kimo
Security

Elastic Security + Kimo

SIEM detections and endpoint events. Correlate alerts and telemetry with intelligence feeds and assets, and cut the noise your analysts wade through.

Auth
Read-only credentials
Sync
Real time
Setup
≈ 10 min
Request access

Live demo workspace with fictional data · no signup, no credentials needed

kimo / connectors / elasticSyncing
Sync logreal time
  • Succeeded:endpoint_events+1,387 rowsnow
  • Succeeded:detections+2,168 rows2m ago
  • Succeeded:endpoint_events+2,225 rows4m ago
  • Succeeded:detections+606 rows6m ago
Rows synced · 30 days
64.1M
Workspaces
5%
Simulated demo data
What you can do

What teams build with Elastic Security

Elastic Security on its own answers half the question. Joined with the rest of your stack in Kimo, it answers the other half.

01

Alerts by ATT&CK tactic

Group detections by MITRE technique and see which ones actually fire in your estate.

MITRE heatmap
02

MTTD / MTTR tracking

Measure detection and response times per team, severity and asset criticality.

MTTR p50
03

Enrich with intelligence

Correlate indicators from alerts with OSINT and threat feeds in one view.

IOC matches
Objects & tables

Exactly what gets synced

Kimo maps Elastic Security into clean, typed tables with primary keys and incremental cursors, so syncs stay fast and joins just work.

2 tables · 9 fields

detections

Streaming≈ 8,980,000 rows
FieldTypeNotes
ididPrimary key
@timestampstring
rule.namestring
severityenumLow-cardinality dimension
host.namestring
Custom fields and extra objects are discovered automatically on each sync. Row counts are illustrative.
Sample model

From raw Elastic Security tables to a certified metric

A starter model Kimo suggests the moment Elastic Security is connected. Every join is editable.

Elastic Security · SOC overview

Events and alerts joined with assets and threat intelligence on host and indicator.

Template
  • Elastic Security
    detections
  • OSINT Feeds
    indicators
  • Apache Kafka
    topic.telemetry
Model
host · indicator
Measuresalertsincidents
Alerts · last 30 days
1,782-4.1% wk/wk

Fictional data · hover the chart for daily values

Setup

Connect Elastic Security in 10 min

No engineers, no pipelines to maintain. Kimo asks for the minimum access it needs and tells you exactly what it will read.

  1. 1

    Create a service identity

    Issue a token or account scoped to the indexes, topics or feeds Kimo should read.

  2. 2

    Open network access

    Allow Kimo’s static egress IPs, use an SSH tunnel, or run the on-prem agent inside your network.

  3. 3

    Enter connection details

    Credentials are encrypted at rest with a per-workspace key and tested before saving.

  4. 4

    Select tables

    Choose what to sync, starting with detections. Kimo backfills, then keeps it fresh.

Read-only, encrypted, revocable. Credentials are encrypted with a per-workspace key, never logged, and can be rotated without breaking your models.

Connect Elastic Security
Step 2 of 3 · Kimo demo workspace
  • Reaching host
  • Authenticating
  • Reading schema
Read-only access
Illustration only · placeholder values, never real secrets
FAQ

Elastic Security questions, answered

Elastic Security is ingested as a stream. New records typically appear in models and maps within a few seconds.

Elastic Security · Read-only credentials · Real time

See your Elastic Security data in Kimo in 10 min.

Try it on the live demo workspace first, then connect your own account when you are ready.

Request access