Elastic extends production-ready AI capabilities for all!
Elastic Security is making your organization safer with general availability of our favorite AI features.

Elastic Security is announcing the general availability (GA) of two of our most widely deployed generative artificial intelligence (GenAI) capabilities: Attack Discovery, launched in May, and Automatic Import, launched in August. Elastic’s AI-driven security analytics are providing immense value to many organizations. A recent value study from Enterprise Strategy Group reports that one customer utilizing Attack Discovery distilled 1,018 alerts into 8 actionable discoveries.
In joining GA, Automatic Import and Attack Discovery pair with the AI Assistant for Security to bring security operations into the generative AI era. In addition to the powerful, natural language sidekick, organizations everywhere can streamline data ingestion and surface crucial patterns and insights.
“Building a security solution on the foundation of Search AI means that we get to share incredible capabilities that are the very best of what AI can offer security practitioners,” said James Spiteri, director of AI and advanced analytics for Elastic Security. “Both Automatic Import and Attack Discovery uplevel practitioners, but in addition to that efficiency they’re quickly valuable and easy to use. That low learning curve is a top priority for us as product managers, and I’m excited for even more customers to see that increase in visibility for themselves.”
Powerful AI for every SOC
Ease data onboarding with Automatic Import
The most advanced feature of its kind, Automatic Import builds and validates custom data integrations in just minutes. This capability saves practitioners hours of work, enabling teams to efficiently extend visibility across their attack surface.

Surface what’s important with Attack Discovery
Attack Discovery seamlessly transforms all of your SIEM’s alerts into a clear and actionable picture of advancing attacks, enabling teams to respond with exceptional precision and speed. This strengthens defenses, improves team efficiency, and lowers risk.

Together, Automatic Import and Attack Discovery greatly increase an organization’s visibility, reclaim hours for the team, and lower risk. These capabilities are powered by large language models (LLM) and supported by Elastic’s openness and transparency.
The power to use your LLM of choice
Security begins with data and ends with action. But how do you get from point A to point B — and quickly? For Elastic, it’s the use of retrieval augmented generation (RAG) — a technology that grounds LLM prompts in organizational context to improve accuracy and relevance. Elastic’s Search AI Platform is uniquely suited to apply RAG to deliver actionable insights to security teams, and is the foundation of our AI capabilities.
Because Elastic’s capabilities are built upon RAG, Automatic Import and Attack Discovery will always pull accurate, timely context regardless of the LLM you have in place. Security teams can pick and choose the best LLM for them at the time of query, regardless of cost, speed, accuracy, or privacy.
Elastic Security connects natively with the most popular commercial LLMs, as well as any LLM that leverages the OpenAI SDK for their inference service. Some of the most performant models and integrations include:
Google Cloud’s Gemini 1.5 Pro 002 and Gemini Flash 1.5 002 models via the Google Cloud Vertex AI platform
Anthropic’s Claude family of models via Amazon Bedrock
The GPT-4 family of models via OpenAI or Azure’s OpenAI Service
You can see a recommended list of LLM options and their performance here. If you want a deeper dive into how Elastic connects to and protects these LLMs, you can check out the Elastic Security Labs article Elastic Advances LLM Security with Standardized Fields and Integrations.
Try it for free
You can try Elastic Security’s powerful AI-driven security analytics entirely free of charge! Automatic Import and Attack Discovery will speed integration and identify unknown threat patterns for your organization on your LLM of choice. See what you can discover in two weeks, started in a snap with Elastic Cloud Serverless.
The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all.
In this blog post, we may have used or referred to third party generative AI tools, which are owned and operated by their respective owners. Elastic does not have any control over the third party tools and we have no responsibility or liability for their content, operation or use, nor for any loss or damage that may arise from your use of such tools. Please exercise caution when using AI tools with personal, sensitive or confidential information. Any data you submit may be used for AI training or other purposes. There is no guarantee that information you provide will be kept secure or confidential. You should familiarize yourself with the privacy practices and terms of use of any generative AI tools prior to use.
Elastic, Elasticsearch, ESRE, Elasticsearch Relevance Engine and associated marks are trademarks, logos or registered trademarks of Elasticsearch N.V. in the United States and other countries. All other company and product names are trademarks, logos or registered trademarks of their respective owners.