Aug 10, 2026
Enterprise

Elastic Alert Zero sets guarded automation rules for SOC triage

Elastic Security 9.5 combines AI triage, deeper alert investigation and workflows, while leaving customers to set approval and auto-close limits.

Wei-Lin Zhao

By Wei-Lin Zhao · AI Correspondent

· 3 min read

Elastic Alert Zero sets guarded automation rules for SOC triage
Photo: SiliconANGLE

Elastic Alert Zero is the company’s proposed operating model for security operations centers, using AI to classify and investigate alerts before analysts work them. Elastic detailed the approach for Elastic Security 9.5 on July 30, saying it combines alert triage, its Attack Discovery investigation tool and workflow automation to reduce queue noise, rather than promising a queue that stays empty.

The distinction matters for security teams assessing agentic-SOC products. Alert Zero is not a feature an administrator can enable once and leave unattended, according to Elastic. New alerts will continue to arrive, and some cases still need human investigation. The company has not disclosed pricing, supported model providers or adoption figures in the supplied materials.

What is Elastic Alert Zero and how does it work?

Elastic describes Alert Zero as a target state in which analysts spend less time on repetitive initial triage and more time on threat hunting, detection engineering and consequential investigations. The workflow begins with Security alert analysis, which can process alerts generated by rules a customer selects.

That analysis can label an alert a true positive, false positive or inconclusive. Elastic says it collects the alert’s details, related alerts, frequency and prior-resolution history, then records its classification, confidence and reasoning for review. Customers choose the agent and model, participating rules and confidence requirements.

Auto-closing is deliberately bounded. It is disabled by default, Elastic says, and applies only to likely false positives that meet a customer-set confidence threshold after the customer elects to activate it. That makes the product a configurable control system, not a claim that an AI model can safely dismiss every routine alert.

How Attack Discovery changes the workflow

Cases that remain open can be sent to Attack Discovery for further work. Elastic says the expanded tool examines underlying events, entity-risk scores and corroborating evidence to assemble attack narratives and identify relationships among signals. SiliconANGLE reported that Mike Nichols, Elastic’s general manager of security, framed the objective as narrowing the analyst queue to validated attacks.

When Attack Discovery identifies a possible detection-coverage gap, Elastic says it can draft a rule, but routes that rule to an analyst for approval. Elastic Workflows supplies the automation layer for steps a team chooses to automate. The company says its recent workflow updates include plain-language generation, version history with rollback, a visual graph view and approval routing to tools such as Slack.

What Elastic has and has not shown

The announcement places Elastic in an active market for AI-assisted SOC triage, where vendors are pitching automation as a way to handle alert volume. Torq describes alert fatigue as analyst exhaustion and desensitization caused by more security alerts than teams can investigate, often including low-priority or false-positive events. That is a vendor characterization, rather than independent evidence of Elastic’s results.

The supplied materials do not include customer deployment results, alert-reduction figures, missed-incident rates or response-time improvements for Alert Zero. For buyers, the practical evaluation is narrower: test false-positive closures against human review, inspect the system’s rationale and escalations, and measure whether the configured workflow returns analyst time without suppressing real incidents.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →