Using LLM together Elastic SIEM

Hi all

I have configured a local Mistral LLM with my Elastic Stack (version 9.3.3). I also have the full Enterprise license enabled.

From a security perspective, I’m curious how others are using LLMs within Elastic. Have you implemented any useful workflows, automations, or detection-related use cases?

I’d also love to hear any creative or practical ideas for security-focused use cases that I could experiment with.