Network Analyzer Agents for Elastic
Use three Elastic Agent Builder agents and supporting ES|QL tools to analyze network health, packet evidence, Suricata findings, DNS/TLS risks, HTTP failures, and top conversations.
Get content for Kibana, Elasticsearch, Logstash and more
Elastic Content Share
Download overview
Elastic Solutions are a great addition to the common usage of Elasticsearch, Kibana, Logstash and Beats. They combine the power of all tools and provide best practice implementation for their specific key area.
However using Elastic Solutions in Kibana also feels limited from time to time as you need to stick to the UI of the specific solution. If you want to get more out of the data you need to create your own dashboard based on Elastic Common Schema (ECS) to reuse the data that is also used in the Elastic Solutions.
Here you find community driven dashboards and other conent that enhancing the OOTB experience of any Elastic solution.
Use this collection
Solutions downloads collect reusable Elastic Stack examples that can help you build dashboards, rules, pipelines, visualizations, and operational workflows faster.
Download the content, import it into your Elastic environment, review the saved objects or rules, and adapt the fields, filters, and visualizations to your own data.
Use the related collections below to move between dashboards, security content, observability examples, pipelines, Elasticsearch resources, and AI-assisted Elastic workflows.
Use three Elastic Agent Builder agents and supporting ES|QL tools to analyze network health, packet evidence, Suricata findings, DNS/TLS risks, HTTP failures, and top conversations.
Analyze live network topology, packet inspection signals, application flows, DNS/TLS posture, and Suricata findings with reusable Kibana dashboards and Vega visualizations.
Monitor Elastic Defend endpoint posture, malware prevention, open alerts, policy issues, and top affected hosts with a reusable Kibana dashboard for security operations teams.
Explore ServiceNow CMDB and ITSM data faster with two Kibana dashboards for asset topology, incident priority, change activity, and people-focused operations review.
Turn Kubernetes health signals into error-budget decisions. Use these OTel SLO templates when alerts show something broke, but you need to know which workload is burning reliability budget and how urgent the response should be.
Start an incident from evidence instead of a blank chat. This RCA workflow uses Agent Builder to investigate observability alerts, create a case, and attach the reasoning trail so engineers can review the likely cause faster.
Search Labs companion app and ES|QL queries for OpenTelemetry-based search analytics, click quality, conversions, personalization, and SLO reliability analysis.
Official Elastic threat hunting queries with TOML metadata and Markdown docs for proactive investigations across endpoint, cloud, network, Okta, and LLM telemetry.
A hands-on Kubernetes observability demo with Beats manifests and a sample guestbook app for sending infrastructure and application signals into Elastic.
Elastic Security rules that use ES|QL COMPLETION to triage curl and wget activity after deterministic filtering and aggregation.
Search is the foundation of all kinds of experiences—from finding documents to monitoring infrastructure to preventing security threats. Elastic is a search company that supports three solutions built on a powerful stack: Elastic Stack. Deploy them anywhere (from cloud to bare metal) to instantly find actionable insights from any type of data.
Elastic Security equips security teams to stop threats quickly and at cloud scale, with the best-in-class platform for prevention, detection, and response.
Its the first free and open XDR solution and its one of the leading SIEM technologies that you can find. One of the great things about Elastic Security is the combination of free Elastic Endpoint Security and the free Elastic SIEM in one single solution. That makes it really handy to start with your Security project and improve it over time to perfectly fit into your needs.
Bring your logs, metrics, and APM traces together at scale in a single stack so you can monitor and react to events happening anywhere in your environment. And it’s free and open.
With Elastic Observability you get everything you need to monitor your full IT Landscape. It starts with the Infrastructure monitoring, including network monitoring but also fulfils the needs for complete Application level monitoring using the APM technology. Going with Elastic Observability provides the ability to extend your current monitoring landscape with every single bit that is missing. And at the same time you also have the ability to replace more expensive tools with this free solution.