Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Elasticsearch Incident Enrichment integration

The Elasticsearch - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.

Explore Security Incident Response integrationsSet up - Get started with the Elasticsearch - Incident Enrichment integration - Create sightings search configuration records
Use - Run a Sightings Search - Security Operations Integration - Sightings Search Flow - Security Operations - Elasticsearch Sightings Search FlowDevelop - ServiceNow Security Operations integration development guidelines - Tips for writing integrations - Developer training - Developer documentation - Find components installed with an application
Troubleshoot and get help - Integration troubleshooting - Ask or answer questions in the Security Operations community - Search the Known Error Portal for known error articles - Contact Customer Service and Support