Elastic Security π¦
Elastic Security provides SIEM capabilities built on the Elasticsearch/Logstash/Kibana (ELK) stack.
Components
- Elasticsearch β Security events storage and search
- Beats/Fleet β Lightweight agents for log collection
- Elastic Defend β Endpoint security integration (replacement for Endpoint Integrations)
- Kibana Security β Dashboards, detection rules, case management
Architecture
Agents (Elastic Defend, Filebeat)
β
βΌ
Logstash / Fleet Server
β
βΌ
Elasticsearch Indexer
β
βΌ
Kibana (Security App)
βββ Detection Rules
βββ Cases
βββ Timelines
βββ Dashboards
Detection Rules
Built-in rules mapped to MITRE ATT&CK. Custom rules written in KQL (Kibana Query Language).
event.category: process and process.name: "powershell.exe" and
process.args: "-enc" and not user.name: "SYSTEM"Your Context
If youβre using Wazuh as primary SIEM, Elastic Security is a potential migration target for:
- Large-scale environments (Elastic scales better at 10B+ events/day)
- Teams already on the ELK stack
- When you need advanced ML anomaly detection (Elastic SIEM has built-in ML jobs)