I am using it to get some hands-on experience and learn the product by searching, building use cases, test cases, dashboards, and visualizations.
With hands-on experience, you learn more about the product and how it works.
It should be easier to use. It has been getting better because many functions are pre-defined, but it still needs improvement.
If you have a large enterprise environment, it is costing a lot of money and it's not a full-blown SIEM. It has SIEM features but a lot is missing. You need to involve other products to make a SIEM out of it.
Some of the other products needed were Apache, Kafka, and ticket tools. It was custom made and not what I had expected in the end.
I would like to see them get closer to a full-blown orchestrated SIEM, and create predefined modules to bring you to using it as a SIEM faster, and on the fly instead of having to tweak the Grok filter for weeks.
I would like to see more pre-defined modules.
I have been using Elasticsearch for two weeks.
We are not using the latest version, but not an old version.
It's a stable solution and we have not had any issues.
I have contacted technical support, once or twice. The experience was okay.
The initial setup was okay, not as easy as Splunk but it was manageable.
The pricing model is questionable and needs to be addressed because when you would like to have the security they charge per machine. If you are building any cluster and you are paying €6,000 per machine, that is expensive.
I think that Elasticsearch is a good product and cheaper than Splunk.
I like this solution, but it has too much hands-on time required tweaking to get it up and running.
I have no plans to continue using this product. Currently, I am focused on SIEMonster because I signed a partnership and I would like to sell a total product. It doesn't make sense to spread across multiple products.
I would like to earn money out of it, so I'm focusing currently on SIEMonster.
I think that Elasticsearch is a good product and cheaper than Splunk.
When I check Gartner, I don't see mention of Elasticsearch, it seems they need to make some improvements.
I would rate this solution a seven out of ten.