Elastic integrations, in detail.

Documented work with an Elastic component. Elasticsearch storage, rule conversion and event forwarding are different functions.

Filter these tools

Check the actual function

Each entry describes the documented operation and links to its source. A format reference, an optional connector and built-in execution are different capabilities. Check the note before shortlisting.

Before you connect it

Confirm your product version, edition, connector and access requirements in the upstream instructions. These listings record documentation, not a tested configuration. Read the evidence standard.

4 tools with documented Elastic integration evidence.

droid

Detection and monitoring · Belgium

Read the tool profile

Documented support

Searches and exports Elastic Security rules through configured Elasticsearch and Kibana endpoints. Supports EQL and ES|QL; the guide limits Sigma correlation rules to ES|QL.

T-Pot

Detection and monitoring · Germany

Read the tool profile

Documented support

Bundles an Elastic Stack pipeline for collecting and visualizing honeypot events. This documents the supplied T-Pot stack; compatibility with an independently managed Elastic deployment is not established here.

A missing tool may support this feature without having been checked in this research pass.

Send a source or correction