Automate detection and investigation with Tines and Elastic
Together, Tines and Elastic provide security teams with all the information they need to investigate alerts, make business critical decisions in one place all while saving valuable time and resources. By combining the value of high-fidelity detection and alerting delivered by Elastic Security with Tines’ robust automation, SOC teams can effectively support continuous monitoring, threat detection and prevention, alert enrichment, incident response and more. Learn how Texas A&M University System Cyber Operations drives efficient scaling with Tines and Elastic.
Key benefits
Scale security operations efforts
Integrate context & data enrichment into alerts
Investigate & react to alerts faster
Use case examples

Monitor BitSight findings and track remediation in ServiceNow
Retrieve compromised systems and botnet infection findings from BitSight, create ServiceNow incidents, and enrich them with Elasticsearch and Shodan data. Generate CSV reports, update BitSight remediation status, and email security findings to relevant teams.
Tools

Elastic SIEM to Slack alert enrichmentTools: Elastic, Slack, Tines



Check Workday for unauthorized travel and alert in SlackTools: Elastic, Jumpcloud, OpsGenie, Slack, WorkdayUseful resources

Announcing a new joint product offering from Tines and Elastic

“Better context in a world that's changing quickly”: Leading CISOs discuss AI’s role in SecOps

How cloud engineering teams use Elastic Observability and Tines to optimize resources

Elastic’s Mandy Andress on switching from a tech-first to people-first approach to security

“Crawl, walk, run into zero trust”: a Q&A with Elastic’s John Harmon

Automating Detection-as-Code

Tines and Elastic partner to detect security threats and reduce mean time to respond

Elastic’s James Spiteri: Why SecOps teams need to focus on small incremental wins and not try to boil the ocean

ELK Stack automation and the Elasticsearch API
