Elastic Security MCP connector
Elastic Security is a SIEM and endpoint security solution built on the Elastic Stack for threat detection and incident response. The Elastic Security MCP connector allows AI agents to create, update, and manage security cases throughout their investigation lifecycle. It also supports tracking case status and tags, adding and updating comments, and searching across cases to streamline incident triage and collaboration.
Authentication type
- API Key - Requires a static API key to be configured before the agent can connect to the service.
Uses
Use the Elastic Security MCP connector to perform the following actions:
- Investigate security incidents by creating and tracking cases in Elastic Security
- Track case status and progress across active security investigations
- Organize threat investigations with tags, comments, and status updates
- Coordinate incident response teams through shared case comments and updates
- Audit case history by retrieving comments and updates for compliance reviews
- Connect Elastic Security to external tools and services through connectors
- Monitor open, in-progress, and closed case counts across the security team
- Search and filter cases to prioritize the most critical threats
Example prompts
Use the following example prompts to invoke Elastic Security MCP connector tools from your AI assistant or Boomi Connect workflow:
Create a new case in Elastic Security for the suspicious login activity we found today.Show me all open cases in Elastic Security from this week.Add a comment to the phishing incident case in Elastic Security.How many cases are currently open in Elastic Security?Find all cases tagged as high priority in Elastic Security.Update the status of the malware case in Elastic Security to closed.List all the tags used across cases in Elastic Security.Delete the duplicate case that was created by mistake in Elastic Security.Get the details of case number 452 in Elastic Security.Set up a new connector in Elastic Security for our ticketing system.
Elastic Security MCP connector tools
The Elastic Security MCP connector provides the following tools. Each tool maps to a specific action you can invoke from your AI agent or automation.
| Tool | Description |
|---|---|
| createCase | Create a case |
| updateCase | Update a case |
| deleteCase | Delete cases |
| getCase | Get a case |
| findCases | Find cases |
| getCaseStatus | Get case status counts |
| getCaseTags | Get all case tags |
| getAllCaseComments | Get all case comments |
| addCaseComment | Add a case comment |
| updateCaseComment | Update a case comment |
| getCaseComment | Get a case comment |
| removeCaseComment | Remove a case comment |
| createConnector | Create a connector |
| findConnectors | Find connectors |