Elastic is straightforward, easy to integrate, and highly customizable.
Professional Services Manager at PT Korelasi Persada Indonesia
It's easy to integrate and highly customizable
Pros and Cons
- "Elastic is straightforward, easy to integrate, and highly customizable."
- "The Integration module could be improved. It is a pain to build integration with any product. We have to do parking and so on. It's not like other commercial solutions that use profile integration. I would also see more detection features on the SIEM side."
- "The Integration module could be improved. It is a pain to build integration with any product."
What is most valuable?
What needs improvement?
The Integration module could be improved. It is a pain to build integration with any product. We have to do parking and so on. It's not like other commercial solutions that use profile integration. I would also see more detection features on the SIEM side.
What do I think about the scalability of the solution?
Elastic is easily scalable.
How are customer service and support?
Elastic support is good.
Buyer's Guide
Elastic Security
September 2026
Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
912,006 professionals have used our research since 2012.
How was the initial setup?
Elastic's initial setup is quite straightforward.
What's my experience with pricing, setup cost, and licensing?
Elastic is still priced far less than other commercial products.
What other advice do I have?
I rate Elastic SIEM eight out of 10. Elastic is easy, lightweight, and highly scalable, but you need to be skilled at scripting to use it. If you're going to use the product, you need to ensure your engineers have the scripting ability.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Desarrollador Java Senior Full Stack at Optimissa Capital Markets Consulting
Strong search function improved our speed
Pros and Cons
- "The most valuable feature is the search function, which allows me to go directly to the target to see the specific line a customer is searching for."
- "The price of this product could be improved, especially the additional costs. I would also like to see better-quality graphics."
What is our primary use case?
My primary use case is to check market prices.
How has it helped my organization?
The main benefit of using this solution is that it improves your speed as you don't have to waste time searching for answers.
What is most valuable?
The most valuable feature is the search function, which allows me to go directly to the target to see the specific line a customer is searching for.
What needs improvement?
The price of this product could be improved, especially the additional costs. I would also like to see better-quality graphics.
What do I think about the stability of the solution?
I have found some bugs, but overall the stability is fine.
What do I think about the scalability of the solution?
The scalability is fine.
How are customer service and support?
Technical support is good, they're able to answer all of our questions.
How was the initial setup?
The initial setup wasn't difficult, but that varies depending on the number of servers you have.
What's my experience with pricing, setup cost, and licensing?
This tool is affordable, and its price is ok.
What other advice do I have?
I would rate this solution eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Elastic Security
September 2026
Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
912,006 professionals have used our research since 2012.
AVP, Site Reliability Engineer at a financial services firm with 10,001+ employees
Good monitoring and behavior prediction; troubleshooting tool could be improved
Pros and Cons
- "Enables monitoring of application performance and the ability to predict behaviors."
- "This solution enables us to monitor application performance from Elasticsearch and we can predict some behaviors for applications using ELK."
- "Upgrades currently released as stacks when it should be a plugin or an extension to save removal and reinstallation."
- "I'm not satisfied with technical support because whenever you raise a case, it goes to some random support person who asks questions about the architecture."
What is our primary use case?
Our primary use case of this solution is for application performance monitoring. We are customers of ELK.
What is most valuable?
This solution enables us to monitor application performance from Elasticsearch and we can predict some behaviors for applications using ELK. This product is distributed and scalable which is good for us.
What needs improvement?
The troubleshooting or diagnostic tool can be improved to provide a better understanding of internal behavior and how data is stored. It would also be helpful if they were to release the next version as a plugin or an extension, or as a JAR file, for the latest features. When releasing a new version they currently provide a new stack which means everything needs to be removed before the new version is installed.
For how long have I used the solution?
I've been using this solution for five years.
What do I think about the stability of the solution?
The solution is generally stable, although with each new upgrade there is an adjustment period. They upgrade versions very regularly and it's hard to keep up. By the time my environment is stable with the previous versions, they are already bringing out a new version.
What do I think about the scalability of the solution?
Scalability is very good with this product.
How are customer service and technical support?
I'm not satisfied with technical support because whenever you raise a case, it goes to some random support person who asks questions about the architecture. It's a waste of time. I'm a platinum customer so each time I raise a request, it should go to a dedicated customer support representative who knows my case. It's very difficult when you work in a highly secure environment to get all the logs and send the logs to them each time.
How was the initial setup?
The initial setup is easy, but as you begin using the more advanced features like security and authentication with an AM and LM, then it becomes a bit tricky.
What's my experience with pricing, setup cost, and licensing?
Licensing costs are high, they charge based on the nodes and the RAM. If I purchase a license for a 64GB RAM node and then want to have 128GB RAM, I can't because it's not in the contract so I have to pay on top of that. They removed a feature that allows me to provide multiple disks for one node so if I now want to add an extra disk to the volume, I have to buy a license for one extra node. It's very unfair.
What other advice do I have?
I would recommend this solution for an organization that doesn't require a highly secured environment, because they'll have to deal with the issues of VM upgrades and installations. If it's a highly secured environment like a bank, then I suggest ELK cloud instead of on-prem.
I rate this solution a seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Devops/SRE tech lead at a transportation company with 201-500 employees
Scalable with good logging functionality and good stability
Pros and Cons
- "The solution is quite stable. The performance has been good."
- "The solution has very good logging functionality, the aggregation capability is quite useful, the solution is quite stable, the performance has been good, and the solution scales well."
- "The problem with ELK is it's difficult to administer. When you have a problem, it can be very, very difficult to rebuild indexes."
What is our primary use case?
We do not use monitoring due to the fact that we use Prometheus for monitoring. We don't use APM and so on. We use ELK only for logging.
What is most valuable?
The solution has very good logging functionality.
The aggregation capability is quite useful.
The solution is quite stable. The performance has been good.
The solution scales well.
The solution has gotten easier to deploy since the 2019 version.
What needs improvement?
Using ELK the first time there was a lack of security. We had to buy the paid version due to the fact that we needed to secure access to Kubernetes.
The problem with ELK is it's difficult to administer. When you have a problem, it can be very, very difficult to rebuild indexes. In fact, you have to monitor the stack and it's very, very difficult. Sometimes we lose indexes or we have nothing on the dashboard.
For how long have I used the solution?
I've been using the solution for about two years at this point. It hasn't been an extremely long amount of time.
What do I think about the stability of the solution?
The solution is stable. It's reliable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution can scale. If a company needs to expand it, it can do so pretty easily.
We use the solution for quite a small team. Ten people work on it.
How are customer service and technical support?
Due to the fact that we have a paid version of the product, technical support has been fine. We've been satisfied with the level of service provided to us. They are quite helpful and responsive.
Which solution did I use previously and why did I switch?
Previously, we were on Datadog, Kubernetes Logs. It was not very easy to debug incidents and so on. If I had to compare, I'd say that Datadog is very easy to implement and it's such a fast solution.
How was the initial setup?
The first time, it was very hard to deploy on Kubernetes. However, as we reached version seven, they are now an operator. Now it's very easy to deploy. We no longer have any issues.
What's my experience with pricing, setup cost, and licensing?
The solution is a bit expensive. I don't know the pricing of Datadog, which is what we used to use, however, it's my understanding that it is very expensive also.
What other advice do I have?
We are a customer and an end-user. We do not have a business relationship with ELK.
The solution is deployed on Kubernetes in Azure.
I would advise other companies and users not to mix monitoring and logging. It's not the same purpose. Many people do monitoring by scanning logs. It's not a good idea. The good idea is to monitor separately. In case of incidents, you have to monitor metrics and logins for the root cause. It's important to separate this, and not treat them as the same thing.
I'd rate the solution at an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
DevOps Manager at a tech services company with 11-50 employees
Lacking user interface, not stable, but free to use
Pros and Cons
- "The solution is free."
- "The solution does not have a UI and this is one of the reasons we are looking for another solution."
What needs improvement?
The solution does not have a UI and this is one of the reasons we are looking for another solution.
When setting up some of the pipelines we are receiving different types of log messages with different patterns. When I try to force a certain pattern I need to restart the solution causing a huge inconvenience for us.
For how long have I used the solution?
I have been using the solution for one year.
What do I think about the stability of the solution?
The solution is not stable.
What do I think about the scalability of the solution?
We have approximately 15 users using the solution in my organization.
How was the initial setup?
When doing the installation, the ELK is working well but sometimes when we search for specific words there is no longer any inception throughout. This issue has been difficult to debug or fix.
The index is very important when using this solution. We encountered a couple of issues when we set up the wrong index, it causes everything to go down. That means if we set up something incorrectly with the index, the solution will be down and we do not know why.
What's my experience with pricing, setup cost, and licensing?
The solution is free.
Which other solutions did I evaluate?
We are currently evaluating other solutions to replace this one, such as Datadogs and New Relic. Datadog has a UI that this solution is lacking.
What other advice do I have?
I would not recommend this solution.
I rate ELK Logstash a five out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Tech Engineer at a tech services company with 1,001-5,000 employees
Easy to set up, reasonably priced, and offers good integration
Pros and Cons
- "The cost is reasonable. It's not overly pricey."
- "I would advise others to use this solution as it is relatively low cost and the implementation is quick, giving you results faster."
- "This type of monitoring is not very mature just yet. We need more real-time information in a way that's easier to manage."
- "We find that solutions such as Dynatrace and Datadog offer much more functionality, perhaps due to the fact that they are more mature."
What is our primary use case?
In general, the solution is working together with Open Shift's deployment for the continuous delivery of many projects. This product takes the metrics and checks the log for components that Open Shift deploys. We work with the observation team that monitors the entire company to understand what can be observed and analyzed.
What is most valuable?
The solution is able to handle searches quickly and efficiently. It's much faster than other solutions we've tried. It spends far less time on searches related to capacity and indexing information.
The possibility to stack, locate, and search with your indexing feature at a high rate of speed is its best feature.
It helps that the solution can work together with the infrastructure agents to get the metrics we need.
The integration is quite good.
The initial setup is not difficult. It's easy to set up and customize. It's a strong selling point for the solution.
It's easy to collect the data.
The documentation is big. It's very well documented.
It's working and easy to work with.
The cost is reasonable. It's not overly pricey.
What needs improvement?
This type of monitoring is not very mature just yet. We need more real-time information in a way that's easier to manage.
We need to be able to monitor from any location in the world and any location in the company. We find that solutions such as Dynatrace and Datadog offer much more functionality, perhaps due to the fact that they are more mature.
The solution needs to integrate more AI capabilities, specifically to assist in anomaly detection.
The instrumentation of APM can be enhanced; can be better. It's not automated. It's a very manual process. This ends up being more costly for us. Dynatrace and Datadog are better in this area.
The support on offer could be much better.
For how long have I used the solution?
I've been using the solution for the last six months at this point. It hasn't been an extremely long amount of time just yet.
What do I think about the stability of the solution?
The stability has been pretty good. It's reliable. There aren't bugs or glitches. it doesn't crash or freeze. I'd describe it as 95% stable overall.
What do I think about the scalability of the solution?
We haven't really done any scaling. We only have had an environment with a small cluster on-premises and we can't really test it for scalability. We have no more than four servers for the platform and never really needed to expand anything.
The solution may be used by around 1,000 people in our organization.
How are customer service and technical support?
Technical support could be a lot better. They should offer online chat functionality so that we can get answers to questions right away. It would make troubleshooting a lot faster and less cumbersome.
We've had some troubles, and when we do, we need to open a ticket to get it resolved, which takes some time.
That said, it does offer very good documentation and their knowledge is very good when you do interact with them.
How was the initial setup?
The initial setup is easy. It's not complex or difficult. It's pretty straightforward.
It's very easy to set everything up and configure it on-premises.
The deployment only took an hour or two. We only deployed to one environment. It was pretty fast.
What's my experience with pricing, setup cost, and licensing?
The cost is pretty low. It is not open-source, however.
What other advice do I have?
We are just customers and end-users.
I would advise others to use this solution. It's relatively low cost and the implementation is quick, giving you results faster.
I would rate the solution at an eight out of ten overall.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
VP Platform Engineering at Hydrogen
Free to use, easy to set up, and quite stable
Pros and Cons
- "We've found the initial setup to be quite straightforward."
- "The product in general has come very far and it's gotten a lot better over the years."
- "Sometimes, the solution isn't the easiest to use."
What is our primary use case?
ELK Stack is made up of Elasticsearch, Logstash, and Kibana. What we have is considered modified ELK Stack where instead of the Logstash we use Fluentd, but it serves the same purpose as basically a pipe to get the data into the Elasticsearch.
We primarily use the solution for everything you could think of from error detection to general logging and auditing, to security awareness.
What is most valuable?
Recently I started using some Kibana alerting, which is in the latest versions of Kibana. It's very helpful in general.
You can't beat the price as it is basically free. There are also a lot of features on offer.
We've found the initial setup to be quite straightforward.
The stability is excellent.
What needs improvement?
Sometimes, the solution isn't the easiest to use.
The solution probably doesn't have all of the advanced machine learning like some other SIEM providers have right now. It's something that could be improved upon.
For how long have I used the solution?
I've been using the solution for three or four years at this point. It's been a while.
What do I think about the stability of the solution?
The stability of the solution has been excellent. There are no bugs or glitches. It doesn't crash or freeze. The reliability is very high.
What do I think about the scalability of the solution?
I have no reason to believe this solution wouldn't scale well if a company needed it to. I see no limitations there.
That said, that's a speculative area for us right now. We haven't attempted to scale the product ourselves.
Obviously, Elasticsearch has to do all of its indexing upfront and that might be a scaling concern whereas something like Devo with its just-in-time indexing is pretty darned interesting.
On our end, mostly development staff and operations staff are using it right now. For our organization, everything is going to increase. We're just starting to ramp up usage now.
How are customer service and technical support?
I've never dealt with technical support. I can't speak to how helpful or responsive they are.
How was the initial setup?
The initial setup is not overly complex. It's pretty straightforward. A company shouldn't have any issues with the implementation process overall. Everything in AWS has gotten pretty straightforward.
The maintenance of the solution is minimal. It would only take one person to maintain it.
What's my experience with pricing, setup cost, and licensing?
The price of the product is very good, as it is largely free. There isn't any operating cost. It's basically free software. I'm not aware of any enterprise versions that would cost more. Everything is an AWS service.
What other advice do I have?
We're just customers and end-users. We don't have a business relationship with the company.
We're using the latest version of the solution.
The product in general has come very far. It's gotten a lot better over the years.
I'd recommend the solution to other organizations. I'd advise anyone to try it out.
Overall, I would rate it at an eight out of ten. We've largely been very pleased with the product.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Associate Director - Solutions at a comms service provider with 1,001-5,000 employees
Good indexing of logs, cost-effective, and stable
Pros and Cons
- "I like the indexing of the logs."
- "My advice is that this is a good product to use if you are financially contained, and you want to start with something small."
- "Better integration with third-party APMs would be really good."
What is our primary use case?
We use this solution for the Microsoft deployment of auto-management.
What is most valuable?
I like the indexing of the logs.
For how long have I used the solution?
I have been using ELK Logstash for one year.
What do I think about the stability of the solution?
This product is quite stable and I've not seen any type of issue with it so far.
What do I think about the scalability of the solution?
With respect to scalability, you have to properly plan. Generally, I don't see any issues with scalability.
How are customer service and technical support?
We have not used technical support because we always had talent within the company for end-user support.
Which solution did I use previously and why did I switch?
This was a solution that our client chose, and they were not using a different one prior to this.
How was the initial setup?
I do not think that we had any issues with the deployment. Overall, I would say that the process is of medium complexity.
What about the implementation team?
The support team assisted us with the deployment. I don't think that we had any issues with the team.
What's my experience with pricing, setup cost, and licensing?
Compared to other products such as Dynatrace, this is one of the cheaper options.
Which other solutions did I evaluate?
Our client provided us with this option after they had already been through a selection process.
What other advice do I have?
My advice is that this is a good product to use if you are financially contained, and you want to start with something small. Later, if you need to scale then you can look at other options.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
I.T. Manager at a healthcare company with 51-200 employees
Analyses your security data quickly and effectively
Pros and Cons
- "Just the ability to do a lot more than just up-down is nice, which a lot of people take for granted."
- "Elastic SIEM is pretty stable."
- "The biggest challenge has been related to the implementation."
What is our primary use case?
We plan to use it to analyze the data that we're pumping into it from Active Directory and from firewalls, then we'll pass that information onto our own external SOC.
What is most valuable?
We really haven't had any significant SIEM solutions, so it's all new to us, other than a simple up-down solution. Just the ability to do a lot more than just up-down is nice, which a lot of people take for granted.
What needs improvement?
The biggest challenge has been related to the implementation. It's a very complex product which, without a lot of knowledge or a lot of training, it's very difficult to get into and make use of. They try and make a lot of the general features very simple to access; a lot of the dashboards are very simple to use and so forth, but a lot of the refined capabilities take serious skills. They're not necessarily the easiest to implement.
For how long have I used the solution?
We've been trying to implement it and get it up and going for a good three to four months now.
What do I think about the stability of the solution?
Elastic SIEM is pretty stable. I did have a problem during one of the upgrades, but customer support was able to resolve it for me quickly. Other than that, it's been very reliable and stable.
How are customer service and technical support?
The customer service is great; not a whole lot of back-and-forth going on.
How was the initial setup?
The initial setup was pretty straightforward.
What's my experience with pricing, setup cost, and licensing?
It's a monthly cost with Elastic SIEM, but I am not sure of the exact cost.
What other advice do I have?
In our case, being a medium-sized business, it takes a lot of resources to learn how to properly use and implement it — you need to have a good understanding. They give you a very good framework and a very good solution to work with, but there's a lot of intuition that's required to actually make it work well. It requires a lot more effort than they would lead you to believe or that you would even expect.
On a scale from one to ten, I would give this solution a rating of eight. This is based on my experiences from the past as we're still implementing it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Founder & Chief Executive Officer at a consultancy with 11-50 employees
Has good scalability and is consistently stable
Pros and Cons
- "The feature that we have found the most valuable is scalability."
- "It's quite stable; we have not seen it going down at all for the last three years and it's working well consistently."
- "The process of designing dashboards is a little cumbersome in Kibana. Unless you are an expert, you will not be able to use it. The process should be pretty straightforward. The authentication feature is what we are looking for. We would love to have a central authentication system in the open-source edition without the need for a license or an enterprise license. If they can give at least a simple authentication system within a company. In a large organization, authentication is very essential for security because logs can contain a lot of confidential data. Therefore, an authentication feature for who accesses it should be there."
- "The process of designing dashboards is a little cumbersome in Kibana."
What is our primary use case?
We are using ELK Logstash for application log management and fault detection.
What is most valuable?
The feature that we have found the most valuable is scalability.
What needs improvement?
The process of designing dashboards is a little cumbersome in Kibana. Unless you are an expert, you will not be able to use it. The process should be pretty straightforward.
The authentication feature is what we are looking for. We would love to have a central authentication system in the open-source edition without the need for a license or an enterprise license. If they can give at least a simple authentication system within a company. In a large organization, authentication is very essential for security because logs can contain a lot of confidential data. Therefore, an authentication feature for who accesses it should be there.
For how long have I used the solution?
We have been using ELK Logstash for nearly three years.
What do I think about the stability of the solution?
It's quite stable. We have not seen it going down at all for the last three years. It's working well consistently.
What do I think about the scalability of the solution?
Scalability is very good.
How are customer service and technical support?
We have not taken the technical support at all, so we have been supporting ourselves. We are using the open-source edition, and we are supporting ourselves.
How was the initial setup?
The initial setup was very straightforward for us because we are a software development company. We understand how to compile the source code. We can compile the source code, and we can deploy it. It was pretty straightforward for us.
What other advice do I have?
You should know this solution pretty well. You need to be clear beforehand for what you are going to use this product. This is not something that you can use generally for anything and everything. You should be really clear in terms of your requirements.
I would rate ELK Logstash a nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Buyer's Guide
Download our free Elastic Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Log Management Security Information and Event Management (SIEM) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Cortex XDR by Palo Alto Networks
Microsoft Defender for Endpoint
Datadog
Splunk Enterprise Security
SentinelOne Singularity Endpoint
Dynatrace
Darktrace
IBM Security QRadar
Microsoft Sentinel
Huntress Managed EDR
TrendAI Vision One
Trellix Endpoint Security Platform
Buyer's Guide
Download our free Elastic Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- What are the advantages of ELK over Splunk?
- What would you choose for observability: Grafana observability platform or ELK stack?
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?















