Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Elastic has announced AlertZero, an agentic layer for Elastic Security aimed at the alert backlog that many security operations centers struggle to clear. On October 8, 2026, Elastic said an AlertZero technical preview is coming soon. It is not yet generally available as a documented product, and the company has not published a start date, pricing, or a full list of requirements. AlertZero works by assigning AI-driven tasks to four groups called Watches, and it routes consequential decisions to a human analyst as Proposed Actions.

What AlertZero is

AlertZero is Elastic’s name for an agentic layer inside Elastic Security. Elastic presents it as a route toward a security queue that does not dictate what analysts can investigate. The product name borrows from “inbox zero,” but Elastic is explicit that the goal is not a permanently empty queue. New alerts will keep arriving, and some will still need human review or deeper investigation. Treat inbox zero as the ambition behind the product, not a measured result. Elastic’s announcement, “Introducing AlertZero: Inbox zero for your alert queue” by James Spiteri, is the primary source for the product description.

The stated focus is reducing queue volume and false positives through high-volume correlation and enrichment, proposed actions, and support for creating and tuning detections. The capabilities build on Elastic AI Assistant, Attack Discovery, Elastic Agent Builder, security skills, and Elastic Workflows. Within the product, task groupings are called Watches, and the individual tasks inside them are called Workers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The four Watches

The upcoming technical preview introduces four Watches. Each one covers a different kind of SOC work:

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Watch What it does, per Elastic Typical starting point
Triage Assesses alerts, connects related activity, and identifies findings that need attention. A Triage Worker can use Attack Discovery to connect alerts into attack narratives. Incoming alerts
Hunt Uses threat research to look for evidence of attacks in available telemetry. It relates the research to the environment, searches for indicators and supporting behavior, and shows what was searched and what was found. New threat research
Detection Investigates noisy rules and coverage gaps, then prepares detection changes for review. Recurring false positives, as Elastic’s example
Forensics Examines endpoint activity to establish what happened and identify supported response actions. An endpoint finding that needs examination

Watches can be started by triggers or run on a schedule. Elastic says they do not form a mandatory pipeline, so a team can use one Watch on its own without adopting the others.

How approvals and autonomy work

Elastic describes three autonomy levels, which it names manual, assisted, and supervised. The right level depends on the task and the Worker doing it, so teams should not assume one setting applies across the product.

Watches surface their conclusions as Proposed Actions. An analyst can approve, modify, escalate, or dismiss each one. Elastic states the core boundary plainly: “Regardless of level, every consequential action is proposed to the analyst for approval.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

The endpoint example is where the details matter most. Elastic describes a manually reviewed host-isolation action through Elastic Defend, where the analyst can inspect the target, the rationale, and the likely impact before deciding. The same announcement says supervised endpoint operation allows certain supported actions, namely host isolation, process termination, and process suspension, without a separate approval for each one. Detection changes still require approval. Because Elastic’s wording on endpoint actions is specific, read the primary post’s endpoint section before assuming how approvals will behave in your own configuration.

Elastic also says the Investigation records the decision and the execution outcome separately, which is intended to support audit review.

A worked example: suspicious login session

Elastic’s illustrative scenario starts with an impossible-travel finding for an executive account. The account appears active in Boston and, 39 minutes later, from a distant hosting network, using the same session identifier with no fresh multifactor authentication event. Endpoint evidence adds an unsigned process accessing browser session material.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Elastic says this pattern warrants investigating session replay. It also notes that VPN or proxy use and inaccurate geolocation must be ruled out. The 39-minute interval belongs to this product demonstration. It is not a population statistic, and the scenario is not independently verified incident evidence or proof that such signals always indicate compromise.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In the workflow, an analyst opens the associated Investigation, reviews the supporting evidence, related alerts, and affected entities, and asks follow-up questions before deciding. The example asks what the account accessed after sign-in and what endpoint isolation would interrupt. Investigations can also be linked in an Escalation conversation so teammates can coordinate. Treat the output as triage assistance that supports the analyst’s judgment, not as a confirmed security determination.

Where AlertZero sits relative to Elastic Security 9.5

Elastic’s July 31, 2026 article, “AlertZero: Automate alert triage for the agentic SOC,” describes three capabilities in Elastic Security 9.5 that form part of the path toward AlertZero:

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
  • Security alert analysis assesses alerts from selected rules, gathers alert details and history, and adds a classification note with a confidence level and rationale. Auto-close is optional, starts disabled, and applies only to false positives above a confidence threshold that the team selects. Elastic recommends starting with notes and tags, comparing classifications with analyst decisions, and enabling auto-close only after the team trusts the pattern.
  • Attack Discovery correlates related alerts into attack narratives. In the 9.5 capability described, it investigates the underlying activity using security skills, entity context, and raw logs. It can present a detection-gap analysis and draft an ES|QL rule, but an analyst must review and explicitly approve the draft before the rule is created.
  • Elastic Workflows provides an automation layer for bringing these capabilities into existing playbooks.

These 9.5 features explain the product context. They are not the same thing as the upcoming AlertZero preview, and Elastic’s October announcement is the source for what the preview includes.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Deployment and model choice

Elastic says AlertZero follows its “open by design” approach. Teams can use a proprietary or open-source model of their choice across Elastic Cloud, self-managed, or fully air-gapped environments. The announcement does not include a list of supported model versions, system requirements, or a compatibility matrix. Those details should come from Elastic’s documentation when the preview ships, not from assumptions made now.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is confirmed and what is not

  • Availability: Elastic’s October 8 announcement calls the technical preview upcoming and says it will be available soon to Elastic Security users. An Investing.com report from the same day, “Elastic launches AlertZero AI agents for security operations,” describes AlertZero as entering Technical Preview. Neither source gives an exact start date, access conditions, pricing, or licensing terms. Elastic’s primary post should take precedence for product descriptions.
  • Performance: No independent performance study or quantified AlertZero outcome has been published in the sources reviewed. Goals such as answering every alert or reaching inbox zero are product aims, not guarantees.
  • Cost: Pricing is not stated in the sources. Teams evaluating fit should ask Elastic directly about licensing before planning budgets.

How to evaluate fit

Until full documentation is published, compare AlertZero against your own environment on the dimensions Elastic has described:

  • Hosting model: Elastic Cloud, self-managed, or air-gapped, and whether your deployment can use the model you prefer.
  • Model choice: proprietary or open-source, and who in your organization is responsible for that decision.
  • Watch scope: which of Triage, Hunt, Detection, and Forensics match your current pain points, since they can run independently.
  • Approval settings: which autonomy level applies to each task, and which endpoint actions your policy would allow without per-action approval.

If you already run Elastic Security 9.5, the alert analysis and Attack Discovery features described above are a practical way to test how classification notes and approvals fit your workflow before the preview arrives.

The Bottom Line

“”>

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.