#elasticcloudserverless
One SOC can triage alerts across 100 linked projects with Elastic Cloud Serverless CPS, keeping tenant data isolated while running about 2,100 detection rules from a single origin. #ElasticSecurity #CrossProjectSearch #ESQL
Centralized Alert Triage: One SOC, 100 Linked Projects
Elastic Cloud Serverless Cross-project search (CPS) lets one Elastic Security origin project run detection, triage, investigation, and response workflows across linked projects while keeping each tenant’s data isolated. In testing, a single origin handled about 2,100 prebuilt detection rules across 100 linked projects, with ES|QL guidance, operational limits, and clear boundaries on what CPS can and cannot do. #ElasticCloudServerless #ElasticSecurity #CrossProjectSearch #ES|QL
www.hendryadrian.com
September 20, 2026 at 12:15 AM
Elastic tested ES|QL COMPLETION in curl and wget rules to filter benign cloud activity before alerts. In 7 days, only 3 wget destinations survived filtering, all were triaged by the LLM, and none reached analysts. #ESQL_COMPLETION #curl #wget
How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts
Elastic tested ES|QL COMPLETION on noisy curl and wget detection rules in cloud environments to filter benign activity before alerts reached analysts. In a seven-day wget evaluation, only three destinations survived deterministic filtering, all were triaged by the LLM, and none produced analyst-opened alerts, helping preserve trust in detections for cases like ingress tool transfer. #ESQL_COMPLETION #curl #wget #ElasticCloudServerless #Auditbeat
www.hendryadrian.com
July 25, 2026 at 1:15 AM