IntelMQ
Feed automation · Austria
Read the tool profileDocumented support
Documents event delivery to Elasticsearch through a Redis output bot and Logstash. The walkthrough targets ELK 6.8.0, so current-version setup needs adaptation.
An independent tool index
for incident response teams
Documented work with an Elastic component. Elasticsearch storage, rule conversion and event forwarding are different functions.
Filter these toolsEach entry describes the documented operation and links to its source. A format reference, an optional connector and built-in execution are different capabilities. Check the note before shortlisting.
Confirm your product version, edition, connector and access requirements in the upstream instructions. These listings record documentation, not a tested configuration. Read the evidence standard.
4 tools with documented Elastic integration evidence.
Feed automation · Austria
Read the tool profileDocuments event delivery to Elasticsearch through a Redis output bot and Logstash. The walkthrough targets ELK 6.8.0, so current-version setup needs adaptation.
Detection and monitoring · Belgium
Read the tool profileSearches and exports Elastic Security rules through configured Elasticsearch and Kibana endpoints. Supports EQL and ES|QL; the guide limits Sigma correlation rules to ES|QL.
Detection and monitoring · Germany
Read the tool profileBundles an Elastic Stack pipeline for collecting and visualizing honeypot events. This documents the supplied T-Pot stack; compatibility with an independently managed Elastic deployment is not established here.
Feed automation · Germany
Read the tool profileThe to_opensearch operator, also exposed as to_elasticsearch, sends batched events to an Elasticsearch-compatible Bulk API.
A missing tool may support this feature without having been checked in this research pass.
Send a source or correction