# Ingest data to Elastic Security using third-party collectors configured to ship ECS-compliant data

**URL:** <https://discuss.elastic.co/t/ingest-data-to-elastic-security-using-third-party-collectors-configured-to-ship-ecs-compliant-data/303023>\
**Category:** Elastic Security\
**Created:** [April 22, 2022, 11:25am UTC](https://discuss.elastic.co/t/ingest-data-to-elastic-security-using-third-party-collectors-configured-to-ship-ecs-compliant-data/303023 "2022-04-22T11:25:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![msilva](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@msilva](https://discuss.elastic.co/u/msilva)\
**Post date:** [April 22, 2022, 11:25am UTC](https://discuss.elastic.co/t/ingest-data-to-elastic-security-using-third-party-collectors-configured-to-ship-ecs-compliant-data/303023/1 "2022-04-22T11:25:20Z")

</div>

Hi,  
In [Ingest data to Elastic Security | Elastic Security Solution [8.1] | Elastic](https://www.elastic.co/guide/en/security/8.1/ingest-data.html#ingest-data), it is mentioned that data can be ingested to Elastic Security using third-party collectors configured to ship ECS-compliant data.  
What could be the best approach to directly send data to an Elastic Security SIEM using an AWS lambda instance? Would this process be an options?

- Use a cloud API/API keys for authentication
- Wrap ECS fields in a format used by Logstash
- Send the wrapped fields to an Elastic Endpoint Security instance  
Kind regards,

Moacir

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2022, 11:25am UTC](https://discuss.elastic.co/t/ingest-data-to-elastic-security-using-third-party-collectors-configured-to-ship-ecs-compliant-data/303023/2 "2022-05-20T11:25:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
