Skip to main content
Connect your Elastic Security deployment so Myrmex can run Kibana queries and API commands for threat auditing, detection-rule operations, and incident documentation. Myrmex reaches Kibana over HTTPS through a Collector on your network. Every query and command runs live, on demand — Myrmex returns only what you ask for and copies or stores nothing from Elastic on its side. Credentials are resolved on your side and never pass through the model.

What Myrmex Can Do

Run Kibana queries

Execute advanced Kibana and Elasticsearch queries to investigate activity — read-only for analysis.

Detection rule operations

Review and, with write access, manage detection rules.

Threat auditing

Audit signals and coverage to find gaps worth closing.

Document incidents

Capture findings and keep cases and alerts documented.

Before You Start

  • A Collector that can reach the Kibana host over HTTPS (commonly port 443 or your Kibana port such as 5601). See Collector mode.
  • A Kibana user with read access for analysis, or read and write to manage detection rules and cases.
  • The Kibana Space id, if your rules and cases live outside the default space.

Step 1 — Create the Credential in Elastic Security

1

Create a role

In Kibana, go to Stack Management → Security → Roles and create a role with the index and Kibana Security privileges Myrmex needs — read for analysis, or read and write to manage rules and cases.
2

Create the user

In Stack Management → Security → Users, add a user, set a strong password, and assign the role. The field help describes this as an “Elastic Security user with read and write permission.”
3

Note the Kibana space (optional)

If your detection rules and cases live in a non-default space, note its Space id; leave it blank for the default space.
Assign a read-only role first. Add write privileges only when you want the agents to manage rules and cases for you.

Step 2 — Add the Integration in Myrmex

From the Directory, choose Add Integration → Elastic Security, then fill in:

Connect

Click Connect to validate the API connection and finish. Elastic Security then appears under Environment → Integrations, and you can ask about it in the Workspace or through the Integration Specialist agent.
Use HTTPS with a valid certificate on Kibana. If Kibana runs behind a proxy, point the URL at the address the Collector can reach.