Elasticsearch v1.7.0
Search for and analyze data in real time. Supports version 6 and later.
- Author:
- Cortex XSOAR
- Support:
- xsoar
- Default data source:
- Elasticsearch v2
AgentixCloud Runtime SecurityXSIAMEDRCortex CloudAttack Surface ManagementCloud Posture SecurityExposure Management
Database
Incident fields (14)
- Elasticsearch Alert ID
- Elasticsearch Alert Reason
- Elasticsearch Case Close Reason
- Elasticsearch Case ID
- Elasticsearch Case Status
- Elasticsearch Event info
- Elasticsearch Host
- Elasticsearch Machine
- Elasticsearch Source
- Elasticsearch Status Update Date
- Elasticsearch Timestamp
- Elasticsearch Workflow Alert Status
- Elasticsearch Workflow Alert Status Reason
- Elasticsearch index
Integrations (2)
README
Elasticsearch is the distributed search and analytics engine at the heart of the Elastic Stack and where the indexing, search, and analysis magic happens.
Elasticsearch offers speed and flexibility to handle data in a wide variety of use cases.
What does this pack do?
This pack provides an integration with the Elasticsearch API and allows you to
- Query Elasticsearch instances using DSL, EQL and Lucene syntaxes.
- Search an index in Elasticsearch
- Index a document into an Elastisearch index.
In addition, you can fetch incidents with predefined query.