Skip to main content
Feedback

Elastic Security MCP connector

Updated 

Elastic Security is a SIEM and endpoint security solution built on the Elastic Stack for threat detection and incident response. The Elastic Security MCP connector allows AI agents to create, update, and manage security cases throughout their investigation lifecycle. It also supports tracking case status and tags, adding and updating comments, and searching across cases to streamline incident triage and collaboration.

Authentication type

  • API Key - Requires a static API key to be configured before the agent can connect to the service.

Uses

Use the Elastic Security MCP connector to perform the following actions:

  • Investigate security incidents by creating and tracking cases in Elastic Security
  • Track case status and progress across active security investigations
  • Organize threat investigations with tags, comments, and status updates
  • Coordinate incident response teams through shared case comments and updates
  • Audit case history by retrieving comments and updates for compliance reviews
  • Connect Elastic Security to external tools and services through connectors
  • Monitor open, in-progress, and closed case counts across the security team
  • Search and filter cases to prioritize the most critical threats

Example prompts

Use the following example prompts to invoke Elastic Security MCP connector tools from your AI assistant or Boomi Connect workflow:

  • Create a new case in Elastic Security for the suspicious login activity we found today.
  • Show me all open cases in Elastic Security from this week.
  • Add a comment to the phishing incident case in Elastic Security.
  • How many cases are currently open in Elastic Security?
  • Find all cases tagged as high priority in Elastic Security.
  • Update the status of the malware case in Elastic Security to closed.
  • List all the tags used across cases in Elastic Security.
  • Delete the duplicate case that was created by mistake in Elastic Security.
  • Get the details of case number 452 in Elastic Security.
  • Set up a new connector in Elastic Security for our ticketing system.

Elastic Security MCP connector tools

The Elastic Security MCP connector provides the following tools. Each tool maps to a specific action you can invoke from your AI agent or automation.

ToolDescription
createCaseCreate a case
updateCaseUpdate a case
deleteCaseDelete cases
getCaseGet a case
findCasesFind cases
getCaseStatusGet case status counts
getCaseTagsGet all case tags
getAllCaseCommentsGet all case comments
addCaseCommentAdd a case comment
updateCaseCommentUpdate a case comment
getCaseCommentGet a case comment
removeCaseCommentRemove a case comment
createConnectorCreate a connector
findConnectorsFind connectors
On this Page