# Server objects and network objects?

**URL:** <https://discuss.elastic.co/t/server-objects-and-network-objects/381760>\
**Category:** Elastic Security\
**Created:** [September 8, 2025, 9:39am UTC](https://discuss.elastic.co/t/server-objects-and-network-objects/381760 "2025-09-08T09:39:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![kippi](https://avatars.discourse-cdn.com/v4/letter/k/ee59a6/32.png) [@kippi](https://discuss.elastic.co/u/kippi)\
**Post date:** [September 8, 2025, 9:39am UTC](https://discuss.elastic.co/t/server-objects-and-network-objects/381760/1 "2025-09-08T09:39:38Z")

</div>

Hi I’m a rookie student try to understand if something is possible in Elasticsearch…

In Qradar you can define server objects and network objects, for example internal servers, network zones or IP ranges and then use them directly in correlation rules.

I’m wondering if something similar can be done in Elasticsearch / Elastic Security with the free basic license.

-Can I model servers and networks as documents (e.g in a dedicated index) and the reference them in detection rules?

-Or is there any built-in feature in Elastic Security for managing such assets/objects out of the box?

-If it’s possible, are there examples or best practices for implementing this?

Thanks in advance for any guidance!

---

<div class="post-metadata">

**Author:** ![lcamargo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lcamargo/32/125144_2.png) [@lcamargo](https://discuss.elastic.co/u/lcamargo)\
**Post date:** [October 22, 2025, 7:21pm UTC](https://discuss.elastic.co/t/server-objects-and-network-objects/381760/3 "2025-10-22T19:21:07Z")

</div>

Hello @kippi

I am leaving 2 links that can help you with this topic:

> **[Inventory to insight: How Elastic’s asset inventory powers InfoSec use cases](https://www.elastic.co/blog/how-elastic-asset-inventory-powers-infosec)**
>
> See how Elastic’s asset inventory has evolved into a critical tool for InfoSec, transforming from a basic inventory to a powerful solution that addresses real-world cybersecurity challenges....

> **[Tutorial: Threat hunting with ES|QL | Elastic Docs](https://www.elastic.co/docs/solutions/security/esql-for-security/esql-threat-hunting-tutorial)**
>
> This hands-on tutorial demonstrates advanced threat hunting techniques using the Elasticsearch Query Language (ES|QL). Following a simulated Advanced...
