elasticsearch data.md

For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.

Elasticsearch

{% hint style="info" %} Elasticsearch is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis. {% endhint %}

The Dropzone platform integrates with the Elasticsearch security SIEM. Many customers ingest other alert sources into Elasticsearch (e.g. IDPs) and integrate Dropzone into Elasticsearch rather than the source systems.

Create an API Key and Obtain a Cloud ID

Elasticsearch requires an API Key and an Elasticsearch Cloud ID to enable.

{% hint style="info" %} If you are using the Elasticsearch Serverless Projects-Based Model or an On-premise Elasticsearch using the Dropzone connector, you will not need to provide a Cloud ID. {% endhint %}

To obtain an API Key, do the following:

Click Manage

Navigate to API keys

Click "Create an API key"

Create an API key>

Copy the key

To obtain your Elasticsearch Cloud ID, do the following:

Click Open

Click Endpoint & API Keys

Copy the Elasticsearch Cloud ID

Enable Elasticsearch

To enable the Data Source integration, you will need the following information:

Dropzone Field Source
Elasticsearch Cloud ID The cloud ID value copied earlier. Only necessary if you have an Elastic Cloud Hosted deployment
Elasticsearch Server The server for your Elasticsearch project, e.g. https://my-project.es.us-west-2.aws.elastic.cloud
API Token The API token value generated earlier

To enable the Data Source integration, do the following:

Integrations Dropdown

Click Available

The Elasticsearch Tile

The Elasticsearch Data Configuration (pt 1)

The Elasticsearch Data Configuration (pt 2)

The Elasticsearch Data Configuration (pt 3)

If you have any errors engage your Dropzone AI support representative.