AI-Assisted Security Operations Using Elastic SIEM and Local AI Models
Speaker: Nikhil Ajit
This case study is a look at how we built a local AI-assisted security operations platform for a small cybersecurity team using Elastic SIEM, n8n, Ollama, MISP, Microsoft Teams, and a dashboard. The goal was not to build an autonomous SOC, and not to let AI block users, change firewall rules, or query the SIEM directly. The goal was to answer a more practical question: can local AI help a one-person SOC triage faster without handing the keys to the machine?
We will walk through how the system was designed, what worked, what failed, and why the final architecture keeps AI fenced in. The local model can understand plain-English SOC questions, propose read-only investigations, and help summarize evidence. n8n acts as the control plane, safety gate, credential holder, and executor. Elastic remains the source of truth. MISP adds threat intelligence context. The human remains the final decision maker.
This session will also explore how this model can support “Threat Diligence” across Atlantic Canadian universities. Many institutions receive threat intelligence, but a feed alone does not answer the operational questions that matter: did this indicator touch us, was it accepted or denied, which asset or user was involved, and are other institutions seeing the same thing? We will discuss how AI-assisted workflows can help turn threat feeds into safe, evidence-backed, human-reviewed regional intelligence without sharing raw logs or automating response.
We will break down the journey from an early single-workflow prototype to a modular SOC platform with safety gates, read-only Elastic queries, alert summaries, priority drilldowns, MISP enrichment, Teams reporting, dashboard access, audit trails, and fail-closed behavior. The session will focus on practical lessons for small teams that want AI assistance without unsafe autonomy.
Learning Objectives:
By the end of this session, participants will:
- Understand how local AI can assist SOC triage without receiving credentials or direct access to security tools
- Learn how to separate AI reasoning from automation control using safety gates, read-only queries, and human approval
- See how Elastic, n8n, Ollama, MISP, Teams, and a dashboard can be combined into a practical SOC workflow for a small team
- Learn how threat feeds can be turned into “Threat Diligence” by validating indicators against local evidence
- Understand how a regional shared-intelligence model could help Atlantic Canadian universities collaborate safely without sharing raw logs
- Take away design patterns for building AI-assisted security workflows that fail closed instead of failing dangerously
Speaker Bio:
Nikhil Ajit is the Manager of Cybersecurity at Acadia University. He has over 11 years of experience across higher education, healthcare, finance, and national infrastructure. Before joining Acadia, he worked as Senior Manager, Cybersecurity at Mannai in Qatar.
