ELK + ElastAlert

My SIEM is ELK + ElastAlert and it seems I can't connect ElastAlert to siemplify

0 6 143
6 REPLIES 6

Thanks to everyone who will take time to answer this

Hi @Paul_Skaf how are you? The Elastic Search Integration isn't currently available in the Community edition and is available in our Enterprise edition. However, this should become available soon and I can update you once it does.

I'm good and you @shakedtal ? Thanks for your answer.
Does the Elastic Search Intergrations is also the name/ same object in the marketplace for the Connector ? It seems that in the Community Edition online we can't have any connectors that support ElastAlert or the ELK Stack

Yes the integration including the connector isn't available in the Community Edition but will be soon. You can see what the integration includes in the following integration documentation - Elastic V5 + Elastic V7 . Once it becomes available I will notify via this thread. In the meantime I can connect you with a sales rep to provide a demo and assist with access to a trial environment. Please let me know and I'll be happy to assist.

Hi @shakedtal . Thanks for the answer. I'll be happy to have a trial environment about the elasticsearch integrator + connector.
I can't know yet if siemplify would be a nice solution for us becasue of this limitation

Late reply, but FWIW, I don't think you really would want to connect ElastAlert to Siemplify per-se, but instead would connect Siemplify to an output that ElastAlert generates.

You _could_ connect Siemplify to the ElastAlert "alerts" index in Elasticsearch using the Siemplify ElasticSearch connector, or you could configure ElastAlert to run an "alert" that writes the alert message to some external service that Siemplify can use as an input (i.e. Email, Slack, Teams, or more likely the "post2" alert which would send the alert to an arbitrary external API as a JSON message).

Of course, you won't be able to do any of that with the Community edition at present.

We, too, have an Elastic-based SIEM, but we are looking into using the Kibana Security app with its native Rules and Alerts engine as an alternative to ElastAlert. If this works out, it will be considerably easier for our analysts to generate Elastic Stack alerts for ingestion into Siemplify. ElastAlert is a bit ungainly for use by our analysts.