logo

From plain English to production rule: AI-native Elasticsearch ES|QL detection in Elastic Security

ID: 02661b31-5e0f-53a1-9c4b-f092ddd33ad4

STIX ID: report--02661b31-5e0f-53a1-9c4b-f092ddd33ad4

Feed Name: Elastic Security Labs

Date Published: 2026-05-04

Date Updated: 2026-08-27

Author: Kseniia Ignatovych

...
...

Elastic Security introduces an AI-powered rule creation feature that converts plain-English threat descriptions into validated ES|QL detection rules (including MITRE ATT&CK mappings, severity recommendations, and live previews). The post demonstrates the workflow with an Okta credential-stuffing and account-takeover example, showing how the AI agent constructs multistage aggregation queries, allows iterative refinements, and previews results against real data; it is a product feature walkthrough and guidance for detection engineers, not an incident report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.