Skip to content

Elastic AlertZero Enters Technical Preview: Four SOC Watches Triage, Hunt, Detect and Forensics With Human Approval Gates

Elastic announced AlertZero on 8 Oct 2026 as a Technical Preview for Elastic Security: four Watches for triage, hunt, detection and forensics propose evidence-backed actions, while consequential changes still need human approval. Standalone USD pricing was not published.

Elastic AlertZero graphic showing 3000 alerts reduced to 6 human decisions across Triage Detection Forensics and Hunt Watches

On 8 Oct 2026, Elastic introduced AlertZero, an agentic layer inside Elastic Security. The pitch is blunt: every alert gets an answer, and every consequential change still needs a human yes.

In a same-day Elastic Security Labs post, product design lead James Spiteri describes four specialized agent groups called Watches. They cover triage, hunting, detection tuning, and forensics. Each Watch proposes evidence-backed actions. Host isolation, rule edits, and similar moves stay behind approval gates unless a team deliberately raises autonomy.

AlertZero is entering Technical Preview for Elastic Security customers on Elastic Cloud, self-managed, and air-gapped deployments. Launch materials do not publish a separate AlertZero price or a general availability date. Treat it as a preview of Elastic’s agentic SOC stack, not a finished SKU with public list pricing.

What Elastic Confirmed Versus What Remains Open

The IR release and the Security Labs post agree on the product shape. Both name the four Watches, the Technical Preview, model choice across cloud and air-gapped installs, and the rule that consequential actions are proposed for approval. Mike Nichols, Elastic’s general manager for Security, is quoted saying the team built for visibility and control so SOC teams can dial autonomy to what they can handle.

What they do not publish is a dollar price for AlertZero alone, third-party accuracy numbers for the four Watches, or a GA calendar. Vendor demos and Elastic’s own internal SOC stories are useful context. They are not independent benchmarks.

Claim Status Source notes
AlertZero announced as Elastic Security agentic layer Confirmed Elastic IR and Security Labs, 8 Oct 2026
Four Watches: Triage, Hunt, Detection, Forensics Confirmed Both primary posts
Technical Preview on Cloud, self-managed, air-gapped Confirmed IR availability section
Works with customer-chosen models (proprietary or open source) Confirmed as design Security Labs and IR
Consequential actions proposed for analyst approval Confirmed Security Labs; autonomy settings still allow supervised endpoint actions
Builds on Attack Discovery, Agent Builder, Elastic Workflows, ES|QL Confirmed Both posts
Separate AlertZero list price in USD Unconfirmed Not in launch posts; sold as Elastic Security capability
GA date Unconfirmed TP interest form says “almost here”; no dated GA
Independent accuracy of all four Watches in customer SOCs Unconfirmed No third-party eval in launch pack

The Four Watches, In Plain Terms

Spiteri’s post maps each Watch to a familiar SOC job, then notes that Workers inside a Watch run as Elastic Workflows calling Agent Builder skills.

  • Triage Watch enriches alerts, links related activity, and uses Attack Discovery to open Investigations for suspected attacks. It is the queue cleaner.
  • Hunt Watch starts from threat research, maps exposures in your telemetry, and looks for evidence even when no detection fired.
  • Detection Watch studies noisy rules and coverage gaps, then prepares rule changes or exceptions with diagnosis and backtest samples. It will not change a rule without approval.
  • Forensics Watch digs into endpoint activity, malware paths, and supported response actions such as host isolation through Elastic Defend.

Watches are not a mandatory pipeline. A hunt can start from new research. Detection work can start from recurring false positives. Endpoint analysis can start from a finding that needs a closer look. That matters for teams that already have strong SIEM rules but weak hunting capacity, or the reverse.

Autonomy Settings Are The Real Product Decision

Elastic describes per-Worker autonomy as manual, assisted, or supervised. The Security Labs walkthrough is careful: even when a Watch is aggressive, consequential actions still show up as Proposed Actions with evidence.

Supervised endpoint analysis is the sharp edge. Elastic says supervised mode is designed to allow host isolation, process termination, and process suspension without an extra click for each action. Detection rule changes still need approval. Teams that outsource night shifts or share a thin Tier-1 bench should treat supervised endpoint control as a policy choice, not a default to turn on for marketing screenshots.

The demo scenario in the Labs post is concrete. An executive account shows impossible travel in about 39 minutes on the same session identifier without a fresh MFA event. An unsigned process touches browser session material. The Proposed Action under review is endpoint isolation for that host. Analysts can ask follow-up questions in the Investigation before they approve or dismiss. That is the workflow Elastic wants buyers to imagine: agents gather, humans decide.

Why Elastic Is Pushing Agentic SOC Now

The IR release cites a high-profile attack in which an autonomous AI agent generated more than 17,000 events across a production environment in four days, moving from a dataset-pipeline exploit into credential theft and lateral movement. Individual signals were detectable. Connecting them as one attack was the bottleneck.

That storyline matches what other vendors keep saying about AI-accelerated offense. Our coverage of Microsoft’s 2026 Digital Defense Report and Anthropic’s report on Claude agents misusing live sites in evals points the same direction: volume and speed are rising faster than headcount. AlertZero is Elastic’s bid to keep the queue from becoming the priority list.

It also sits next to Anthropic’s free OSS Scanner on the broader AI-for-defense map. OSS Scanner pushes model-written vuln reports into open-source repos. AlertZero pushes model-written investigations into a commercial SIEM. Different buyers, same pressure: too many signals, not enough senior analysts.

What It Means For Indian Developers And SOC Teams

India hosts a large share of outsourced SOC, MSSP, and managed detection work for US, Canadian, Australian, and European clients. AlertZero’s inbox-zero framing lands hardest there: night coverage, thin senior benches, and SLA pressure on alert dwell time.

USD pricing still rules the buying conversation. Elastic did not publish a standalone AlertZero tariff. Expect cost to ride Elastic Security subscription tiers, plus whatever model spend you attach. If you bring your own model on self-managed or air-gapped nodes, token bills move to your GPU or API vendor. If you stay on Elastic Cloud with a hosted model path, model cost may be bundled or metered. Ask for a written quote before you promise a customer “AI SOC” in an RFP.

For Indian product engineers building detection content, the Detection Watch’s ES|QL examples and backtest samples are the practical hook. A Watch that ranks rules by recent false-positive closures, then proposes exceptions with before/after query results, is closer to real detection engineering than a chat box that invents YAML. Still validate against known-bad traffic. Elastic itself says a clean false-positive backtest does not prove attack coverage survived.

Air-gapped support matters for Indian BFSI, defense-adjacent, and public-sector environments that cannot send logs to a US SaaS. Model choice on-prem is the selling point. Latency, evaluation harnesses, and prompt-injection hardening for tools that can isolate hosts remain your problem.

Skeptical Checklist Before You Pilot

Ask Elastic for autonomy matrices per Worker, audit logs of Proposed Actions versus executed actions, and how Attack Discovery false narratives are caught. Demand sample Investigations from environments that look like yours, not only polished demos.

Measure queue reduction and mean time to investigation with human review still in the loop. Do not grade the pilot only on “alerts closed by AI.” Closed noise is useful. Missed true positives are expensive.

Compare against adjacent agent platforms such as Google’s Gemini agent private preview only where the job overlaps. Gemini agent is a general workplace orchestrator. AlertZero is a SOC-specific stack glued to Elastic’s data plane. Different category, overlapping hype words.

FAQ

What is Elastic AlertZero?

AlertZero is Elastic’s agentic layer for Elastic Security. It uses specialized agent groups called Watches to triage alerts, hunt, tune detections, and run forensics-style endpoint analysis, with Proposed Actions for human approval on consequential changes.

When did Elastic announce AlertZero and is it generally available?

Elastic announced it on 8 Oct 2026. Launch materials describe a Technical Preview for Elastic Security customers. A public GA date was not published in the IR release or the Security Labs post.

How much does AlertZero cost in USD?

Elastic did not publish a separate AlertZero list price in the Oct 8 materials. Availability is framed for Elastic Security customers. Buyers should request current Elastic Security and model-usage quotes in USD.

Can AlertZero run without sending data to Elastic Cloud?

Elastic says AlertZero works in Elastic Cloud, self-managed, and air-gapped deployments, and that teams can choose models, including open source options. Exact model hosting details for each deployment mode should be confirmed in the preview docs and your account team.

Do the agents change rules or isolate hosts on their own?

Detection rule changes require approval. Endpoint response autonomy is configurable. Elastic’s Security Labs post says supervised endpoint analysis can allow isolation and process kill or suspend without an extra per-action click, while manual mode keeps those Proposed Actions in the review queue.

Share this article

Leave a Reply

Your email address will not be published. Required fields are marked *

Loading the next article…

Continue reading