Back to News
ProductAI Understanding briefing

Elastic launches AlertZero and nightshift AI agents for security and observability

Elastic has unveiled AlertZero, an agentic security layer, and nightshift, an AI site reliability engineering agent, both entering preview phases to address detection gaps highlighted by recent AI-related breaches.

4 min readRead the linked source
Source-provided image accompanying Elastic launches AlertZero and nightshift AI agents for security and observability
Source referenceSource recorded
Publisher
smbtech.au
Source type
Linked source — primary-source status has not been established.
ContextUnderstand this in 60 seconds

Key terms

Knowledge Graph
A graph structure of entities and relationships used for reasoning or retrieval.
AI Agent
A software system that can observe, reason, and take actions to achieve a goal, often using tools and memory.
Feature
An input variable used by a model to make predictions.
Test yourselfAI Agents Quiz

What happened

Elastic announced the launch of two new products: AlertZero for security operations and nightshift for site reliability engineering. AlertZero is an agentic layer within Elastic Security that uses specialized 'Watches' to handle alert triage, threat hunting, and forensics. nightshift is an AI SRE agent in Elastic Observability that investigates root causes across the tech stack. Both are currently in technical or private preview.

Elastic has introduced AlertZero, an agentic layer built into Elastic Security, which deploys specialized AI agents across the security operations lifecycle. The system organizes work into 'Watches,' such as Triage Watch for alert filtering and Hunt Watch for continuous threat hunting. These agents are designed to reduce the volume of raw alerts presented to human analysts, focusing on recommended actions while retaining human oversight for final decisions.

Simultaneously, Elastic launched nightshift, an AI site reliability engineering (SRE) agent integrated into Elastic Observability. This tool continuously detects and investigates issues across an organization's entire stack, testing multiple root-cause hypotheses in parallel. It utilizes a to connect telemetry with source code from GitHub, allowing it to identify specific commits that may have caused exceptions. The agent's reasoning is visible to engineers, who can inspect the queries and data used in its investigations.

The announcement follows research by Elastic surveying over 850 IT and cybersecurity professionals in Australia and New Zealand. The study found that only 9% of Australian organizations could detect a compromise within five minutes outside business hours, and only 14% could respond to AI-automated attacks at machine speed. Furthermore, only about 20% of respondents in both countries reported that their security data was ready for reliable usage, highlighting a significant infrastructure gap.

Source details: smbtech.au ↗

Why it matters

These launches address a critical gap in organizational visibility, where most companies cannot detect AI-driven compromises quickly enough. By automating triage and investigation, Elastic aims to reduce the reliance on manual processes that currently slow down response times. The products are model-agnostic, allowing organizations to use various AI backends while maintaining control over automation levels.

The timing of these launches is significant given recent incidents where rogue AI agents accessed government systems in Australia without immediate detection. Elastic positions these tools as a response to the 'cyber equation' change brought by AI, arguing that organizations need AI-driven defense to match AI-driven threats.

A key differentiator cited by Elastic is the model-agnostic nature of both products. They can operate with any AI model in various deployment scenarios, including Elastic Cloud, self-managed, and air-gapped environments. This flexibility allows organizations to avoid vendor lock-in while leveraging the most effective AI models for their specific security and operational needs.

The products aim to solve the problem of 'blind spots' in security and observability. By consolidating data and providing agents with broader context, Elastic argues that these tools can identify issues that rule-based alerts miss, thereby improving the overall resilience of enterprise infrastructure against both cyberattacks and system failures.

Interactive Mechanism

Interactive Mechanism: How It Actually Works

Explore the underlying technology behind this development interactively.

Thinking Budget (Test-Time Tokens):1,024 tokens
Complex Accuracy79%Math & Code Logic
Latency3.2sTime to first full output
Inference Cost$0.0092Per query estimated
Reasoning StyleStep VerificationInternal chain depth
Active Thinking Trace:
1Deconstruct user problem into formal constraints
2Propose candidate hypotheses & step-by-step calculation
3Self-correction: Backtrack and refute subtle edge cases
4Exhaustive consistency check & final output synthesis
Core takeaway: Test-time compute fundamentally changes AI economics. Instead of only scaling during pre-training, giving reasoning models more tokens at inference time allows them to systematically solve PhD-level STEM problems.
Interactive Concept Check+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

What to watch next

Monitor the transition of these tools from preview to general availability, particularly regarding their effectiveness in air-gapped environments and their ability to integrate with existing heterogeneous data estates without creating new blind spots.

The progression of AlertZero and nightshift from technical and private previews to general availability will be a key indicator of their practical utility. Specific attention should be paid to how well these agents perform in complex, heterogeneous environments where data is often scattered across disconnected systems.

Organizations should monitor the adoption of the 'Watches' framework in AlertZero to see if it effectively reduces alert fatigue without introducing new risks through over-automation. The balance between agent autonomy and human control will be critical for widespread acceptance in security operations centers.

The integration of nightshift with source code repositories via knowledge graphs represents a novel approach to SRE. Watching how this handles false positives and the accuracy of its root-cause identification in real-world scenarios will determine its value for engineering teams.

Related guides & quizzes

Found this useful?