









Elastic automatically translates your Microsoft Sentinel detection rules into Elastic Security. Export your Scheduled and Near Real Time (NRT) analytics rules from Sentinel, upload them, and Elastic picks up the mapping and translation from there using an LLM you choose. Watchlists and severity mappings carry over. This is the first automatic migration path off a modern SIEM, available now in Tech Preview in 9.5, and it works across multiple cloud providers and regions so you can deploy closer to where your data lives.
Automatic Migration focuses on the rules that carry your detection logic. In 9.5, it translates Scheduled and Near Real Time (NRT) analytics rules from Microsoft Sentinel, exported from your Sentinel workspace, and handles the translation for you.
It uses the same mapping and translation as our existing rule migrations, now extended to Microsoft Sentinel. The following are supported:
The migration runs in a few steps, from exporting your rules in Sentinel to reviewing the translated versions in Elastic. Once you've decided which rules and data to migrate, follow these steps:
For more information, refer to the technical documentation.
Translation summary showing 34 of 35 Microsoft Sentinel detection rules successfully translated to Elastic Security in 15 minutes, with status breakdown by translated, partially translated, not translated and failed
One of the first decisions in a migration is sequencing: data or rules first. Elastic supports both paths, so you can start wherever makes sense for your team.
| Path | When to use | What happens |
|---|---|---|
| Rules first | You do not know exactly which data sources to prioritise before moving any logs. | Translate your Sentinel rules first. Elastic identifies which integrations those rules need, so you can plan data onboarding around what your detections actually require. |
| Data first | Your log sources are already being onboarded, or you want detections to work the moment they're installed. Onboarding data beforehand improves the translation quality. | Onboard your log sources into Elastic, then migrate your Sentinel rules to match. Rules can be installed and enabled immediately against data that's already flowing. |
| Custom data | You have proprietary or non-standard log sources that don't map to a prebuilt Elastic integration. | Use Automatic Import to ingest custom data sources in minutes, then migrate or write rules against them. |
By identifying exactly which integrations are needed before moving a single log, teams can build a precise, risk-aware roadmap for their migration project. This transparency eliminates the guesswork and helps ensure that critical visibility gaps are addressed long before you fully decommission your environment.
Once your rules are running in Elastic, Workflows lets you build automation around them. The moment a rule fires, a workflow can kick off multi-step remediation, enrichment, and notification automatically. And building these automations in Agent Builder lowers the barrier, so you can create a workflow in natural language.
Elastic Security brings generative AI into the SOC with retrieval augmented generation (RAG) and open agentic frameworks. Automatic Migration joins the lineup of Elastic Security’s AI features, helping SOC teams strengthen defenses across the IT environment:
Elastic’s SIEM and XDR solution helps analysts detect earlier and respond faster.
Migrating a SIEM has always meant rebuilding your detection rules by hand, and that cost is what keeps teams on a platform long after they've decided to leave. Automatic Migration simplifies that process, providing mapping to existing Elastic rules and helping to translate the rest. Your watchlists and severity levels carry over as well, and you move on your own terms, with your data and your tooling under your control. For further details check out our documentation.
Try it free, or get in touch. Have feedback? Tell us what you think in the Elastic Community Slack channel or on the Elastic Security forum.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。