Showing ideas with status Investigating.
Show all ideas
Status:
Investigating
Submitted on
‎03-03-2025
08:59 AM
Submitted by
gurveersingh
on
‎03-03-2025
08:59 AM
Can we update the Elasticsearch connector to ingest triggered alerts in the same way we do for other SIEMs like FortiSIEM and Splunk? Additionally, can we create playbook collections that can be scheduled to ingest these alerts? Here is the API documentation for retrieving alerts: https://www.elastic.co/guide/en/security/current/signals-api-overview.html Please let me know if you need any further information
... View more