<h2>Configure and enable Elasticsearch integration</h2><br/><div style="overflow-x:auto"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><head><meta content="text/html; charset=UTF-8" /><meta name="copyright" content="(C) Copyright 2025" /><meta name="DC.rights.owner" content="(C) Copyright 2025" /><meta name="generator" content="DITA-OT" /><meta name="DC.type" content="task" /><meta name="DC.title" content="Configure and enable Elasticsearch integration" /><meta name="abstract" content="Elasticsearch is a distributed, RESTful search and analytics engine that easily integrates with Security Operations." /><meta name="description" content="Elasticsearch is a distributed, RESTful search and analytics engine that easily integrates with Security Operations." /><meta name="DC.relation" scheme="URI" content="../../../product/secops-integration-threat-security-center/concept/get-started-with-elasticsearch-integration.html" /><meta name="DC.relation" scheme="URI" content="../../../product/secops-integration-threat-security-center/concept/integrating-threat-intelligence-security-center.html" /><meta name="DC.relation" scheme="URI" content="../../../product/secops-integration-threat-security-center/concept/tisc-integrations.html" /><meta name="DC.relation" scheme="URI" content="../../../product/secops-integration-threat-security-center/concept/tisc-sighting-search.html" /><meta name="DC.creator" content="ServiceNow" /><meta name="DC.date.created" content="2023-12-19T18:15:39+05:30" /><meta name="DC.date.modified" content="2024-02-01" /><meta name="DC.format" content="XHTML" /><meta name="DC.identifier" content="tisc-elasticsearch-integration" /><link rel="stylesheet" type="text/css" href="../../../CSS/commonltr.css" /><title>Configure and enable Elasticsearch integration</title></head><body id="tisc-elasticsearch-integration"> <div class="breadcrumb"><a class="link" href="https://docs.servicenow.com/bundle/washingtondc-security-management/page/product/secops-integration-threat-security-center/concept/integrating-threat-intelligence-security-center.html" title="Use this section to understand the Threat Intelligence Security Center integrations.">Integrating Threat Intelligence Security Center</a> > <a class="link" href="https://docs.servicenow.com/bundle/washingtondc-security-management/page/product/secops-integration-threat-security-center/concept/tisc-integrations.html" title="This section provides instructions for configuring and enabling the Threat Intelligence integrations.">TISC Integrations</a> > <a class="link" href="https://docs.servicenow.com/bundle/washingtondc-security-management/page/product/secops-integration-threat-security-center/concept/tisc-sighting-search.html" title="This section describes the TISC Sighting Search and Elastic Search integrations.">Sighting Search</a> > </div> <h1 class="title topictitle1" id="ariaid-title1">Configure and enable Elasticsearch integration</h1> <div class="body taskbody"><p class="shortdesc">Elasticsearch is a distributed, RESTful search and analytics engine that easily integrates with Security Operations.</p> <div class="section prereq p" id="tisc-elasticsearch-integration__prereq_ejb_ctp_tzb"> <p class="p">Before you can use the Elasticsearch, you must download it from the ServiceNow Store.</p> <p class="p">Role required: sn_sec_tisc.admin</p> <ul class="ul" id="tisc-elasticsearch-integration__ul_nh2_cc4_tzb"><li class="li">The Threat Intelligence Security Center plugin must be installed and activated before you can use the Elasticsearch integration.</li><li class="li">Obtain the Elasticsearch API Base URL, Kibana Base URL, Username, and Password under your Elasticsearch profile.</li></ul> </div> <ol class="ol steps" id="tisc-elasticsearch-integration__steps_fjb_ctp_tzb"><li class="li step stepexpand"> <span class="ph cmd">Using your instance, access <span class="ph uicontrol">Threat Intelligence Security Center</span>.</span> </li><li class="li step stepexpand"> <span class="ph cmd"><a class="xref" href="https://docs.servicenow.com/bundle/washingtondc-security-management/page/product/security-incident-response/reference/download-app-first-time.html" title="Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.">Download the integration from the <span class="ph">ServiceNow Store</span></a>.</span> </li><li class="li step stepexpand"> <span class="ph cmd">When the installation is complete, navigate to <span class="ph menucascade"><span class="ph uicontrol">Workspaces</span> > <span class="ph uicontrol">Threat Intelligence Security Center</span></span>.</span> </li><li class="li step stepexpand"> <span class="ph cmd">Select <span class="ph menucascade"><span class="ph uicontrol">Integrations</span> > <span class="ph uicontrol">Enrichment Integrations</span> > <span class="ph uicontrol">All Integrations</span></span>.</span> </li><li class="li step stepexpand"> <span class="ph cmd">Alternatively, you can navigate to <span class="ph menucascade"><span class="ph uicontrol">Integrations</span> > <span class="ph uicontrol">Enrichment Integrations</span> > <span class="ph uicontrol">All Integrations</span> > <span class="ph uicontrol">Sighting Search</span></span></span> <div class="itemgroup info"> <div class="note"><span class="notetitle">Note:</span> The configured integrations appear as a series of cards.</div> </div> </li><li class="li step stepexpand"> <span class="ph cmd">In the <span class="ph uicontrol">Elasticsearch</span> card, click <span class="ph uicontrol">Configure New Enrichment</span> to configure <span class="ph uicontrol">Elasticsearch</span> integration.</span> </li><li class="li step stepexpand"> <span class="ph cmd">Fill in the fields on the Configure New Enrichment form.</span> <div class="itemgroup info"> <div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="tisc-elasticsearch-integration__table_iqf_n4p_tzb" class="table" frame="border" border="1" rules="all"><caption><span class="tablecap"><span class="table--title-label">Table 1. </span>Enrichment Integration</span></caption><colgroup><col style="width:50%" /><col style="width:50%" /></colgroup><thead class="thead" style="text-align:left;"><tr class="row"><th class="entry cellrowborder" style="vertical-align:top;" id="d502109e182">Field</th><th class="entry cellrowborder" style="vertical-align:top;" id="d502109e185">Description</th></tr></thead><tbody class="tbody"><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">Name</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">Enter a name for the sighting search configuration.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">Vendor Name</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">Name of the vendor. The details of the selected vendor is populated by default. For example, Elasticsearch.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">Integration Type</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">Type of integration that you selected. For example, Threat Lookup.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">Description</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">Enter the description for the Elasticsearch integration. For example, The Elasticsearch enrichment integration aids in the investigation of an observable by supporting the querying of logs in your Elasticsearch deployment.</td></tr><tr class="row"><td class="entry cellrowborder" colspan="2" style="vertical-align:top;" headers="d502109e182 d502109e185 "><span class="ph uicontrol">Integration Configuration</span></td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">Elasticsearch API Base URL</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">The base URL you acquired from the Elasticsearch site.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">Kibana Base URL</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">The Kibana Base URL. [Optional] Links to a Kibana instance, when available.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">Username</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">Your Intel Elasticsearch username.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">Password</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">Your Intel Elasticsearch password.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">Elasticsearch Index</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">The Elasticsearch index. These in turn will hold documents that are unique to each index. Indices are identified by lowercase names that refer to actions that are performed actions (such as searching and deleting).</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">Date range field</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">The timestamp of the configuration.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">Max Rows</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">The maximum number of rows you want to search.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">Earliest Result (days)</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">The earliest results you want to see in number of days.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">Include raw data samples in search results</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">Select this to include samples of raw data in your sightings search results. The amount of data returned depends on your setting in the number of rows of raw data property in <a class="xref" href="https://servicenow.com/docs/bundle/vancouver-security-management/page/product/security-incident-response/reference/installed-with-sir.html" target="_blank" rel="noopener noreferrer">Security Incident Response properties</a>.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e182 ">MID Server</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d502109e185 ">Select Any to use any active MID Server, or select a specific MID Server name.</td></tr></tbody></table> </div> <div class="note"><span class="notetitle">Note:</span> Configuring this integration activates workflows. To manage the workflows, navigate to the Workflow Editor.</div> </div> </li><li class="li step stepexpand"> <span class="ph cmd">Click <span class="ph uicontrol">Save</span>.</span> <div class="itemgroup stepresult">The integration details are validated, and by default the Elasticsearch integration's status is disabled.</div> </li><li class="li step stepexpand"> <span class="ph cmd">Click <span class="ph uicontrol">Enable</span> to enable the Elasticsearch integration.</span> </li></ol> <div class="section result" id="tisc-elasticsearch-integration__result_oyx_5v4_tzb"> <p class="p">After it is configured, Elasticsearch can be selected for performing sighting search on observables in Threat Intelligence Security Center.</p> </div> </div> <div class="related-links"> <div class="familylinks"> <div class="parentlink"><strong>Parent Topic:</strong> <a class="link" href="https://docs.servicenow.com/bundle/washingtondc-security-management/page/product/secops-integration-threat-security-center/concept/get-started-with-elasticsearch-integration.html" title="The Elasticsearch enrichment integration searches your logs and adds relevant sighting information to your observables.">Get started with Elasticsearch integration</a></div> </div> </div></body></html></div>