Ingest third-party cloud security data
editIngest third-party cloud security data
editThis section describes how to ingest cloud security data from third-party tools into Elasticsearch. Once ingested, this data can provide additional context and enrich your Elastic Security workflows.
You can ingest both third-party cloud workload protection data and third-party security posture and vulnerability data.
Ingest third-party workload protection data
editYou can ingest third-party cloud security alerts into Elastic Security to view them on the Alerts page and incorporate them into your triage and threat hunting workflows.
- Learn to ingest alerts from Sysdig Falco.
Ingest third-party security posture and vulnerability data
editYou can ingest third-party data into Elastic Security to review and investigate it alongside data collected by Elastic Security’s native cloud security integrations. Once ingested, cloud security posture and vulnerability data appears on the Findings page, on the Cloud Posture dashboard, and in the entity details flyouts for alerts, users, and hosts.