What Myrmex Can Do
Run Kibana queries
Execute advanced Kibana and Elasticsearch queries to investigate activity — read-only for analysis.
Detection rule operations
Review and, with write access, manage detection rules.
Threat auditing
Audit signals and coverage to find gaps worth closing.
Document incidents
Capture findings and keep cases and alerts documented.
Before You Start
- A Collector that can reach the Kibana host over HTTPS (commonly port
443or your Kibana port such as5601). See Collector mode. - A Kibana user with read access for analysis, or read and write to manage detection rules and cases.
- The Kibana Space id, if your rules and cases live outside the default space.
Step 1 — Create the Credential in Elastic Security
1
Create a role
In Kibana, go to Stack Management → Security → Roles and create a role with the index and Kibana Security privileges Myrmex needs — read for analysis, or read and write to manage rules and cases.
2
Create the user
In Stack Management → Security → Users, add a user, set a strong password, and assign the role. The field help describes this as an “Elastic Security user with read and write permission.”
3
Note the Kibana space (optional)
If your detection rules and cases live in a non-default space, note its Space id; leave it blank for the default space.
Step 2 — Add the Integration in Myrmex
From the Directory, choose Add Integration → Elastic Security, then fill in:Connect
Click Connect to validate the API connection and finish. Elastic Security then appears under Environment → Integrations, and you can ask about it in the Workspace or through the Integration Specialist agent.Use HTTPS with a valid certificate on Kibana. If Kibana runs behind a proxy, point the URL at the address the Collector can reach.