Elastic Workflows is a native automation capability now in technical preview within Elastic Security, designed to replace standalone SOAR tools. It combines YAML-defined playbooks with AI agent reasoning to automate alert triage, enrichment, case management, and incident response. Because it runs natively inside Elastic
Table of contents
The challenge: The automation tax and forced tradeoffsElastic Workflows: End the automation taxGet started with Elastic WorkflowsShareSort: