Elastic Security v9.4 introduces Entity Analytics Watchlists, a feature that lets security teams create named, weighted lists of users, hosts, and services to inject organizational context directly into the platform's risk scoring pipeline. Unlike traditional SIEM approaches that rely on behavioral anomalies or threat intel, Watchlists codify institutional knowledge — departing employees, privileged admins, critical infrastructure — as first-class risk signals without requiring ES|QL, pipeline configuration, or detection engineering. Entities on multiple watchlists compound their risk scores alongside alert activity and asset criticality, surfacing the highest-risk entities with full context for analysts. Lists can also be auto-populated via API integrations (e.g., HR systems) to stay current without manual upkeep.

7m read timeFrom elastic.co
Post cover image
Table of contents
Your riskiest entities are already known; your SIEM just doesn't know thatIntroducing Entity Analytics WatchlistsThe lists your security program already maintainsCustom correlation, finally, without the engineering overheadComing in Elastic Security v9.4Frequently Asked Questions