Turn security alerts into documented, acknowledged cases.
security operations
Analyzes Elastic Security alerts, documents classifications in cases, and acknowledges the investigated alerts.
When to use it
Use when triaging alerts, performing SOC analysis, or investigating detections.
Give it an alert-triage request; it investigates the alerts, creates or updates a case, and acknowledges related alerts.
This skill
Elastic Security alerts
Acknowledges Elastic Security alerts (irreversible)
Kibana cases
Creates and updates Kibana cases
Elasticsearch
Reads alerts and security telemetry
npm install
Installs the skill dependencies
Requires Node.js 22 or newer.
The scripts import the Elasticsearch client package.
Requires network access to an Elasticsearch deployment.
Requires a Kibana deployment for case management.