SIEM integration

Automate Elastic Security SIEM with plain language

Read Elastic Security detection alerts and rules from Kibana, and index a VernacSecure SuperBot™ event into Elasticsearch.

What you can do

Elastic Security — Kibana Detections & Elasticsearch API

  • Search detection alerts
  • Read detection rules and their status
  • Index an event document

Connection: header authentication against https://example.kb.us-east-1.aws.found.io. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.

Example

Ask in plain English

Prompt: “Show the last 24 hours of high severity alerts in Elastic Security”

Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.

Get started free

Read actions
  • Fetch detection alerts — Searches the detections alert index.
  • Fetch detection rules — Lists detection rules.
  • Fetch cases — Lists security cases.
Write actions

This integration is read-only today. Write actions are added upstream as the vendor API exposes them.