Ingest data to Elastic Security

Bring your security data into Elastic Security so its analytics, including detection, investigation, and threat hunting, can work across all of it. Elastic Security can ingest data from anywhere, using native Elastic ingest tools as well as third-party tools such as Cribl and Kafka. The most common way to get data in is with integrations, which connect to hundreds of common security tools. Integrations handle both ingesting your events and normalizing them to the Elastic Common Schema (ECS).

Use this page to find the right way to bring in each data source, add it, and confirm that the data reaches Elastic Security.

The method you use depends on what you want to protect or monitor, and on where your data comes from. Find your goal in the following table:

Your goal Start here
Bring in logs, findings, threat intelligence, or alerts from the tools you already use, such as your cloud services, identity provider, or endpoint security tool Ingest data with an integration
Protect your hosts with Elastic's own endpoint protection Configure endpoint protection with Elastic Defend
Ingest data from a source that has no integration Build a custom integration with Automatic Import or Elastic integration skills
Move rules and dashboards from Splunk, Microsoft Sentinel, or QRadar Automatic Migration, which also identifies the data sources your migrated rules need
Send data with Beats, Logstash, or a third-party collector Send data with Beats, Logstash, or third-party collectors

Elastic has hundreds of integrations that collect data from security tools, cloud services, identity providers, and operating systems. Integrations collect data in different ways, including APIs, syslog, cloud storage such as Amazon S3, and log files. Many of them include dashboards for exploring your data and have related prebuilt detection rules that you can install and turn on.

Each integration has its own documentation with setup steps and configuration options. To find the one for your source, refer to Elastic integrations.

Before you add an integration, decide which data you need and how the integration collects it.

You don't need every type of data to get started. Start with the data for the tasks that matter most to you, and add more later:

Data type What you can do with it How to get it
Logs and events Detect threats and find out what happened across your environment. Detection rules create alerts from suspicious events, and Attack Discovery groups related alerts into attack narratives. To investigate, AI Assistant helps you interpret and prioritize alerts, and you can explore events yourself in Timeline and Discover. Add the integration for each tool or service that produces the logs. Then install the prebuilt detection rules that match your data, and turn them on. To also find unusual activity with machine learning, add behavioral detection integrations.
Posture and vulnerability findings Find the cloud resources that fail security guidelines and the hosts with known vulnerabilities, so you can decide what to fix first. When you investigate an alert, the same findings show whether the host or user involved has misconfigurations or vulnerabilities. Review them on the Findings page. To check your own cloud accounts and Kubernetes clusters against security guidelines, add Elastic's cloud security posture management (CSPM) or Kubernetes security posture management (KSPM) integration. To find known vulnerabilities in your cloud workloads, add cloud native vulnerability management (CNVM). To bring in findings from other tools, add one of the integrations that power Findings and Alerts.
Threat intelligence Find out when activity in your environment involves known malicious IP addresses, domains, or files. Indicator match rules create an alert when your events match an indicator, and you can review each indicator on the Indicators page. Add a threat intel integration.
Endpoint data and alerts from Elastic Defend Prevent threats on your hosts and find out how an attack unfolded. Elastic Defend blocks malware, ransomware, and other malicious behavior, and it collects endpoint data for investigation. When it detects or blocks a threat, its endpoint protection rules create an alert for you to triage. To see the processes that led to the alert, open it in the visual event analyzer. Install Elastic Defend. To also review process sessions in Session View, select Collect session data in the integration policy.
Alerts and data from other endpoint tools Triage alerts from the endpoint security tools you already use, such as CrowdStrike, Microsoft Defender for Endpoint, and SentinelOne, on the same Alerts page as the rest of your alerts. The analytics and AI features in Elastic Security can then correlate endpoint activity with identity, cloud, and network data. Add the integration for your endpoint tool. To find it, refer to Elastic integrations. To turn the tool's alerts into Elastic Security alerts, install and turn on its prebuilt promotion rule, such as CrowdStrike External Alerts, or the general External Alerts rule.

On Elastic Cloud Serverless projects and Elastic Cloud Hosted deployments, use an Elastic Managed integration whenever one is available for your source. It's the easiest way to get data in, because Elastic runs and maintains the collector for you. Not every integration is available as an Elastic Managed integration, so check the Elastic Managed integrations quick reference first.

For other sources, and on self-managed deployments, use an integration that runs on Elastic Agent. The following table compares the two types of integration:

Integration type Who runs the collector Data sources To get started
Elastic Managed integrations Elastic. You only provide credentials, such as an API key. Cloud services, through an API Enable an Elastic Managed integration.
Integrations that use Elastic Agent You. You install, update, and scale Elastic Agent with Fleet. The host where Elastic Agent runs, or remote sources such as syslog, cloud storage, or an API Install Fleet-managed Elastic Agents.

After you decide which data you need and how to collect it, add the integration:

  1. Go to the Get started page in Elastic Security, and select Set up Security.

  2. In the Ingest your data section, select Add data with integrations.

  3. Select an integration, or browse by category.

    Tip

    To browse the full catalog, go to the Integrations page using the navigation menu or the global search field, then select the Security category.

  4. On the integration's page, select Add followed by the integration's name, such as Add Okta.

  5. Follow the prompts to configure the integration. If you're adding an Elastic Managed integration, also select it as the deployment mode:

    • In the Deployment section, select Elastic Managed Integration.
    • In the Deployment options section, select Agentless.
  6. Select Save and continue.

When you're done, verify that your data reaches Elastic Security.

If you can't find an integration for your data source, such as an in-house application or a less common tool, you can create a custom integration. Elastic offers two ways to build one, and both use a large language model (LLM). Either way, the custom integration maps your data to the Elastic Common Schema (ECS), so you can use it in Elastic Security like data from any other integration.

Option Use it when How you build the integration What you need
Automatic Import You want a working integration quickly, and the integration can collect your data through a method that Automatic Import supports, such as files, cloud storage, Kafka, TCP, or UDP. In Kibana, without writing code. You provide a sample of your data, and the LLM maps it to ECS and creates the integration. An LLM connector, and an Enterprise subscription or the Security Analytics Complete project feature tier. For details, refer to the Automatic Import requirements.
Elastic integration skills The integration must collect data from an HTTP API, or you want full control over the package, including its ingest pipelines, field mappings, dashboards, and tests. In the AI coding environment you already use, such as Cursor, Claude Code, or Codex. AI agent workflows research your data source, then build and test the integration package. To use the finished package, upload it to Kibana. The skills are in beta, so expect them to change. Experience building integration packages, and the tools that the skills run, such as Docker and the elastic-package CLI.

If you already use other tools to collect and ship data, you can send it to Elastic Security with:

  • Beats, lightweight shippers that you install on each system you want to monitor.
  • Logstash, a pipeline that ingests, transforms, and ships data in any format.
  • Third-party collectors and pipelines, such as Cribl, and message queues, such as Kafka.

Elastic Security relies on data that conforms to ECS. Most integrations map their data to ECS with ingest pipelines. If you ship data another way, map as much of it to ECS as you can. To learn how, refer to Map custom data to ECS. When all your sources use the same fields, detection rules, dashboards, and other Elastic Security features work with all your data. For the ECS fields that Elastic Security uses, refer to Elastic Security ECS field reference.

Elastic Security reads data from a default set of index patterns, including logs-*, filebeat-*, and winlogbeat-*. Integrations write their logs to logs-* indices, and Beats write to indices such as filebeat-*, so their data appears in Elastic Security without extra setup.

Important

If your data goes to an index that doesn't match the default index patterns, such as a custom index that Logstash or a third-party collector writes to, add the index to the data view that Elastic Security uses. The default data view reads the index patterns in the securitySolution:defaultIndex advanced setting, so add your index there. If you use a custom data view, add your index to that data view instead.

Whichever method you use, confirm that your data reaches Elastic Security:

  • In Discover, select or create a data view that includes your index, then filter for documents from your source. For integration data, filter on the data_stream.dataset field, for example data_stream.dataset : "okta.system". For data from other methods, filter on the index name, for example _index : filebeat-*.

  • If you used an integration, open a dashboard that it installed. To find one, go to Dashboards and search for the integration's name.

  • On the Data Quality dashboard, select Check now for the index that holds your data. If the check fails, the Incompatible fields tab lists the fields that don't match ECS, so you know which ones to fix in your mappings or ingest pipeline.

  • On the Hosts page, check that each host appears only once. Elastic Security identifies hosts by the host.name field, so a host that sends different host.name values appears as more than one host.

After your data arrives, you can: