← Back to connectors

Elastic Security connector for Okou

Connect to Elastic Security through Kibana to investigate detection alerts, cases, endpoints, exceptions, timelines, osquery results, and entity analytics.

Engineering · Kibana API key

Use Elastic Security in Okou

Use Elastic Security through the Kibana API for read-only detection investigation, alert and case lookup, endpoint metadata, exceptions, timelines, osquery results, Attack Discovery, and entity analytics.

Once connected, supported Elastic Security actions can become steps in a reusable workflow alongside the other services your team uses. Run the workflow once, on a schedule, or when an event starts it.

What you can do with Elastic Security

  • Read Kibana alerting health, rule metadata, query inspectors, and backfill status.
  • Read detection rules, alerts, attack findings, prebuilt-rule status, and detection metadata.
  • Read cases, case alerts, comments, activity, templates, and case configuration.
  • Read endpoint actions, endpoint metadata, response notes, scripts, and collected files.
  • Read detection and endpoint exception lists, items, and summaries.
  • Read security lists, list items, list privileges, and exported list items.
  • Read security timelines, notes, drafts, and exported timeline data.
  • Read osquery history, live-query results, packs, saved queries, and scheduled results.

How the Elastic Security connector works

A connected service becomes one permissioned step in the work you hand off.

  1. 1

    Connect Elastic Security

    Choose Kibana API key.

  2. 2

    Choose the work

    Use only the supported actions your workflow needs.

  3. 3

    Run it your way

    Start it once, schedule it, or attach an event trigger.

Connect Elastic Security securely

Use the connection method that fits your account and grant only the access the workflow needs.

  • Kibana API key

Connector access is controlled per service and per action, so a workflow does not need broader access than the work you ask it to do.

Elastic Security connector questions

What can Okou do with Elastic Security?
Connect to Elastic Security through Kibana to investigate detection alerts, cases, endpoints, exceptions, timelines, osquery results, and entity analytics. Documented actions include: Read Kibana alerting health, rule metadata, query inspectors, and backfill status. Read detection rules, alerts, attack findings, prebuilt-rule status, and detection metadata.
How do I connect Elastic Security to Okou?
Connect Elastic Security using Kibana API key. The connection controls which supported actions a workflow can use.
Can Elastic Security run in an automated workflow?
Yes. After it is connected, supported Elastic Security actions can run in reusable Okou workflows on demand, on a schedule, or from an event trigger.

More engineering connectors

Explore other connectors in the same product category.