for search, correlation, and alerting. Integrate Elastic into your security product stack without managing custom index schemas or API versions.
Configuration for Elastic SIEM.
[Configuration guide](https://docs.synqly.com/guides/provider-configuration/elastic-setup)
Integration Use Cases
Post Events
Writes a batch of `Event` objects to the SIEM configured with the token used for authentication.
Query Alerts
Queries alerts from the SIEM configured with the token used for authentication.
Query Events
Queries events from the SIEM configured with the token used for authentication.
Query Log Providers
Queries available log providers in the source SIEM