Try our new research platform with insights from 80,000+ expert users
Sr Cloud Data Architect at Sun Cloud LLC
Real User
A flexible product that can be used in a number of scenarios, but its knowledge is quite rare and hard to come by
Pros and Cons
  • "Its flexibility is most valuable. We can have a number of scenarios, and we can get logs from anything. If we know how to use Logstash, we can tweak it in many ways. This makes the logging search on Elastic very easy."
  • "We are paying dearly for the guy who is working on the ELK Stack. That knowledge is quite rare and hard to come by. For difficulty and availability of resources, I would rate it a five out of 10."

What is our primary use case?

It is for our own infrastructure. We are trying to do ELK Stack for everything. We are trying to build our own monitoring solution. For now, we are using it as an alerting solution, and SIEM is going to be our destination.

What is most valuable?

Its flexibility is most valuable. We can have a number of scenarios, and we can get logs from anything. If we know how to use Logstash, we can tweak it in many ways. This makes the logging search on Elastic very easy.

With Kibana, we can make very beautiful dashboards the way we wanted. It makes sense for the business.

What needs improvement?

We are paying dearly for the guy who is working on the ELK Stack. That knowledge is quite rare and hard to come by. For difficulty and availability of resources, I would rate it a five out of 10.

What do I think about the scalability of the solution?

We don't have any scalability problems as of now. We have less than 2,000 devices.

Buyer's Guide
Elastic Security
January 2025
Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.

What about the implementation team?

We have a contractor who is trying to develop and deploy the ELK Stack for us. He has requested a couple of servers, and we have given those to him. He asked for more RAM and storage for the service, and he will take time developing the custom Logstash scripts that we have asked for.

What's my experience with pricing, setup cost, and licensing?

I find it better than Splunk in terms of cost-effectiveness. For cost-effectiveness, I would rate it a nine out of 10.

What other advice do I have?

It is complex, but you just need to have patience and personnel to develop it. Unless you explore a technology, you won't know what are the pros and cons. I have not seen any cons as of now, but it has miles to go in terms of being equal to Splunk. It is a community-driven technology. So, it will get there.

I would rate this solution a seven out of 10.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Vikas Dusa - PeerSpot reviewer
Cyber Security Trainer and Programmer at Freelancer
Real User
Top 5Leaderboard
Traces ransomware and manages threat scenarios
Pros and Cons
    • "Improvements in Elastic Security could include refining and normalizing queries to make them more user-friendly, enhancing the user experience with better documentation, and addressing any latency issues."

    What is our primary use case?

    My use case for the product revolved around conducting demonstrations and testing. It also helped me with tracing ransomware and managing threat scenarios.

    What is most valuable?

    The integration with Siemens Endpoint Security in Elastic Security has been beneficial for security. The provided rules are good, making it easy to create and understand rules. Patterns and detections are made through index patterns, requiring some follow-up steps.

    In real-time, the impact of Elastic Security on ransomware is significant. For known and repeated ransomware, it can detect and prevent effectively using established signatures and behavioral patterns. However, for new types of ransomware with less complex behaviors or those that modify files minimally, conventional detection methods may struggle. Elastic Security proves to be effective even in challenging cases.

    On the cloud, it allows testing of SaaS-based applications, performance evaluations using CDMs and APIs, incident detection within company network infrastructures, and comprehensive management of security services.

    What needs improvement?

    Improvements in Elastic Security could include refining and normalizing queries to make them more user-friendly, enhancing the user experience with better documentation, and addressing any latency issues.

    For how long have I used the solution?

    I have utilized Elastic Security for approximately three to four months.

    What do I think about the stability of the solution?

    I rate the product’s stability an eight out of ten.

    What do I think about the scalability of the solution?

    Scaling Elastic Security is relatively easy, with a rating of seven out of ten.

    How was the initial setup?

    The tool's deployment is straightforward. 

    What other advice do I have?

    I rate the overall product an eight out of ten.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Elastic Security
    January 2025
    Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
    831,158 professionals have used our research since 2012.
    HamadaElewa - PeerSpot reviewer
    Technical Sales Manager at Spire Solutions
    Reseller
    Top 5Leaderboard
    A unified SIEM platform that is supported by a large community of users
    Pros and Cons
    • "I like that it's a SIEM platform. I like that I can sell Elastic Security quickly. Elastic Security has a large community that can support users."
    • "It would be better if Elastic Security had less storage for data. My customers do not like this. Other vendors have local support in different countries, but Elastic Security doesn't. I would like to have Operational Technology (OT) security in the next release."

    What is our primary use case?

    I sell Elastic Security to my customers. Almost all my customers use the free version, but some use the enterprise version.

    What is most valuable?

    I like that it's a SIEM platform. I like that I can sell Elastic Security quickly. Elastic Security has a large community that can support users.

    What needs improvement?

    It would be better if Elastic Security had less storage for data. My customers do not like this. Other vendors have local support in different countries, but Elastic Security doesn't. I would like to have Operational Technology (OT) Security in the next release.

    For how long have I used the solution?

    I have been working with this Elastic Security for about ten months.

    What do I think about the stability of the solution?

    Elastic Security is a stable solution. It's the most stable solution I have ever seen.

    How was the initial setup?

    The initial setup is straightforward. Anyone who knows the basic features can implement this product. Elastic Security has a large community that can support users.

    What about the implementation team?

    We implement this solution for our customers. We present and demonstrate the POC, and we support them. After the implementation, we provide the provisioning service. Deployment time depends on the business size, but it usually takes about 20 days to a month. 

    What's my experience with pricing, setup cost, and licensing?

    The price is reasonable. It probably costs the same as ArcSight and LogRhythm SIEM. FortiSIEM might cost less than Elastic Security. There are no hidden or additional costs.

    What other advice do I have?

    This product is better suited for large enterprises. It's one of the best options in the marketplace. I would tell potential users to use all the features because they are already collecting all the logs and data in one place.

    On a scale from one to ten, I would give Elastic Security an eight.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor
    PeerSpot user
    Giuseppe Ragazzini - PeerSpot reviewer
    Project Delivery Manager at Spindox
    Real User
    A good SIEM solution but doesn't have as many features as its competitors
    Pros and Cons
    • "It's not very complicated to install Elastic."
    • "With Elastic, you have to build the use cases for the specific requirement. Other products have a simple integration and more use cases to integrate out-of-the-box solutions for SIEM."

    What is our primary use case?

    I worked for a telco client for the security model of Elastic, but my role was unit manager. I don't have a lot of technical expertise, but I decided on the solution for a client, and I was responsible for the delivery.

    I worked with the security of the mobile app. I see all the logs in Elastic for SIEM. I monitored the logging and some logs from the machine for a UNIX system with some use cases like the machine's file system.

    This solution is deployed on-premise.

    We provide this solution to our customers, which are telcos, in the finance industry, and in retail.

    What is most valuable?

    I think that it's a good solution for a SIEM.

    What needs improvement?

    Elastic doesn't have the features like other competitors in SIEM. For example, Dynatrace as a solution for SIEM has features that Elastic actually don't have.

    With Elastic, you have to build the use cases for the specific requirement. Other products have a simple integration and more use cases to integrate out-of-the-box solutions for SIEM. That's the improvement I would like to see.

    What do I think about the stability of the solution?

    The product is stable.

    Which solution did I use previously and why did I switch?

    Other products like Splunk are better than Elastic for a SIEM because there are some use cases already available for a client. Elastic doesn't have this, so the user must build the SIEM solution. I think that Elastic has to increase the features for the SIEM.

    How was the initial setup?

    It's not very complicated to install Elastic, but I didn't deploy it.

    What other advice do I have?

    I would rate this solution 7 out of 10.

    It's a good solution and I would recommend it, but there are other products that have more features that Elastic doesn't have.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    Chief Operating Officer / SR. Project Manager at SCS
    Real User
    A flexible, cost-effective, and reliable solution
    Pros and Cons
    • "One of the most valuable features of this solution is that it is more flexible than AlienVault."
    • "It is difficult to anticipate and understand the space utilization, so more clarity there would be great."

    What is our primary use case?

    We use it as a SIEM for monitoring a client's environment.

    What is most valuable?

    One of the most valuable features of this solution is that it is more flexible than AlienVault. 

    What needs improvement?

    It is difficult to anticipate and understand the space utilization, so more clarity there would be great.

    For how long have I used the solution?

    My company has been using this solution for two years.

    What do I think about the stability of the solution?

    It is a very stable solution.

    What do I think about the scalability of the solution?

    The solution is very scalable.

    How are customer service and support?

    The technical support is adequate.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    We currently use AlienVault for some clients and Elastic Security for others. We chose Elastic Security because we felt it was the most flexible, cost-effective solution to provide the results needed.

    How was the initial setup?

    In certain respects, the setup of this solution is more straightforward than other solutions, but in other respects, it's more complex because it needs more fine-tuning than Splunk or AlienVault.

    What about the implementation team?

    We implemented through an in-house team and it took about two months.

    What's my experience with pricing, setup cost, and licensing?

    The licensing cost depends on the size of the environment it's monitoring. Everything is based on volume, as with all SIEMs. When compared to other products, the price is average or on the low side.

    Which other solutions did I evaluate?

    We evaluated several options, including Monster SIEM, Splunk, and Wazuh.

    What other advice do I have?

    There's a lot of fine-tuning involved with this solution. When you go to a diner, and the menu has everything on it, and you can't figure out which part to look at first, it's a double-edged sword. You can do everything with this solution, which means you have to figure out which part of "everything" makes sense for your company to do.

    I would rate this solution as an eight out of ten. It's a good value for money and a  reliable solution, but it's heavily reliant on appropriate configuration.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer1363986 - PeerSpot reviewer
    IT at a tech vendor with 10,001+ employees
    Real User
    Easy to set up with a helpful community and a good dashboard tutor
    Pros and Cons
    • "The solution has a good community surrounding it for lots of helpful documentation for troubleshooting purposes."
    • "The solution needs to be more reactive to investigations. We need to be able to detect and prevent any attacks before it can damage our infrastructure. Currently, this solution doesn't offer that."

    What is our primary use case?

    We primarily use the solution to have a correlation on all the Windows event logs. We use it more for forensic purposes now. We are looking for something which will be a more proactive product for us and be able to detect any threats and take automatic action.

    What is most valuable?

    All of the features on the solution are useful due to the fact that I have the full Stack, therefore I can collect and then visualize. We have the dashboard tutor as well.

    The solution has a good community surrounding it for lots of helpful documentation for troubleshooting purposes.

    What needs improvement?

    The solution is lacking some features of AI and machine learning. There may be a feature out there we are not using or maybe it's on a different solution, however, having more AI would be so helpful for us.

    The solution needs to be more reactive to investigations. We need to be able to detect and prevent any attacks before it can damage our infrastructure. Currently, this solution doesn't offer that.

    I know there are some features which are coming, and which is already available. To be honest, I haven't had any time to play around and check what could be the advantages of them. Compared to other products, already the features available - and there are lots of things which are provided - are quite useful. We are not managing it. We're only using it. For us, if we had the technical skills to manage the solution, we might be able to see and understand a few features that we're not already taking advantage of.

    For how long have I used the solution?

    I've been using the solution for three years.

    What do I think about the scalability of the solution?

    The solution is scalable for us now, although it didn't start that way.

    We have about 50 users between SecOps and the Microsoft team. The network team of between 50 and 100 people are using it on a regular basis.

    How are customer service and technical support?

    I never had to be in contact with technical support. I mainly rely on the communities around the solution and that is where I find almost all of the information I need. They're great. There's lots of information available that helps you troubleshoot issues.

    Which solution did I use previously and why did I switch?

    We previously used a product from Quest Software called Change Auditor. We actually didn't switch off this solution. We use both Quest and ELK in our organization.

    The main difference is that one you have to pay for, while the other one is much cheaper and if you don't need all the features, you can use it for free.

    ELK has much more information, as well. You can grab much more information with ELK than you can with Change Auditor, without adding any additional modules.

    How was the initial setup?

    The initial setup as I recall was pretty easy. However, I moved to an infrastructure that had a connection to a second ELK instance that I am not managing.

    The settings on that instance are more complex than my initial setup. 

    I am not a specialist in big data infrastructure. I am a process engineer. You need some dedicated and well-trained people as soon as you have a large infrastructure and you are sending a lot of events to the elastic instance so that it is performed correctly. That's always the challenge you have with on-premise infrastructure.

    What's my experience with pricing, setup cost, and licensing?

    I'm not sure how much the company pays to use ELK. It's not part of the job that I handle.

    What other advice do I have?

    We're ELK customers. Mostly I'm a specialist on the infrastructure of the solution.

    The solution is perfect as long as you are using it for forensics. In terms of threat detection, it could be better. There could be another product that is more appropriate for that aspect.

    I'd rate the solution eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer2198715 - PeerSpot reviewer
    DevOps Engineer at a tech services company with 51-200 employees
    Real User
    Top 5
    Efficiently handle millions of loads simultaneously
    Pros and Cons
    • "It can handle millions of loads at a time, and you can always use the filters to find exactly what you are looking for and detect errors in every log message you are searching for, basically."
    • "There is an area of improvement in the Logs list. The load list may need to be paginated as there are limits."

    What is our primary use case?

    We are using Elastic Security for logging the application logs, as we use a microservice architecture. So all application logs are saved to this LogSpot.

    How has it helped my organization?

    It helps us detect errors and keep an eye on the application in both the development and production environments.

    What is most valuable?

    It can handle millions of loads at a time, and you can always use the filters to find exactly what you are looking for and detect errors in every log message you are searching for, basically.

    What needs improvement?

    There is an area of improvement in the Logs list. The load list may need to be paginated as there are limits. So if you are looking for logs for a specific application, you may get 50 lines of logs, but then you are lost. You need to add more features to specify your request so you can get the final result. It would be better to have additional features to specify your request and get the complete result.

    For how long have I used the solution?

    I have been using this solution for nine months. Although, I am not using the latest version. 

    What do I think about the stability of the solution?

    I would rate the stability a nine out of ten. 

    What do I think about the scalability of the solution?

    I would rate the scalability an eight out of ten. 

    What was our ROI?

    We definitely saw an ROI. It quickly finds the bugs.

    What other advice do I have?

    I would recommend using it, especially if you have a microservice architecture. I also have a friend who has been using it for some big data projects, so I would recommend it for that as well. 

    Overall, I would rate the solution a nine out of ten. 

    Which deployment model are you using for this solution?

    Private Cloud
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer2125281 - PeerSpot reviewer
    Intern Cybersecurity at a computer software company with 10,001+ employees
    Real User
    Top 10
    It's a highly flexible platform you can implement anywhere, but the setup is complex and difficult
    Pros and Cons
    • "Elastic Security is a highly flexible platform that can be implemented anywhere."
    • "The setup process is complex. You need a solid working knowledge of networking, operating systems, and a little programming."

    What is our primary use case?

    I use Elastic Search to collect logs from an Active Directory server and forward the incidents to the SOAR solution.

    What is most valuable?

    Elastic Security is a highly flexible platform that can be implemented anywhere. 

    What needs improvement?

    The setup process is complex. You need a solid working knowledge of networking, operating systems, and a little programming. 

    For how long have I used the solution?

    I have used Elastic Security for three or four months.

    What do I think about the stability of the solution?

    I rate Elastic Security seven out of 10 for stability. It isn't very stable. 

    How was the initial setup?

    The setup process is highly complex because you need to configure every agent separately and then connect them to each other and the system architecture. It would be difficult for the average user. I had a cybersecurity consultant to help me set up some of the agents. It took about three days to deploy. Maintaining Elastic Search is also challenging.

    What other advice do I have?

    I rate Elastic Search seven out of 10. I would recommend it for people who are using it to learn about solutions, but I don't think it's capable of doing the work on an enterprise level. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free Elastic Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: January 2025
    Buyer's Guide
    Download our free Elastic Security Report and get advice and tips from experienced pros sharing their opinions.