The Dataminr integration with Elastic Security brings Dataminr Indicators and their Attributes and Associations into Elastic Security. To accomplish this, the integration uses the Filebeat module to pull data from Dataminr via the Dataminr API and store the data in Elastic Security as log files. The Dataminr log files can then be parsed and visualized using Kibana Discover, a built-in Kibana dashboard, and the Indicators page in Elastic Security. Detection rules that activate on the threat intelligence data ingested by Elastic Security can be defined too. The integration is highly customizable via specific configurations and its ability to use TQL.
The integration is available directly from the Elastic Stack via the Integrations section under Stack Management.