Company
Date Published
Author
Mike Paquette
Word count
1163
Language
-
Hacker News points
None

Summary

Elastic SIEM, now part of Elastic Security, was introduced as a beta feature in the 7.2 release of the Elastic Stack, offering a new approach to Security Information and Event Management (SIEM) through data integrations and a dedicated app in Kibana. This tool allows security teams to streamline host and network security workflows with features like the Timeline Event Viewer for investigation and evidence gathering. Elastic SIEM utilizes the Elastic Common Schema (ECS) to normalize data from various sources, facilitating cross-source correlation and analysis. With its free availability as part of the Elastic Stack's default distribution, Elastic SIEM has been adopted by organizations such as Bell Canada, Slack, Cisco Talos, and others for security analytics and threat hunting. It provides an interactive workspace for security practitioners in Kibana, enhancing capabilities for host and network security event analysis. The company plans to expand its offerings with features like detection rules and threat intelligence integration, as it continues to innovate and redefine traditional SIEM boundaries.