---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Elasticsearch Incident Enrichment integration

# Elasticsearch Incident Enrichment integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Elasticsearch -
Incident Enrichment integration searches your logs and adds relevant sighting information to
your security incidents.

|-|-|
| Explore [Security Incident Response integrations](https://servicenow-prod.fluidtopics.net/RhaRoT0Fn_2fkoMqo0mGDA "Security Incident Response (SIR) integrates with third-party security tools to create security incidents.") | Set up * [Get started with the Elasticsearch - Incident Enrichment integration](https://servicenow-prod.fluidtopics.net/BTt8SnWGMFpeNIUZcMKnXA "Elasticsearch is a distributed, RESTful search and analytics engine that easily integrates with Security Operations. Before you can use the Elasticsearch - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate API Base URL and login credentials.") * [Create sightings search configuration records](https://servicenow-prod.fluidtopics.net/~C_EZsSWY13JtBYZ0oNFWA "Create multiple sightings search configuration records and use them while querying multiple log stores or varying the search parameters.") {#elasticsearch-landing-page__ul_kmj_mrn_lw} |
| Use * [Run a Sightings Search](https://servicenow-prod.fluidtopics.net/PhrwoCC1EliI1442kisZFw "Determine the prevalence of a threat over time or test remediation or eradication efforts. You can select individual or multiple observables and the date range for your search from a security incident. Results are included in the Security Incident Observables related list.") * [Security Operations Integration - Sightings Search Flow](https://servicenow-prod.fluidtopics.net/h_dAICTJQ0lbJ~eF~zxSLA "Security Operations Integration - Sightings Search flow is a high-level flow independent of integrations. It uses the configured queries to search for a set of observables based on the configured integrations which support the capability. Use it to fulfill an integration such as Splunk or Elasticsearch.") * [Security Operations - Elasticsearch Sightings Search Flow](https://servicenow-prod.fluidtopics.net/WlNDPef9Jnx5HTnbYw5bwA "Security Operations - Elasticsearch Sightings Search flow is the Elasticsearch implementation launched by the Security Operations Integration - Sightings Search flow.") {#elasticsearch-landing-page__ul_qkh_cpj_dx} | Develop * [ServiceNow Security Operations integration development guidelines](https://servicenow-prod.fluidtopics.net/bvG2Jf6vlu8fw3IEOvGdMg "The ServiceNow platform provides several mechanisms for developing integrations with external systems. The ServiceNow Security Operations product suite adds integration capabilities intended to streamline the process of integrating with security-focused external systems.") * [Tips for writing integrations](https://servicenow-prod.fluidtopics.net/WrftS4_aOuJx7CfDqNBj1g "Avoid some of the pitfalls you can encounter when writing your own integrations by following these guidelines.") * [Developer training](https://developer.servicenow.com/app.do#!/training/landing) * [Developer documentation](https://developer.servicenow.com/app.do#!/documentation) * [Find components installed with an application](https://www.servicenow.com/docs/access?context=find-components&version=australia&pubname=australia-platform-administration&ft:locale=en-US) {#elasticsearch-landing-page__ul_zsn_wnv_qx} |
| Troubleshoot and get help * [Integration troubleshooting](https://servicenow-prod.fluidtopics.net/_DwvxRbS3tQogK5A_dB8UQ "These troubleshooting suggestions can help you resolve common issues you can encounter when setting up or running integrations.") * [Ask or answer questions in the Security Operations community](https://community.servicenow.com/community/security-operations) * [Search the Known Error Portal for known error articles](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0597477) * [Contact Customer Service and Support](https://support.servicenow.com/now?draw=case) {#elasticsearch-landing-page__ul_zyk_3j4_qx} |   |
[ ]

{#elasticsearch-landing-page__simpletable_g33_wwg_vt}

