logo

STIXy Situations: ECSaping your threat data

ID: 4053581b-bad7-532b-b783-41f259430045

STIX ID: report--4053581b-bad7-532b-b783-41f259430045

Feed Name: Elastic Security Labs

Date Published: 2024-02-09

Date Updated: 2026-04-27

...
...

This document presents Elastic’s stix2ecs tool for converting STIX 2.x threat intelligence into Elastic Common Schema (ECS), with options to output as NDJSON or ingest directly into Elasticsearch for analysis in Kibana and use with Indicator Match rules. It explains prerequisites, setup, CLI arguments, and practical examples, helping teams normalize and operationalize threat indicators in a machine-readable, standardized format.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.