12.3 Elastic AI Assistant for Security & Attack Discovery

Key Takeaways

  • Elastic AI Assistant and Attack Discovery require an Enterprise subscription and an LLM connector (OpenAI, Azure OpenAI, Amazon Bedrock, Google Vertex, or a local OpenAI-compatible model).

  • Analysts open AI Assistant with the Chat button in the alert or event flyout (and from Timeline, Rules and the Data Quality dashboard) to explain alerts, decode commands and draft KQL, EQL or ES|QL queries.

  • Attack Discovery (technical preview in 8.15) analyzes open and acknowledged alerts from the past 24 hours, 20 by default and up to 100, and describes related alerts as discoveries with hosts, users and MITRE ATT&CK stages.

  • Anonymization is field-based: only Allowed fields are sent, and Allowed fields marked Anonymized are replaced with random values before reaching the LLM.

  • The assistant never takes response actions itself; analysts verify its output and decide, and Kibana feature privileges control who can use and configure the AI features.

Last updated: September 2026

Generative AI Architecture in Security Operations

Security Operations Centers face a compounding triad of operational challenges: exponential telemetry growth, rapid evolution of adversary tactics, and a persistent global shortage of experienced cybersecurity analysts. Tier 1 analysts are frequently overwhelmed by high-volume, cryptic detection alerts containing dense JSON payloads, obfuscated command lines, and obscure Windows Event IDs. Investigating these alerts requires deep contextual expertise across operating systems, network protocols, and threat actor tradecraft.

The Elastic AI Assistant for Security introduces domain-specialized generative AI directly into the analyst workflow. Rather than acting as a disconnected general chatbot, the AI Assistant is deeply integrated into the Elastic Security fabric—accessible from the Alert Details Flyout, Timelines, Cases, Rule Management, and Kibana Discover.

Requirements at a Glance

  • Subscription: Elastic AI Assistant and Attack Discovery require an Enterprise subscription.
  • Privileges: Using AI Assistant needs Elastic AI Assistant: All plus Actions and Connectors: Read. Setting it up (creating the LLM connector) needs Actions and Connectors: All, and changing anonymization settings needs the Customize sub-feature privilege. Attack Discovery has its own feature privilege.
  • An LLM connector: Elastic does not supply the model. You connect a third-party or local large language model (LLM).
+-------------------------------------------------------------------------+
|               Elastic AI Assistant Architectural Stack                  |
+-------------------------------------------------------------------------+
|  Analyst prompt + optional context (alert, event, Timeline, dashboard)  |
|                                    |                                    |
|                                    v                                    |
|        [ Anonymization settings: Allowed fields, Anonymized fields ]    |
|                                    |                                    |
|                                    v                                    |
|   [ Knowledge base (optional): ES|QL docs, alerts, via ELSER ]          |
|                                    |                                    |
|                                    v                                    |
|                    [ Kibana LLM connector ]                             |
|    +------------------+------------+-----------+-------------------+    |
|    v                  v                        v                   v    |
| [OpenAI]       [Azure OpenAI]           [Amazon Bedrock]  [Google Vertex|
|                                         (e.g. Claude)      (Gemini)]    |
|              [Local LLM, e.g. LM Studio, OpenAI-compatible]             |
+-------------------------------------------------------------------------+

1. LLM Connectors

AI Assistant and Attack Discovery share the same connectors. Elastic's 8.15 setup guides cover:

  • OpenAI and Azure OpenAI (through the OpenAI connector).
  • Amazon Bedrock, for example with Anthropic Claude models.
  • Google Vertex AI (Gemini models).
  • Custom local LLMs, for example a model served by LM Studio and reached through the OpenAI connector's OpenAI-compatible option.

Elastic does not control these third-party services. Data you send is handled under your provider's terms, so choose a provider and deployment that meet your data-handling policies.

2. Context and the Knowledge Base

AI Assistant opens from several places and passes relevant context with your question:

  • Alert or event details flyout: Click Chat to send that alert or event (after anonymization).
  • Timeline (its Security Assistant tab), the Rules page (help creating or correcting rule queries), and the Data Quality dashboard, where Chat on an incompatible field asks for help fixing the ECS mapping.
  • Anywhere: The AI Assistant button in the top toolbar, or Cmd + ; (Ctrl + ; on Windows).

Quick prompts help with common tasks, such as summarizing an alert or converting a query from another SIEM. System prompts and quick prompts can be customized, and each user's conversations are saved so they can be resumed. Responses offer inline actions: Add note to timeline, Add to existing case, Copy to clipboard, and, for some queries, Add to timeline.

The optional knowledge base (turned on in AI Assistant settings; it uses ELSER and needs machine learning) adds Elastic's ES|QL documentation and, if enabled, alerts from your environment. That lets the assistant answer ES|QL questions and questions about recent alerts more accurately.


Operational SecOps Use Cases

1. Alert Explanation and De-obfuscation

When triaging complex alerts, such as encoded PowerShell, living-off-the-land utilities or memory injection, analysts click Chat in the alert details flyout and use a quick prompt or their own question:

  • Plain-language explanation: Decode base64 commands, unpick obfuscated command lines, and explain what the attacker was trying to do.
  • Impact questions: Ask what the command could have touched and what to check next, then verify the answer against the raw alert data.

2. Natural Language Query Generation (KQL, EQL and ES|QL)

AI Assistant can turn a plain-language request into a query:

  • An analyst asks: "Show source IPs with more than 5 failed SSH logins in the last 6 hours that also had a successful login."
  • The assistant returns a query such as:
FROM logs-system.auth-*
| WHERE event.category == "authentication" AND @timestamp > NOW() - 6 HOURS
| EVAL failed = CASE(event.outcome == "failure", 1, 0),
       succeeded = CASE(event.outcome == "success", 1, 0)
| STATS fail_count = SUM(failed), success_count = SUM(succeeded) BY source.ip, user.name
| WHERE fail_count > 5 AND success_count > 0
| SORT fail_count DESC

The analyst reviews the query before running it, for example in Discover or in Timeline's ES|QL tab. Generated queries can contain mistakes, such as functions that do not exist, and the ES|QL knowledge base reduces them.

3. Remediation Guidance

The assistant can suggest containment and eradication steps, such as isolating a host with Elastic Defend, Osquery queries to sweep other endpoints for a dropped hash, or credential resets. It cannot take response actions itself: an analyst decides and acts.

4. Incident Documentation

Given alert context or pasted case notes, the assistant can draft summaries, timelines and handoff notes for an analyst to review and edit.


Attack Discovery: LLM-Driven Alert Correlation

In a real intrusion an adversary triggers many alerts across hosts and users. Attack Discovery uses the connected LLM to analyze a batch of alerts and describe which of them belong together as attacks. In Elastic Security 8.15 it is a technical preview feature.

+--------------------------------------------------------------------------+
|                         Attack Discovery (8.15)                          |
+--------------------------------------------------------------------------+
| Input: open and acknowledged alerts from the past 24 hours               |
|        (20 alerts by default, up to 100 via AI Assistant settings)       |
|        -> filtered through the same anonymization settings               |
|                            |                                             |
|                            v                                             |
|                 [ Selected LLM connector ]                               |
|                            |                                             |
|                            v                                             |
| Each "discovery": title and summary, number of related alerts, the      |
| MITRE ATT&CK stages involved, and the implicated hosts and users with   |
| what was observed for each                                               |
+--------------------------------------------------------------------------+

1. Generating Discoveries

Open the Attack discovery page, select an LLM connector (the same ones AI Assistant uses), and click Generate. Analysis takes from seconds to several minutes. It considers open and acknowledged alerts from the past 24 hours: 20 by default, which you can raise to 100 in AI Assistant → Settings → Knowledge base (the Alerts setting). Elastic's testing found models with large context windows, such as Claude 3 Sonnet and Opus, performed best.

2. Working with Discoveries

Each discovery includes a descriptive title and summary, the number of associated alerts and the MITRE ATT&CK tactics they map to, and the implicated users and hosts with the activity observed for each. From a discovery you can:

  • Click a user or host to open its details flyout, or add it to Timeline.
  • Take action → Add to new case or Add to existing case.
  • Investigate in timeline to review the underlying alerts.
  • View in AI Assistant to ask follow-up questions.

A discovery is the model's interpretation of the alerts. Treat it as a strong lead and verify it in Timeline before acting.


Security, Privacy and Governance Controls

1. Field-Level Anonymization

The Anonymization tab in AI Assistant settings controls every alert or event you send as context, and Attack Discovery uses the same settings:

  • Fields with Allowed turned on are sent. Other fields are not sent at all.
  • Allowed fields with Anonymized set to Yes are sent with their values replaced by random stand-in values. For example, a host name might become a random string. Kibana maps them back so you still see real values.
  • When you attach a specific event to a conversation, you can adjust these choices for that event before sending.
  • The Show anonymized toggle only changes what you see in the chat. It does not change what is sent.

Anonymization is field-based. It does not automatically detect personal data inside free-text fields, so leave fields such as full command lines or message bodies not allowed if they may contain secrets.

2. Provider Terms and Data Handling

Because Elastic does not control third-party LLMs, anything sent is subject to the provider's terms. Organizations with strict requirements choose enterprise deployments (for example Azure OpenAI or Amazon Bedrock under their own cloud agreements) or a local LLM, and restrict which fields are allowed.

3. Access Control and Records

  • Feature privileges: Elastic AI Assistant and Attack discovery are separate Kibana features (All or None), and configuring connectors requires the Actions and Connectors privilege.
  • Conversation history: Each user's chats and custom prompts are saved automatically. Kibana audit logging can additionally record user activity for compliance.

Reference Matrix: AI Capabilities, Risks and Controls

CapabilityWhat It DoesMain RiskControl
Alert explanationExplains alerts and decodes obfuscated commandsConfident but wrong explanationsVerify against the raw alert (Table and JSON tabs) before deciding
Query generationTurns requests into KQL, EQL or ES|QLInvalid or inefficient queriesAnalyst reviews and runs the query; enable the ES|QL knowledge base
Remediation suggestionsProposes containment and follow-up checksOver-aggressive actionsThe assistant cannot act; a human decides
Attack DiscoveryGroups recent alerts into described attacksLinking unrelated alertsReview each discovery in Timeline; tech preview in 8.15
LLM connectivitySends context to OpenAI, Azure OpenAI, Bedrock, Vertex or a local LLMSensitive data leaving the environmentField anonymization, provider choice, Kibana privileges
Loading diagram...
Elastic AI Assistant Anonymization and LLM Interaction
Test Your Knowledge

A SOC manager is reviewing dozens of security alerts raised over the past day across fifteen Windows endpoints and two Linux servers. Rather than assigning each alert to different analysts in isolation, the manager wants the related alerts grouped, with a narrative of which hosts and users are involved and how the activity maps to MITRE ATT&CK. Which Elastic Security feature provides this capability?

A

Logstash Persistent Queue Manager

B

Elastic Agent Fleet Enrollment Token Rebalancer

C

Attack Discovery, which sends recent open and acknowledged alerts to the connected LLM and returns discoveries describing related alerts, affected hosts and users, and ATT&CK stages

D

Kibana Canvas Workpad Shape Renderer

Test Your Knowledge

An enterprise operating under strict European Union GDPR regulations wants to enable the Elastic AI Assistant for Security using a public cloud LLM connector. Which built-in privacy governance capability ensures that employee personal names, corporate email addresses, and internal network IP addresses are not transmitted to the external LLM provider?

A

The AI Assistant anonymization settings, where user, host and IP fields are either not allowed or set to Allowed with Anonymized = Yes, so their real values are replaced before anything reaches the LLM.

B

Disabling TLS encryption on all Kibana Action Connectors to strip HTTP headers.

C

Recompiling the Elasticsearch JVM to run in single-user maintenance mode.

D

Configuring all endpoints to run in promiscuous packet capture mode without an Elastic Agent.

Test Your Knowledge

A Tier 1 analyst investigating a suspected persistence mechanism wants to query process execution logs for unusual scheduled task creations across all domain controllers, but lacks proficiency in writing complex pipe-based ES|QL syntax. How can the analyst utilize the Elastic AI Assistant to accomplish this task?

A

Request that the AI Assistant reboot the domain controllers and inspect BIOS boot logs.

B

Describe the search objective in natural language within the AI Assistant prompt, which translates the intent into syntactically valid ES|QL queries ready to execute.

C

Download an external third-party compiler script onto the production database server.

D

Manually delete the detection rule and wait for the Fleet Server to regenerate the query syntax.

Sections you finish are checked off in the contents.