I moved your question to #logstash as elasticsearch does not push any data to any external system unless you are using alerting feature (commercial license) which can call an http endpoint.
The streams you describe seem to map quite closely to the type of logic you would implement in Logstash. Logstash has a variety of outputs that you can use to push data to SIEMs.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.