Elastic Cloud Integration

Note: This integration requires Cisco XDR Advantage or Cisco XDR Premier licensing tier.

Accelerate results that matter when you use Elastic to address your search, observability, and security challenges. Deploy in your favorite public cloud, or in multiple clouds. Extend the value of Elastic with generative AI, cloud-native features and hundreds of built-in integrations to unlock the power of data, securely and at scale.

From document- and field-level security to analyzing data in real time with interactive visualizations, Elastic Cloud (the Elasticsearch service) delivers powerful features that readily extend what’s possible with the Elastic Stack.

Enabling this integration in Cisco XDR will make the Elastic Cloud API available as a target for automation workflows. Workflows can be used to do things like send incident data to Elasticsearch for indexing and retention.