Native automation with Elastic Workflows — No SOAR required
TL;DR · AI 摘要
Elastic宣布Workflows功能原生集成于Elasticsearch,无需独立SOAR平台即可实现安全自动化,但文章内容严重截断、缺乏技术细节与实操信息。
核心要点
- Elastic Workflows定位为SOAR替代方案,内置于Elasticsearch平台
- 强调‘native automation’和AI推理能力,但未说明具体实现机制
- 页面结构混乱,正文被大量导航栏、广告位和未加载内容截断
Elastic Workflows: Native automation for security — No SOAR required | Elastic Blog
New
Forrester Wave Leader, Q2 2025
About usPartnersSupport|ENLogin
[](http://www.elastic.co/)
- Elasticsearch
##### Elasticsearch for...
- ###### Context engineering Get the most relevant context to agents so that they deliver accurate and trusted outcomes
- ###### Vector database Efficiently create, store, and search vector embeddings
- ###### Search powered applications The speed, scale, and flexibility to power modern application experience
- ###### Logs Collect, search, explore, and act on large volumes
- ###### Threat protection Detect, investigate, and remediate cyber threats at scale on real-time data
- ###### Workflows Combine scripted automation with AI reasoning natively in Elasticsearch
##### Elasticsearch components
- ###### Elasticsearch A distributed, RESTful search and analytics engine
- ###### Kibana (Discover, Dashboards) Explore, visualize, and build dashboards using data stored in Elasticsearch
- ###### Elastic Agent Builder Build context-aware agents faster that incorporate all your data and deliver best-in-class relevance.
- ###### AutoOps Easy cluster management with performance recommendations, resource utilization, and cost insights
- ###### Piped query language Simplify workflows and accelerate query response for efficient data processing
- ###### Jina AI search models Jina AI is part of Elastic, bringing best-in-class models for embeddings, rerankers, and URL and doc extraction
##### Deployment options
- ###### Elastic Cloud Serverless Zero operational load so that you can build fasterStart free trial
- ###### Elastic Cloud Hosted Deploy and scale on any cloud in minutes with ultimate controlStart free trial
- ###### Self-managed Elasticsearch Run locally, via Kubernetes, or your own orchestrationDownload
- Solutions
##### Search
- ###### Ecommerce search Improve customers' search experience and drive conversion
- ###### Customer support search Help customers find support information quickly and easily
- ###### Search-driven apps Create engaging apps quickly and easily with Elasticsearch
##### Observability
- ###### Log analytics Centralize and analyze logs using Search AI to detect, investigate, and remediate incidents
- ###### Infrastructure monitoring Monitor, visualize, and analyze the health of your on-premises and cloud infrastructure
- ###### Digital experience monitoring Improve users' experience with real user monitoring (RUM), synthetic testing, and uptime monitoring
- ###### App performance monitoring Monitor, visualize, and analyze the performance and availability of your applications
- ###### AIOps Automatically detect, diagnose, and resolve issues faster with GenAl and ML
- ###### LLM observability Monitor and optimize LLM performance, cost, safety, and reliability
##### Security
- ###### Next-gen SIEM Detect, investigate, and respond to evolving threats with Al-driven security analytics
- ###### Workflows for security Automate alert triage, enrichment, and response natively. No separate SOAR required.
- ###### XDR and endpoint security Secure your endpoints, clouds, and containers with AI-driven insights
- ###### AI for security Automate your triage, investigation, and response workflows with Search AI
- Enterprise
##### Why Elastic?
##### Industry
Financial servicesManufacturingPublic sectorRetailTelecommunicationsView all industries
##### Better together
- ###### Cloud providers Deploy with your favorite cloud marketplace: AWS, Azure, or Google Cloud
- ###### Elastic AI Ecosystem Use Elastic with built-in integrations with leading Al technology providers
- ###### Search AI Partner Program Partner with Elastic so we can find the answers, together
##### Accolades
- ###### AV-Comparatives Elastic earns Endpoint Prevention and Response Certification from AV-Comparatives
- ###### Forrester Wave™ Leader A Leader in The Forrester Wave™: Security Analytics Platforms, Q2 2025
- ###### Gartner Magic Quadrant Leader A Leader in 2025 Gartner® Magic Quadrant™ for Observability Platforms
- ###### IDC MarketScape Leader Leader in IDC MarketScape: Worldwide SIEM for Enterprise 2024
##### Customers
[Search Docusign powers millions of e-signature searches daily with Elasticsearch](http://www.elastic.co/customers/docusign)
[Security UOL slashes incident resolution time by 80% with Elastic Security](http://www.elastic.co/customers/uol)
[Observability Pepsi boosts efficiency and reduces MTTR by 30% with Elastic Observability](http://www.elastic.co/customers/pepsico)
- Resources
##### Launch
- ###### Get started Follow along with beginner guides for each solution
- ###### Demo gallery Play in our hands-on sandbox and watch how-to videos
- ###### Downloads Download Elasticsearch now to get started for free
- ###### Integrations Easily connect Elasticsearch to all the systems that matter
##### Learn
- ###### Docs Learn how to use all of Elastic's products and features
- ###### Elasticsearch Labs Learn how to build with the latest features and abilities
- ###### Elastic Security Labs Understand the threat horizon and see the latest research
- ###### Elastic Observability Labs Explore what's next in monitoring and metric trends
- ###### Blog Read all of the latest company news from Elastic's blog
##### Connect
- ###### Community Join our community of developers on Slack, GitHub, and more
- ###### Events Attend your local meetups, workshops, and Elastic{ON}
- ###### Webinars Check out Elastic webinars and learn directly from our experts
- ###### Discuss Share tips, ask questions, and learn from other developers
##### Get help
- ###### Training Learn Elastic for free and expand your skills with our courses
- ###### Support Get expert advice on your Elasticsearch deployments for fast resolution
- ###### Consulting Drive success with custom support and consulting services
Search
Table of Contents
Table of contents
- Close
Native automation with Elastic Workflows — No SOAR required
Elastic Workflows brings automation directly into Elastic Security. Execute defined tasks from playbooks while AI agents reason through complex investigations to shut down threats faster.
By
March 23, 2026
.png)
- )Share on Twitter
- )Share on LinkedIn
- )Share on Facebook
- )Share by Email
- )Print
Elastic Workflows, now generally available in 9.4, brings native automation to Elastic Security, the agentic security operations platform that already includes unified SIEM and XDR. Stop paying the automation tax. There is no separate SOAR tool to buy, integrate, or maintain.
Built natively inside Elastic Security, Workflows has direct access to your alerts, cases, and investigation data. Eliminate manual triage by executing defined tasks from playbooks while AI agents reason through complex investigations to shut down threats faster.
The challenge: The SOC automation tax and forced trade-offs
Security teams can't keep pace with growing alert volumes and AI-driven threats. Automation is essential. But the legacy approach of buying a standalone SOAR to bolt onto your SIEM has created its own category of problems. The result is an automation tax on the SOC.
SOAR sits apart from your security data. This forces teams to build and maintain brittle integrations just to act on what the SIEM already knows. That means there are more vendors, more costs, and more complexity along with analysts burning hours on integration overhead instead of investigating threats. According to theState of the SOC report, the average SOC operates across 11 security consoles, and 91% of security leaders trace a serious incident directly back to the friction between their disconnected tools.
And teams face a trade-off between reliability and reasoning. Traditional playbooks handle defined tasks with consistency but can't adapt when an investigation doesn't match a known pattern. AI tools offer reasoning but often lack the reliability that security operations require.
Elastic Workflows: End the SOAR automation tax
Instead of maintaining a separate automation platform, Workflows runs natively in Elastic Security — no complex integration to build and no data to move between platforms. Close proximity to your data gives automation richer context and faster execution.
Defined in YAML, Workflows are executed by a built-in engine designed for reliability at scale. They are fully composable and event-driven, responding to alerts, schedules, external system events, and analyst-initiated actions.

Once running, Workflows connects seamlessly to external systems that your SOC depends on, such as cloud providers, identity platforms, service desks, and messaging tools, allowing a single automation to synchronize context across your security stack.

Workflows and agents for intelligent automation
Elastic Workflows combines scripted automation with AI reasoning. Execute defined tasks from playbooks with consistency and reliability, while AI agents reason through complex investigations.

Workflows gets its agentic capabilities through integration with[](https://www.elastic.co/search-labs/blog/elastic-ai-agent-builder-context-engineering-introduction)Elastic Agent Builder, a native capability of Elasticsearch for creating custom AI agents. The integration works in both directions. Workflows can call agents as intelligent steps for analysis and decision-making. Agents can invoke Workflows as tools to take concrete actions, such as isolating a host, querying threat intel, escalating an incident, or updating a case. Each action and reasoning step is transparent and configurable.

Because Elastic Security is built on the Elasticsearch Platform, agents reason with superior context from your security data, delivering more accurate results tailored to your environment. AI Skills will extend this by giving agents modular, domain-specific reasoning like alert triage or malware analysis that loads dynamically on demand, keeping agents fast and accurate at scale.
Here's what that looks like in practice. Imagine an alert fires for a suspicious login from an unrecognized location on a high-privilege account. Normally, this is where your manual work begins. But with Workflows, the moment that alert triggers, the system immediately begins verifying the user's typical behavior, checking for other recent sign-in anomalies, and bundling the findings into a new case while alerting the team on Slack.
If there isn't a defined playbook for automatically triaging this specific scenario, the workflow can call an AI agent to step in. The agent analyzes the activity, compares it against known attack patterns, and provides a summary of what actually happened. By the time an analyst opens the case, they aren't starting with a vague alert and a blank screen; they are starting with context already assembled.


Using Workflows enabled our SOC to spend so much more time on the things that matter. On a daily basis, we ran through 500 alerts, spending 3 hours creating cases and enriching them manually. Using Workflows, this is all done automatically, saving up to 2.5 hours a day.
###### SOC leader, European government agency
For teams with an existing SOAR
If your team already has a SOAR platform, Workflows doesn't require you to replace it. Automation that touches your Elastic data, such as alert triage, enrichment, case management, and response actions, moves natively into Workflows. Cross-platform orchestration across non-Elastic systems stays in your existing SOAR. Over time, you can consolidate at your own pace.
Get started with Elastic Workflows
Elastic Workflows is generally available in 9.4 in Elastic Security, the agentic security operations platform. Get started with an Elastic Cloud trial, and check out the documentation.
It's available with an Enterprise license on Elastic Cloud Hosted and self-managed deployments and with the Complete tier on Elastic Cloud Serverless for Security. Pricing is execution-based with a monthly baseline allocation included.See full pricing details.
For a hands-on walkthrough of building security playbooks with Workflows, watch the demo on YouTube or read the Security Labs technical blog.
If your team has been looking for a way to automate SOC operations without adding another tool to your stack, this is a good place to start.
_The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all._
_In this blog post, we may have used or referred to third party generative AI tools, which are owned and operated by their respective owners. Elastic does not have any control over the third party tools and we have no responsibility or liability for their content, operation or use, nor for any loss or damage that may arise from your use of such tools. Please exercise caution when using AI tools with personal, sensitive or confidential information. Any data you submit may be used for AI training or other purposes. There is no guarantee that information you provide will be kept secure or confidential. You should familiarize yourself with the privacy practices and terms of use of any generative AI tools prior to use._
_Elastic, Elasticsearch, and associated marks are trademarks, logos or registered trademarks of Elasticsearch B.V. in the United States and other countries. All other company and product names are trademarks, logos or registered trademarks of their respective owners._
Share
- )Share on Twitter
- )Share on LinkedIn
- )Share on Facebook
- )Share by Email
- )Print
Sign up for Elastic Cloud free trial
Spin up a fully loaded deployment on the cloud provider you choose. As the company behind Elasticsearch, we bring our features and support to your Elastic clusters in the cloud.
Follow us
- 
- 
- 
- 
- 
- About us About ElasticLeadershipBlogNewsroom
- Join us CareersCareer portalHow we hire
- Partners Find a partnerPartner loginRequest accessBecome a partner
- Trust & Security LegalTrust centerPrivacyTrade ComplianceEthics & Compliance
- Investor relations Investor resourcesGovernanceFinancialsStock
- Excellence Awards Previous winnersElastic{ON} TourBecome a sponsorAll events
About us
Join us
Partners
Trust & Security
Investor relations
Excellence Awards
© 2026. elasticsearch B.V. All Rights Reserved
This website and all associated content, software, discussion forums, products, and services are intended for professional use only. No consumer use of this website or its content is intended or directed.
Elastic, Elasticsearch, and other related marks are trademarks, logos, or registered trademarks of elasticsearch B.V. in the United States and other countries.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries. All other brand names, product names, or trademarks belong to their respective owners.
