Self-managed custom LLMs
You can connect self-managed LLMs to maintain more control of your data, operate in an air-gapped environment, or use specific open-source models of your choosing.
The guides on this page use Generative AI connectors, which are deprecated. For new setups, add an inference endpoint that uses the openai service and points at your local LLM.
For model performance on Elastic Security and Observability AI tasks, refer to the LLM performance matrix for Observability and the LLM performance matrix for Elastic Security.
Self-managed LLMs work well for Elastic Security's AI Assistant. For Attack Discovery, we recommend using one of the models in the LLM performance matrix for Elastic Security.
The following guides describe how to set up self-managed LLMs for Elastic Security and Observability.
Self-managed LLMs for Elastic Security:
- For production environments or air-gapped environments, you can connect to vLLM.
- For test environments, you can connect to LM Studio.
Self-managed LLMs for Observability:
-
For production, test, or air-gapped environments, you can connect to LM Studio.