# Using LLM together Elastic SIEM

**URL:** <https://discuss.elastic.co/t/using-llm-together-elastic-siem/386464>\
**Category:** Elastic Security\
**Created:** [May 24, 2026, 7:25am UTC](https://discuss.elastic.co/t/using-llm-together-elastic-siem/386464 "2026-05-24T07:25:46Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![arcsons](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@arcsons](https://discuss.elastic.co/u/arcsons)\
**Post date:** [May 24, 2026, 7:25am UTC](https://discuss.elastic.co/t/using-llm-together-elastic-siem/386464/1 "2026-05-24T07:25:46Z")

</div>

Hi all

I have configured a local Mistral LLM with my Elastic Stack (version 9.3.3). I also have the full Enterprise license enabled.

From a security perspective, I’m curious how others are using LLMs within Elastic. Have you implemented any useful workflows, automations, or detection-related use cases?

I’d also love to hear any creative or practical ideas for security-focused use cases that I could experiment with.
