Skip to main content
Back to products
Subscription

RST Elastic AI Copilot

Alert triage and detection-rule authoring for Elastic, with field masking so the same workflow runs against a cloud, private or air-gapped model.

A 14-day trial licence, issued as soon as you sign in.

Elastic AI Copilot interface
Elastic AI Copilot interface

Overview

An Elastic analyst spends the day on two things: deciding which alerts matter, and writing the detection rules that raise them. Both are judgement work that an assistant can carry most of the way.

RST Elastic AI Copilot triages alerts, assembles the context for an investigation, and drafts detection rules against your own data model. Multi-turn conversations keep the thread of an investigation instead of restarting at every question.

Field masking decides what may leave the cluster. The same workflow runs against a cloud model, a private one, or nothing off-site at all, which is what makes it usable in an environment where the first two are not permitted.

Capabilities

  1. A question, the query, the answer

    People who cannot write a query get their own answers - and see the result: nine accounts were tried in rotation, and only svc_backup eventually let someone in.

    >
  2. Morning shift opens the queue: 42 alerts

    A batch arrives and a person starts at the top - including telling apart the two that look alarming and are in fact your own systems.

  3. Open the first one: what actually happened

    The first ten minutes of an investigation - gathering the context - is already done, with the ATT&CK chain assembled along with it.

    >
  4. Next time, it raises the alert itself

    Writing a detection rule goes from an afternoon in the documentation to one sentence describing the behaviour - and the rule that comes back can be read and reviewed.

    >
  5. What does our own procedure say?

    Answers follow your own response procedures rather than generic advice, and the page says which documents they came from.

    >
  6. Of these fields, which may leave?

    You decide which fields may leave your network, and it still works when the answer is none of them.

Also in the box

Every model call audited
A full record of each call and its token usage, alongside scheduled inspection reports and team dashboards. A lead can reconstruct exactly what the AI did on their data and take that upward.
Deterministic baseline inspection
等保 2.0 and CIS checks evaluated as rules over osquery results. No model call, so the verdicts are reproducible and the check runs in an air-gapped deployment.
Multi-model failover
Runs against a cloud endpoint, a self-hosted model, or several in turn: a provider outage falls through to the next rather than stopping the desk, and every answer records which model produced it.

Editions

Standard 14-day trial

Free

Includes

  • Batch alert triage with recommended action
  • Investigation context assembled automatically
  • Detection-rule drafting with ATT&CK mapping
  • Platform ops copilot

Standard

Recommended

$4,900/yr

$490/mo

Includes

  • Batch alert triage with recommended action
  • Investigation context assembled automatically
  • Detection-rule drafting with ATT&CK mapping
  • Platform ops copilot

Enterprise

Pricing on request

Unlimited servers · 12-month term

What each edition includes

Capability
CapabilityStandard 14-day trial1 server · 14 daysStandardRecommended1 server · 12-month termEnterpriseUnlimited servers · 12-month term
PriceFree$4,900/yrPricing on request
Batch alert triage with recommended actionIncludedIncludedIncluded
Investigation context assembled automaticallyIncludedIncludedIncluded
Detection-rule drafting with ATT&CK mappingIncludedIncludedIncluded
Platform ops copilotIncludedIncludedIncluded

Included in every edition

Trial, Standard and Enterprise all include the following. None of it is gated by edition.

  • Smart query: natural language to Elasticsearch DSL, validated read-only and executed, with result and aggregation tables, per-row explanation and deep links back to Kibana; multi-turn follow-ups with saved conversations
  • Field masking, all three modes: cloud, private model, fully air-gapped — you decide which fields may leave
  • Analysis history: investigation and triage results archived and reopenable
  • Security posture overview
  • Field dictionary: reads mappings and samples data, so queries match how your cluster is actually indexed
  • Runbooks: a knowledge base over your SOPs and runbooks; every answer cites the documents it used
  • Baseline inspection: 等保 2.0 / CIS checks evaluated over osquery results — no model call, reproducible, works air-gapped
  • Asset inventory: asset and identity enrichment, CSV import
  • Operations reports, scheduled inspection reports, team dashboards
  • Call audit: every model call and its token usage
  • Outbound channels: webhook / SMTP / Feishu
  • AI configuration: multi-model failover, embedding settings
  • Users and roles (admin / analyst / read-only), sign-in, SSO / forward-auth
  • Live alert intake: pull Elastic security alerts or receive them by webhook

Need Enterprise, or a deployment shape not in the table? Contact sales