Elastic Blog

Native automation with Elastic Workflows — No SOAR required

6.2内容质量
Native automation with Elastic Workflows — No SOAR required

TL;DR · AI 摘要

Elastic宣布Workflows功能原生集成于Elasticsearch,无需独立SOAR平台即可实现安全自动化,但文章内容严重截断、缺乏技术细节与实操信息。

核心要点

  • Elastic Workflows定位为SOAR替代方案,内置于Elasticsearch平台
  • 强调‘native automation’和AI推理能力,但未说明具体实现机制
  • 页面结构混乱,正文被大量导航栏、广告位和未加载内容截断
#Elastic#SOAR#Security Automation#Elasticsearch
打开原文

Elastic Workflows: Native automation for security — No SOAR required | Elastic Blog

Skip to main content

New

Forrester Wave Leader, Q2 2025

Access report

About usPartnersSupport|ENLogin

[](http://www.elastic.co/)

  • Elasticsearch

##### Elasticsearch for...

##### Elasticsearch components

##### Deployment options

  • Solutions

##### Search

Overview

##### Observability

Overview

##### Security

Overview

  • Enterprise

##### Why Elastic?

Knowledge Hub

##### Industry

Financial servicesManufacturingPublic sectorRetailTelecommunicationsView all industries

##### Better together

##### Accolades

##### Customers

View all customers stories

Image 8: logo for Docusign
Image 8: logo for Docusign

[Search Docusign powers millions of e-signature searches daily with Elasticsearch](http://www.elastic.co/customers/docusign)

Image 9: logo for UOL
Image 9: logo for UOL

[Security UOL slashes incident resolution time by 80% with Elastic Security](http://www.elastic.co/customers/uol)

Image 10: logo for PepsiCo
Image 10: logo for PepsiCo

[Observability Pepsi boosts efficiency and reduces MTTR by 30% with Elastic Observability](http://www.elastic.co/customers/pepsico)

  • Resources

##### Launch

##### Learn

##### Connect

##### Get help

PricingDocs

Search

Start free trialContact sales

Blog

Company

* Solutions

* Stack + Cloud

* News

* Customers

* Generative AI

* Culture

Elasticsearch Labs

* Blogs

* Tutorials

* Examples

* Integrations

Security Labs

* Blogs

* Reports

* Tools

Observability Labs

* Blogs

Image 11: Blog feed
Image 11: Blog feed

Table of Contents

Table of contentsImage 12: icon-toc-16-blue.svg

  • Close

Native automation with Elastic Workflows — No SOAR required

Elastic Workflows brings automation directly into Elastic Security. Execute defined tasks from playbooks while AI agents reason through complex investigations to shut down threats faster.

By

Sumana Mannem

March 23, 2026

Image 13: image1_(2).png.png)

Elastic Workflows, now generally available in 9.4, brings native automation to Elastic Security, the agentic security operations platform that already includes unified SIEM and XDR. Stop paying the automation tax. There is no separate SOAR tool to buy, integrate, or maintain.

Built natively inside Elastic Security, Workflows has direct access to your alerts, cases, and investigation data. Eliminate manual triage by executing defined tasks from playbooks while AI agents reason through complex investigations to shut down threats faster.

The challenge: The SOC automation tax and forced trade-offs

Security teams can't keep pace with growing alert volumes and AI-driven threats. Automation is essential. But the legacy approach of buying a standalone SOAR to bolt onto your SIEM has created its own category of problems. The result is an automation tax on the SOC.

SOAR sits apart from your security data. This forces teams to build and maintain brittle integrations just to act on what the SIEM already knows. That means there are more vendors, more costs, and more complexity along with analysts burning hours on integration overhead instead of investigating threats. According to theState of the SOC report, the average SOC operates across 11 security consoles, and 91% of security leaders trace a serious incident directly back to the friction between their disconnected tools.

And teams face a trade-off between reliability and reasoning. Traditional playbooks handle defined tasks with consistency but can't adapt when an investigation doesn't match a known pattern. AI tools offer reasoning but often lack the reliability that security operations require.

Elastic Workflows: End the SOAR automation tax

Instead of maintaining a separate automation platform, Workflows runs natively in Elastic Security — no complex integration to build and no data to move between platforms. Close proximity to your data gives automation richer context and faster execution.

Defined in YAML, Workflows are executed by a built-in engine designed for reliability at scale. They are fully composable and event-driven, responding to alerts, schedules, external system events, and analyst-initiated actions.

Image 24: traditional triage
Image 24: traditional triage

Once running, Workflows connects seamlessly to external systems that your SOC depends on, such as cloud providers, identity platforms, service desks, and messaging tools, allowing a single automation to synchronize context across your security stack.

Image 25: overlapping images - SS
Image 25: overlapping images - SS

Workflows and agents for intelligent automation

Elastic Workflows combines scripted automation with AI reasoning. Execute defined tasks from playbooks with consistency and reliability, while AI agents reason through complex investigations.

Image 26
Image 26

Workflows gets its agentic capabilities through integration with[](https://www.elastic.co/search-labs/blog/elastic-ai-agent-builder-context-engineering-introduction)Elastic Agent Builder, a native capability of Elasticsearch for creating custom AI agents. The integration works in both directions. Workflows can call agents as intelligent steps for analysis and decision-making. Agents can invoke Workflows as tools to take concrete actions, such as isolating a host, querying threat intel, escalating an incident, or updating a case. Each action and reasoning step is transparent and configurable.

Image 27: threat hunting agent
Image 27: threat hunting agent

Because Elastic Security is built on the Elasticsearch Platform, agents reason with superior context from your security data, delivering more accurate results tailored to your environment. AI Skills will extend this by giving agents modular, domain-specific reasoning like alert triage or malware analysis that loads dynamically on demand, keeping agents fast and accurate at scale.

Here's what that looks like in practice. Imagine an alert fires for a suspicious login from an unrecognized location on a high-privilege account. Normally, this is where your manual work begins. But with Workflows, the moment that alert triggers, the system immediately begins verifying the user's typical behavior, checking for other recent sign-in anomalies, and bundling the findings into a new case while alerting the team on Slack.

If there isn't a defined playbook for automatically triaging this specific scenario, the workflow can call an AI agent to step in. The agent analyzes the activity, compares it against known attack patterns, and provides a summary of what actually happened. By the time an analyst opens the case, they aren't starting with a vague alert and a blank screen; they are starting with context already assembled.

Image 28: overlapping images
Image 28: overlapping images
Image 29: workflows
Image 29: workflows

Using Workflows enabled our SOC to spend so much more time on the things that matter. On a daily basis, we ran through 500 alerts, spending 3 hours creating cases and enriching them manually. Using Workflows, this is all done automatically, saving up to 2.5 hours a day.

###### SOC leader, European government agency

For teams with an existing SOAR

If your team already has a SOAR platform, Workflows doesn't require you to replace it. Automation that touches your Elastic data, such as alert triage, enrichment, case management, and response actions, moves natively into Workflows. Cross-platform orchestration across non-Elastic systems stays in your existing SOAR. Over time, you can consolidate at your own pace.

Get started with Elastic Workflows

Elastic Workflows is generally available in 9.4 in Elastic Security, the agentic security operations platform. Get started with an Elastic Cloud trial, and check out the documentation.

It's available with an Enterprise license on Elastic Cloud Hosted and self-managed deployments and with the Complete tier on Elastic Cloud Serverless for Security. Pricing is execution-based with a monthly baseline allocation included.See full pricing details.

For a hands-on walkthrough of building security playbooks with Workflows, watch the demo on YouTube or read the Security Labs technical blog.

If your team has been looking for a way to automate SOC operations without adding another tool to your stack, this is a good place to start.

_The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all._

_In this blog post, we may have used or referred to third party generative AI tools, which are owned and operated by their respective owners. Elastic does not have any control over the third party tools and we have no responsibility or liability for their content, operation or use, nor for any loss or damage that may arise from your use of such tools. Please exercise caution when using AI tools with personal, sensitive or confidential information. Any data you submit may be used for AI training or other purposes. There is no guarantee that information you provide will be kept secure or confidential. You should familiarize yourself with the privacy practices and terms of use of any generative AI tools prior to use._

_Elastic, Elasticsearch, and associated marks are trademarks, logos or registered trademarks of Elasticsearch B.V. in the United States and other countries. All other company and product names are trademarks, logos or registered trademarks of their respective owners._

Share

Sign up for Elastic Cloud free trial

Spin up a fully loaded deployment on the cloud provider you choose. As the company behind Elasticsearch, we bring our features and support to your Elastic clusters in the cloud.

Start free trial

Image 40: Elastic The Search AI Company
Image 40: Elastic The Search AI Company

Follow us

About us

Join us

Partners

Trust & Security

Investor relations

Excellence Awards

© 2026. elasticsearch B.V. All Rights Reserved

This website and all associated content, software, discussion forums, products, and services are intended for professional use only. No consumer use of this website or its content is intended or directed.

Elastic, Elasticsearch, and other related marks are trademarks, logos, or registered trademarks of elasticsearch B.V. in the United States and other countries.

Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries. All other brand names, product names, or trademarks belong to their respective owners.

Image 47Image 48Image 49

Image 50
Image 50