Elastic integration
Sync Elasticsearch users, roles, and access policies into your service intelligence layer for unified identity and security management.
What it connects
- Security users with assigned roles and account status across your Elasticsearch cluster.
- Role definitions including cluster permissions, index access levels, and application privileges.
- External identity mappings that connect LDAP, SAML, and SSO groups to roles for federated access.
- User metadata, email addresses, and full names for building a complete identity inventory.
What it automates
- Disable or enable user accounts in response to offboarding workflows or security incidents.
- Create new users and assign roles automatically during employee onboarding.
- Rotate and invalidate API keys when credentials are suspected compromised or rotated.
- Update role definitions and external identity mappings to sync permission changes across your system.
In practice
When a security investigation flags a suspicious API key in Elasticsearch, STLabs automatically revokes it and notifies the owning service team with incident context.
During employee offboarding. STLabs disables the user in Elasticsearch and cross-references their assigned roles to identify services that need similar access removal.
A SAML group policy change in your identity provider is detected; STLabs syncs the updated role mapping into Elasticsearch, ensuring federated users get consistent permissions everywhere.
STLabs correlates Elasticsearch audit logs with identity changes, flagging unusual permission escalations or role assignments that deviate from approval workflows.