Partners

Automate detection and investigation with Tines and Elastic

Elastic logo
Sign upBook a demo

Together, Tines and Elastic provide security teams with all the information they need to investigate alerts, make business critical decisions in one place all while saving valuable time and resources. By combining the value of high-fidelity detection and alerting delivered by Elastic Security with Tines’ robust automation, SOC teams can effectively support continuous monitoring, threat detection and prevention, alert enrichment, incident response and more.

Key benefits

Scale security operations efforts

Integrate context & data enrichment into alerts

Investigate & react to alerts faster

Use case examples

Example 1

Identify and remediate high AWS EC2 Disk Usage with Elastic Observability and document with Tines cases

Receive Elastic Observability Alerts on an AWS EC2 instance's high disk usage performance over average time. This automated process generates a Tines case and solicits input from the administrator regarding the desired size upgrade. Subsequently, the instance is dynamically adjusted to the specified size, ensuring optimal performance.

Example 2

Detect and remediate high AWS EC2 CPU usage with Elastic Observability and document with Tines cases

Receive Elastic Observability Alerts on an AWS EC2 instance's high CPU performance over average time. This Story generates a case in Tines and solicits input from the administrator regarding the desired instance type. Subsequently, the instance is dynamically adjusted to the specified type, ensuring optimal performance.

Example 3

Create Tines Cases from Elastic Common Schema

Elastic Common Schema (ECS) provides a way to normalise data across multiple products. Create Tines cases using this standard format for a variety of tasks.

Tools

Elastic

Created by

Conor Dunne

Example 4

Upload and execute a file on Elastic Fleet endpoint

Use a Tines page to select an endpoint on Elastic and provide a file. The file is uploaded and is executed on the host.

Tools

Elastic

Created by

Conor Dunne

Example 5

Download files from Elastic Agent host via a Tines Page

Select an endpoint on Elastic and provide a file location. Download the file from the host and retrieve it via Tines page if it exists.

Tools

Elastic

Example 6

Isolate a host protected by Elastic Endpoint

Use a sent-to-story and a hostname to manage an endpoints isolation status in Elastic. If no device exists with that hostname, an error is returned.

Tools

Elastic

Created by

Conor Dunne

An illustration of a chain with two rings

Detect security threats and reduce time to respond with Tines and Elastic