Skip to main content

Elastic Cloud

Visualize Elastic Cloud Search Account, Users, Clusters, Nodes, Backup, Roles and Service Accounts changes through queries and alerts.

Installation Guide

Info

User needs to create an instance per deployment.

Requirements

To Configure the integration, ensure you have the following:

  • Elastic Cloud Account ID
  • Elasticsearch API Key
  • Elasticsearch Cloud ID (generated in your Elastic Cloud account)

Configuration in Elastic Cloud

Creating an Elasticsearch API Key

  1. Log in to your Elastic Cloud Account.
  2. Select your deployment from the dashboard.
  3. Select the Search app.
  4. Copy the Elasticsearch Endpoint displayed on the homepage.
  5. Click Manage.
  6. Select Create New API Key.
  7. Provide an API Key Name for identification.
  8. Choose User API Key as the type.
  9. Specify the Expiry date for the API Key.
  10. Enable Control Security Privileges.
  11. Click Create API Key .
  12. Copy the generated Elasticsearch API Key.
  13. Click on your profile icon and select Organization
  14. Copy organization ID.

Configuration in JupiterOne

  1. From the top navigation bar of the J1 Search homepage, go to Integrations.

  2. Search for Elastic Cloud and select it.

  3. Click the Add Instance button and configure the following settings:

    • Elastic Cloud Account ID: Paste the Organization ID copied from Elastic Cloud.
    • Elastic Search Endpoint: Paste the Elasticsearch Endpoint copied from Elasticsearch.
    • Elastic Search API Key: Paste the Elasticsearch API Key generated earlier.
    • Account Name: Provide a name to identify this Elastic Cloud instance in JupiterOne. When the Tag with Account Name option is checked, ingested entities will store this value in tag.AccountName.
    • Description: Add a description to assist your team in identifying this integration instance.
    • Polling Interval (optional): Select a polling interval that fits your monitoring needs. If unsure, leave this as DISABLED and manually execute the integration.
  4. Click Create Configuration to save your settings.

Next steps

Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.