Triage Elastic Security alerts - gather context, classify threats, create cases, and acknowledge. Use when triaging alerts, performing SOC analysis, or investigating detections.
---
name: security-alert-triage
description: >
Triage Elastic Security alerts — gather context, classify threats, create cases,
and acknowledge. Use when triaging alerts, performing SOC analysis, or investigating
detections.
compatibility: >
Requires Node.js 22+, network access to Elasticsearch. Environment variables: ELASTICSEARCH_URL
or ELASTICSEARCH_CLOUD_ID, plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD.
metadata:
author: elastic
version: 0.1.0
---
# Alert Triage
Analyze Elastic Security alerts one at a time: gather context, classify, create a case, and acknowledge. This skill
depends on the `case-management` skill for case creation.
## Prerequisites
Install dependencies before first use from the `skills/security` directory:
```bash
cd skills/security && npm install… install to load the full skillIt activates automatically in your next session.
Not connected yet? Connect your AI first →
MCP endpoint
https://skillme.dev/api/mcp