My use case for the product revolved around conducting demonstrations and testing. It also helped me with tracing ransomware and managing threat scenarios.
Cyber Security Trainer and Programmer at Freelancer
Traces ransomware and manages threat scenarios
Pros and Cons
- "Improvements in Elastic Security could include refining and normalizing queries to make them more user-friendly, enhancing the user experience with better documentation, and addressing any latency issues."
What is our primary use case?
What is most valuable?
The integration with Siemens Endpoint Security in Elastic Security has been beneficial for security. The provided rules are good, making it easy to create and understand rules. Patterns and detections are made through index patterns, requiring some follow-up steps.
In real-time, the impact of Elastic Security on ransomware is significant. For known and repeated ransomware, it can detect and prevent effectively using established signatures and behavioral patterns. However, for new types of ransomware with less complex behaviors or those that modify files minimally, conventional detection methods may struggle. Elastic Security proves to be effective even in challenging cases.
On the cloud, it allows testing of SaaS-based applications, performance evaluations using CDMs and APIs, incident detection within company network infrastructures, and comprehensive management of security services.
What needs improvement?
Improvements in Elastic Security could include refining and normalizing queries to make them more user-friendly, enhancing the user experience with better documentation, and addressing any latency issues.
For how long have I used the solution?
I have utilized Elastic Security for approximately three to four months.
Buyer's Guide
Elastic Security
October 2025

Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
871,358 professionals have used our research since 2012.
What do I think about the stability of the solution?
I rate the product’s stability an eight out of ten.
What do I think about the scalability of the solution?
Scaling Elastic Security is relatively easy, with a rating of seven out of ten.
How was the initial setup?
The tool's deployment is straightforward.
What other advice do I have?
I rate the overall product an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Executive Cybersecurity at a computer software company with 11-50 employees
Dashboard offers different types of reports, including a list of alerts and easy to setup
Pros and Cons
- "The scalability is good. It can be scaled easily in the production environment."
- "One limitation of Elastic Security is that it does not have built-in workflows for all tasks. For example, if you need a workflow for compliance, you will need to create a custom workflow."
What is our primary use case?
We are looking for the same tool on-premises that we can provide to our client as an MSSP. We're evaluating different types of tools in the market.
Although, we have a premium version, and I was checking the functions and features here.
We have some questions about the query language. So that also from this console and so that we can actually want to have a demonstration session where we can clarify this thing query to manage.
What is most valuable?
The interesting thing is about the dashboard. There are available widgets for the dashboards, along with specific features like different types of reports, such as a list of alerts. This helps to remind us which events are happening most often.
We are still evaluating the solution, but the dashboard is something good. And one more thing, it also has anomaly reports. I like that there is a report that is only based on anomaly-related activity.
What needs improvement?
One limitation of Elastic Security is that it does not have built-in workflows for all tasks. For example, if you need a workflow for compliance, you will need to create a custom workflow.
Sometimes, different types of clients require different workflows. And it absolutely varies from context to context. So that is often not available in [Elastic Security].
Additionally, the list of data sources that Elastic Security supports is limited. If you need to collect data from a system or application that is not on the list, you will need to develop a custom integration.
For how long have I used the solution?
We have been evaluating it for the last two months.
What do I think about the stability of the solution?
It works fine on the few devices we have deployed this solution.
What do I think about the scalability of the solution?
The scalability is good. It can be scaled easily in the production environment.
How was the initial setup?
The initial setup is easy.
What's my experience with pricing, setup cost, and licensing?
The pricing is fine. But the basic pricing should cover all the features you need. Elastic needs to add more features, which are available as subscription-based add-ons. So more features may need to be added.
What other advice do I have?
Overall, I would rate the solution an eight out of ten. We are still evaluating Elastic Security, but we are interested in learning more about its capabilities.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Elastic Security
October 2025

Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
871,358 professionals have used our research since 2012.
Head of Platform Development at Patrianna
An easy-to-adapt solution that needs to improve scalability
Pros and Cons
- "Elastic Security is very easy to adapt."
- "The tool should improve its scalability."
What is most valuable?
Elastic Security is very easy to adapt.
What needs improvement?
The tool should improve its scalability.
For how long have I used the solution?
I have been working with the product for seven years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
Our DevOps uses the product regularly.
What other advice do I have?
I would rate the solution a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Lead Enterprise Architect at DigyCorp
A flexible and open solution that supports varieties of integrations
Pros and Cons
- "The product has huge integration varieties available."
- "The tool needs to integrate with legacy servers. Big companies can have legacy servers that may not always be updated."
What is most valuable?
The product has huge integration varieties available.
What needs improvement?
The tool needs to integrate with legacy servers. Big companies can have legacy servers that may not always be updated.
For how long have I used the solution?
I have been working with the solution for the last eight months.
What do I think about the scalability of the solution?
The solution is scalable and flexible. My company has 20 users for the product.
How are customer service and support?
We had relied on in-house support initially. However, we understand now that there are a few areas where we need to have vendor support. So we have contacted a few different companies and contractors for it. In the beginning, it may be possible to do support in-house. However, if you have a lot of commercial production environment services, then it is very hard to do without vendor support.
Which solution did I use previously and why did I switch?
We decided to use the solution because it was a very promising tool and other alternatives had limitations. The tool has availability, data infrastructure, data uptime, etc. The solution is quite flexible in terms of cost. You don't need to buy a license for each and everything. Whenever you require a license, you can just buy it. I think these are the two main drivers. The product is quite open in terms of integration with machine learning which helps us with proactive monitoring.
How was the initial setup?
The product's initial setup is very easy. I think the most important point is how you design your infrastructure because the solution is quite open. So you have to design it based on the nature of the data. You also need to get a life cycle so that there is no load on the storage. The solution's flexibility depends on how you design it.
What's my experience with pricing, setup cost, and licensing?
The tool's pricing is flexible and comes at unit cost. You don't have to pay for everything.
What other advice do I have?
I would rate the product an eight out of ten. You should use the solution if you want to have a very detailed machine-learning artificial intelligence. However, for certain production licenses, you need to prepare. It is open to different configurations and can just fit according to your requirements. This is one of the solution's good parts.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
DevOps Engineer at a tech services company with 51-200 employees
Efficiently handle millions of loads simultaneously
Pros and Cons
- "It can handle millions of loads at a time, and you can always use the filters to find exactly what you are looking for and detect errors in every log message you are searching for, basically."
- "There is an area of improvement in the Logs list. The load list may need to be paginated as there are limits."
What is our primary use case?
We are using Elastic Security for logging the application logs, as we use a microservice architecture. So all application logs are saved to this LogSpot.
How has it helped my organization?
It helps us detect errors and keep an eye on the application in both the development and production environments.
What is most valuable?
It can handle millions of loads at a time, and you can always use the filters to find exactly what you are looking for and detect errors in every log message you are searching for, basically.
What needs improvement?
There is an area of improvement in the Logs list. The load list may need to be paginated as there are limits. So if you are looking for logs for a specific application, you may get 50 lines of logs, but then you are lost. You need to add more features to specify your request so you can get the final result. It would be better to have additional features to specify your request and get the complete result.
For how long have I used the solution?
I have been using this solution for nine months. Although, I am not using the latest version.
What do I think about the stability of the solution?
I would rate the stability a nine out of ten.
What do I think about the scalability of the solution?
I would rate the scalability an eight out of ten.
What was our ROI?
We definitely saw an ROI. It quickly finds the bugs.
What other advice do I have?
I would recommend using it, especially if you have a microservice architecture. I also have a friend who has been using it for some big data projects, so I would recommend it for that as well.
Overall, I would rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Intern Cybersecurity at a computer software company with 10,001+ employees
It's a highly flexible platform you can implement anywhere, but the setup is complex and difficult
Pros and Cons
- "Elastic Security is a highly flexible platform that can be implemented anywhere."
- "The setup process is complex. You need a solid working knowledge of networking, operating systems, and a little programming."
What is our primary use case?
I use Elastic Search to collect logs from an Active Directory server and forward the incidents to the SOAR solution.
What is most valuable?
Elastic Security is a highly flexible platform that can be implemented anywhere.
What needs improvement?
The setup process is complex. You need a solid working knowledge of networking, operating systems, and a little programming.
For how long have I used the solution?
I have used Elastic Security for three or four months.
What do I think about the stability of the solution?
I rate Elastic Security seven out of 10 for stability. It isn't very stable.
How was the initial setup?
The setup process is highly complex because you need to configure every agent separately and then connect them to each other and the system architecture. It would be difficult for the average user. I had a cybersecurity consultant to help me set up some of the agents. It took about three days to deploy. Maintaining Elastic Search is also challenging.
What other advice do I have?
I rate Elastic Search seven out of 10. I would recommend it for people who are using it to learn about solutions, but I don't think it's capable of doing the work on an enterprise level.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Sales Manager at Spire Solutions
A unified SIEM platform that is supported by a large community of users
Pros and Cons
- "I like that it's a SIEM platform. I like that I can sell Elastic Security quickly. Elastic Security has a large community that can support users."
- "It would be better if Elastic Security had less storage for data. My customers do not like this. Other vendors have local support in different countries, but Elastic Security doesn't. I would like to have Operational Technology (OT) security in the next release."
What is our primary use case?
I sell Elastic Security to my customers. Almost all my customers use the free version, but some use the enterprise version.
What is most valuable?
I like that it's a SIEM platform. I like that I can sell Elastic Security quickly. Elastic Security has a large community that can support users.
What needs improvement?
It would be better if Elastic Security had less storage for data. My customers do not like this. Other vendors have local support in different countries, but Elastic Security doesn't. I would like to have Operational Technology (OT) Security in the next release.
For how long have I used the solution?
I have been working with this Elastic Security for about ten months.
What do I think about the stability of the solution?
Elastic Security is a stable solution. It's the most stable solution I have ever seen.
How was the initial setup?
The initial setup is straightforward. Anyone who knows the basic features can implement this product. Elastic Security has a large community that can support users.
What about the implementation team?
We implement this solution for our customers. We present and demonstrate the POC, and we support them. After the implementation, we provide the provisioning service. Deployment time depends on the business size, but it usually takes about 20 days to a month.
What's my experience with pricing, setup cost, and licensing?
The price is reasonable. It probably costs the same as ArcSight and LogRhythm SIEM. FortiSIEM might cost less than Elastic Security. There are no hidden or additional costs.
What other advice do I have?
This product is better suited for large enterprises. It's one of the best options in the marketplace. I would tell potential users to use all the features because they are already collecting all the logs and data in one place.
On a scale from one to ten, I would give Elastic Security an eight.
Disclosure: My company has a business relationship with this vendor other than being a customer. Distributor
Solutions Consultant at a tech services company with 5,001-10,000 employees
Easy to use and set up with good documentation
Pros and Cons
- "It's very stable and reliable."
- "Their visuals and graphs need to be better."
What is our primary use case?
We are using the solution for log management. We use it for monitoring and observing.
What is most valuable?
Its search engine is great, and it is really quick. In the beginning, we wanted to search through terabytes of log data, and after that, we decided to search using the solution.
The initial setup is very easy.
It can scale well.
It's very stable and reliable.
We use it as an open-source product and do not have to pay for licensing.
There is a lot of good documentation online if you need to troubleshoot. Everything is clear and easy to follow.
What needs improvement?
The solution wasn't designed for monitoring at first. It was for search and stack logs and for working with solutions like Kibana. Therefore, they are a bit weak when compared to traditional monitoring tools.
They should work to improve their integration and graphical interfaces. Their visuals and graphs need to be better. They need better charts. These already exist in Kibana and should be in this solution as well.
For how long have I used the solution?
I've been using the solution for two years.
What do I think about the stability of the solution?
The solution is very stable. There are no bugs or glitches, and it doesn't crash or freeze. it is reliable, and the performance is good. It'd rate the general stability ten out of ten.
What do I think about the scalability of the solution?
We can easily scale up, according to our needs. It's easy to expand.
I'd rate the overall ability to scale up eight out of ten.
How are customer service and support?
They do not have technical support. They have community support and documentation to help with troubleshooting. We've been happy with the amount of detail we can find online if we need assistance.
Which solution did I use previously and why did I switch?
I have not used any other products that are the same. I only use Micro Focus Ops Bridge and SiteScope, which are traditional monitoring tools, so I can't categorize them. They are slow yet they can handle big networks.
How was the initial setup?
The solution is straightforward to set up. They have documentation on their site that shows how to do everything step by step. Everything is very clear and easy to understand. I'd rate the overall ease of implementation nine out of ten.
The deployment is fast and only takes hours, not days.
What about the implementation team?
One person helped me deploy the solution. However, we did not need outside assistance. We did it ourselves.
What's my experience with pricing, setup cost, and licensing?
The solution is open-source and, therefore, free to use.
What other advice do I have?
I'm a partner.
I'd advise others to take advantage of the documentation of the solution in order to get the most out of the product.
In general, I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Buyer's Guide
Download our free Elastic Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: October 2025
Product Categories
Log Management Security Information and Event Management (SIEM) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Fortinet FortiEDR
Datadog
Splunk Enterprise Security
Microsoft Sentinel
SentinelOne Singularity Complete
IBM Security QRadar
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
Trellix Endpoint Security Platform
Elastic Observability
Huntress Managed EDR
Buyer's Guide
Download our free Elastic Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- What are the advantages of ELK over Splunk?
- What would you choose for observability: Grafana observability platform or ELK stack?
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?