Contact sales
Details

Accelerate results that matter when you use Elastic to address your search, observability, and security challenges. Deploy in your favorite public cloud, or in multiple clouds.

Accelerate results that matter when you use Elastic to address your search, observability, and security challenges. Deploy in your favorite public cloud, or in multiple clouds. Extend the value of Elastic with generative AI, cloud-native features and hundreds of built-in integrations to unlock the power of data, securely and at scale.

From document- and field-level security to analyzing data in real time with interactive visualizations, Elastic Cloud (the Elasticsearch service) delivers powerful features that readily extend what’s possible with the Elastic Stack.

Enabling this integration in Cisco XDR will make the Elastic Cloud API available as a target for automation workflows. Workflows can be used to do things like send incident data to Elasticsearch for indexing and retention.

Capabilities
Automation
Automatic target creation for Cisco XDR automation
Health
Validates that the integration is healthy
Regions
North America
Europe
Asia-Pacific, Japan & China
Installable workflows

These are workflows that you can install in Cisco XDR automation and use with this integration. These are different from built-in workflows which are built into Cisco XDR by default for all customers.

Cisco Managed
This workflow allows you to export a summary of an XDR incident to an Elastic Cloud index/document.
Built-in workflows

These workflows are built into Cisco XDR automation and can be used with this integration. These are different from installable workflows, which are optional workflows you can install from Cisco and its partners.

Built-in actions

These actions can be used in Cisco XDR automation to build workflows for this product. Workflows can help you automate how you investigate, respond to incidents, and more.

Configuration details