Elastic Security connector for Okou
Connect to Elastic Security through Kibana to investigate detection alerts, cases, endpoints, exceptions, timelines, osquery results, and entity analytics.
Engineering · Kibana API key
Use Elastic Security in Okou
Use Elastic Security through the Kibana API for read-only detection investigation, alert and case lookup, endpoint metadata, exceptions, timelines, osquery results, Attack Discovery, and entity analytics.
Once connected, supported Elastic Security actions can become steps in a reusable workflow alongside the other services your team uses. Run the workflow once, on a schedule, or when an event starts it.
What you can do with Elastic Security
- Read Kibana alerting health, rule metadata, query inspectors, and backfill status.
- Read detection rules, alerts, attack findings, prebuilt-rule status, and detection metadata.
- Read cases, case alerts, comments, activity, templates, and case configuration.
- Read endpoint actions, endpoint metadata, response notes, scripts, and collected files.
- Read detection and endpoint exception lists, items, and summaries.
- Read security lists, list items, list privileges, and exported list items.
- Read security timelines, notes, drafts, and exported timeline data.
- Read osquery history, live-query results, packs, saved queries, and scheduled results.
How the Elastic Security connector works
A connected service becomes one permissioned step in the work you hand off.
- 1
Connect Elastic Security
Choose Kibana API key.
- 2
Choose the work
Use only the supported actions your workflow needs.
- 3
Run it your way
Start it once, schedule it, or attach an event trigger.
Connect Elastic Security securely
Use the connection method that fits your account and grant only the access the workflow needs.
- Kibana API key
Connector access is controlled per service and per action, so a workflow does not need broader access than the work you ask it to do.
Elastic Security connector questions
- What can Okou do with Elastic Security?
- Connect to Elastic Security through Kibana to investigate detection alerts, cases, endpoints, exceptions, timelines, osquery results, and entity analytics. Documented actions include: Read Kibana alerting health, rule metadata, query inspectors, and backfill status. Read detection rules, alerts, attack findings, prebuilt-rule status, and detection metadata.
- How do I connect Elastic Security to Okou?
- Connect Elastic Security using Kibana API key. The connection controls which supported actions a workflow can use.
- Can Elastic Security run in an automated workflow?
- Yes. After it is connected, supported Elastic Security actions can run in reusable Okou workflows on demand, on a schedule, or from an event trigger.
More engineering connectors
Explore other connectors in the same product category.
Encore
Encore Cloud API.
Edworking
Connect Edworking to read and manage tasks, projects, files, messages, users, notifications, folders, and time tracking through its GraphQL API.
Entelligence
Connect Entelligence to review engineering context, investigate incidents, inspect agent insights, and analyze delivery workflows through MCP.

