Elastic AI Copilot
A Docker gateway on an existing Elasticsearch 8.x: plain-language log queries, alert triage, alert investigation, detection-rule drafting.
What it is
Elastic AI Copilot is an AI gateway that runs inside the network and does not ship Elasticsearch: it plugs into an existing ES / Kibana, turns an analyst's natural language into queries and the results into conclusions.

What it does
| Capability | What | Paid? |
|---|---|---|
| Smart query | Natural language → ES query, dry-run repair, follow-up turns | Free |
| Field masking | Cloud / private / air-gapped modes, applied before data leaves the cluster | Free |
| Posture, audit, reports, knowledge base, baseline, ledger | Operational data, summarised and archived | Free |
| Alert batch triage | Cluster, score and rank a batch of alerts | Paid |
| Alert investigation | Multi-round evidence gathering around one alert, with a verdict | Paid |
| Detection-rule drafting | KQL / EQL rules from a description or a sample | Paid |
| Platform-ops copilot | Manage the platform's own configuration in plain language | Paid |
Unactivated, the free capabilities keep working under a daily quota; the paid engines need an activated licence. A trial licence is the Standard tier for 14 days.
Where to start
Quick start
From the delivery archive to a working login, about ten minutes.
Installation
Requirements, deploy.sh, configuration, ES permissions, SSO, upgrade and backup.
User guide
What each page does and where its limits are: smart query, triage, investigation, rules, posture, settings.
Troubleshooting
Causes by symptom; error-code lookup.