Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3
ID: 8291488c-1133-5179-ad0c-1bfcf5c8c1cf
STIX ID: report--8291488c-1133-5179-ad0c-1bfcf5c8c1cf
Feed Name: Elastic Security Labs
This post outlines Elastic InfoSec’s “Agentic SOC” architecture: deterministic ES|QL triage to close obvious false positives at zero token cost, a narrow Initial Triage agent to handle the next layer, domain-specific Specialized agents for focused forensics, and a Final Review agent that synthesizes findings into Kibana Cases — all orchestrated with Elastic Workflows, Agent Builder, and the Elastic Inference Service. The design emphasizes cost, speed, auditability, strict agent output formats, and routing inference to zero-data-retention providers, claiming end-to-end automated triage can reduce manual investigation time from ~30 minutes to under 3 minutes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
