Elasticsearch
Create an API Key and Obtain a Cloud ID








Enable Elasticsearch
Dropzone Field
Source






Last updated
Was this helpful?
Elasticsearch is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.
The Dropzone platform integrates with the Elasticsearch security SIEM. Many customers ingest other alert sources into Elasticsearch (e.g. IDPs) and integrate Dropzone into Elasticsearch rather than the source systems.
Elasticsearch requires an API Key and an Elasticsearch Cloud ID to enable.
If you are using the Elasticsearch Serverless Projects-Based Model or an On-premise Elasticsearch using the Dropzone connector, you will not need to provide a Cloud ID.
To obtain an API Key, do the following:
Navigate to your Elastic Cloud home page or deployment
Under the Hosted Deployments section, locate the deployment you wish Dropzone.AI to be able to access
Click "Open"

In the Deployment overview page, click "Management" in the bottom left corner
Click the icon next to Stack Management
Navigate to API keys

Click "Create an API key"

Name the API key something memorable, such as Dropzone.AI
Under type, select User API key
Click "Create API Key"

Copy the API key generated for use later in the Dropzone UI, where it is called "API Key"

To obtain your Elasticsearch Cloud ID, do the following:
Navigate to your Elastic Cloud home page
Under the Hosted Deployments section, locate the deployment you wish Dropzone.AI to be able to access
Click "Open"

In the upper right of the Overview page, click "Endpoint & API Keys"

Check "Show Cloud ID"
Copy the value shown for use later in the Dropzone UI, where it is called "Elasticsearch Cloud ID"

To enable the Data Source integration, you will need the following information:
Elasticsearch Cloud ID
The cloud ID value copied earlier. Only necessary if you have an Elastic Cloud Hosted deployment
Elasticsearch Server
The server for your Elasticsearch project, e.g. https://my-project.es.us-west-2.aws.elastic.cloud
API Token
The API token value generated earlier
To enable the Data Source integration, do the following:
Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
In the bottom left hand corner, navigate to Settings > Integrations

Click "Available"

In the Search bar, search Elasticsearch, then click "Configure"

Under the Data Source heading, if your Elasticsearch integration is behind an On-premise Dropzone Connector, select your connector from the dropdown
If you have a Cloud deployment, check the box labeled "Connect with Elastic Cloud ID," then input the Elasticsearch Cloud ID and API Key

Otherwise, input the Elasticsearch Server, Port, and API Key

If you want Dropzone to only use remote clusters when making queries, check the box labeled "Search Remote Indices"
Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.
Last updated
Was this helpful?
Was this helpful?