Search Guard covers the full security lifecycle of an Elasticsearch cluster: TLS encryption for all traffic, authentication via LDAP, Active Directory, SAML, OpenID Connect, Kerberos, and JSON Web Tokens, role-based access control down to individual documents and fields, Kibana multi-tenancy, comprehensive audit logging, encryption at rest, and the Signals alerting module for monitoring your data and triggering notifications via email, Slack, PagerDuty, Jira, webhooks, and more.