ElasticSearch ↗
Important
This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.
Elasticsearch is the distributed search and analytics engine at the heart of the Elastic Stack, where the indexing, search, and analysis happens. Query Elasticsearch instances using DSL, EQL, and Lucene syntaxes, search and index documents, collect events, fetch issues with a predefined query, and fetch threat intelligence indicators from an Elasticsearch database.
This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):
- Elasticsearch v2: Search for and analyze data in real time.\
Supports version 6 and later. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. - ElasticsearchEventCollector: Search for and analyze data in real time.\
Supports version 6 and later. This sub-capability is available with any active Cortex XSIAM license. - ElasticsearchFeed: This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
To configure this connector, follow the steps outlined in the configuration wizard.