Triage Elastic Security alerts - gather context, classify threats, create cases, and acknowledge. Use when triaging alerts, performing SOC analysis, or investigating detections.
---
name: security-alert-triage
description: >
Triage Elastic Security alerts — gather context, classify threats, create cases,
and acknowledge. Use when triaging alerts, performing SOC analysis, or investigating
detections.
compatibility: >
Requires Node.js 22+, network access to Elasticsearch. Environment variables: ELASTICSEARCH_URL
or ELASTICSEARCH_CLOUD_ID, plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD.
metadata:
author: elastic
version: 0.1.0
---
# Alert Triage
Analyze Elastic Security alerts one at a time: gather context, classify, create a case, and acknowledge. This skill
depends on the `case-management` skill for case creation.
## Prerequisites
Install dependencies before first use from the `skills/security` directory:
```bash
cd skills/security && npm install… load the full skill through Skill MeIf full content is available, it applies in this conversation and stays installed for future sessions.
Not connected yet? Connect your AI first →
MCP endpoint
https://skillme.dev/api/mcp