Enable large language model (LLM) access

edit
A newer version is available. Check out the latest documentation.

Enable large language model (LLM) access

edit

Elastic Security uses large language models (LLMs) for some of its advanced analytics features. To enable these features, you can connect to a third-party LLM provider or a custom local LLM.

Different LLMs have varying performance when used to power different features and use-cases. For more information about how various models perform on different tasks in Elastic Security, refer to the Large language model performance matrix.

Connect to a third-party LLM

edit

Follow these guides to connect to one or more third-party LLM providers:

Connect to a custom local LLM

edit

You can connect to LM studio to use a custom LLM deployed and managed by you.