SIEM integration
Automate Elastic Security SIEM with plain language
Read Elastic Security detection alerts and rules from Kibana, and index a VernacSecure SuperBot™ event into Elasticsearch.
Elastic Security — Kibana Detections & Elasticsearch API
- Search detection alerts
- Read detection rules and their status
- Index an event document
Connection: header authentication against https://example.kb.us-east-1.aws.found.io. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Ask in plain English
Prompt: “Show the last 24 hours of high severity alerts in Elastic Security”
Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.
- Fetch detection alerts — Searches the detections alert index.
- Fetch detection rules — Lists detection rules.
- Fetch cases — Lists security cases.
This integration is read-only today. Write actions are added upstream as the vendor API exposes them.
Armor Point · Datadog Cloud SIEM · Devo Platform · Exabeam Security Operations · Fortinet FortiSIEM · Google Security Operations (Chronicle)