Our use case for Elastic Security is for log management and security information for the management team.
Presales Solutions Architect (Cyber Security) at a tech services company with 11-50 employees
Offers scalability and useful log management, but faces challenges in alert management
Pros and Cons
- "The most valuable feature is the scalability. We are in Indonesia, more engineers understand Elastic Security here. So it is easier to scale and also develop. In features, the discovery to query all the logs is very important to us. It is very easy, especially with the query function and the feature to generate alerts and create tools. Sometimes we use the alert security dashboard to monitor our clients."
- "I think because we are a cybersecurity company, the thing that can be improved is the prebuilt tools, especially quality. Compared to its competitor, they still have fewer prebuilt security rules. Elastic Security, in terms of generating alerts, cannot group the same products into one another. Even though the alerts are the same, they still generate them one by one. So, it is very noisy in our dashboard. I would like the Elastic Security admin to group all the same alarms into one alarm so that our dashboard is not noisy."
What is our primary use case?
What is most valuable?
The most valuable feature is the scalability. We are in Indonesia, more engineers understand Elastic Security here. So it is easier to scale and also develop. In features, the discovery to query all the logs is very important to us. It is very easy, especially with the query function and the feature to generate alerts and create tools. Sometimes we use the alert security dashboard to monitor our clients.
What needs improvement?
I think because we are a cybersecurity company, the thing that can be improved is the prebuilt tools, especially quality. Compared to its competitor, they still have fewer prebuilt security rules. Elastic Security, in terms of generating alerts, cannot group the same products into one another. Even though the alerts are the same, they still generate them one by one. So, it is very noisy in our dashboard. I would like the Elastic Security admin to group all the same alarms into one alarm so that our dashboard is not noisy.
For how long have I used the solution?
I have been working with Elastic Security for around one or two years in my current company.
Buyer's Guide
Elastic Security
January 2025
Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
What do I think about the stability of the solution?
I would rate the stability of the solution a seven out of ten and there are a lot of glitches.
What do I think about the scalability of the solution?
Elastic Security has very good scalability.
How are customer service and support?
I have had no direct communication with the support team but my technical team says that they are not helpful.
How would you rate customer service and support?
Neutral
How was the initial setup?
The setup process is very complex if you are new to it. But if you already understand how Elastic Security works and how the architect works, I think it is quite simple.
What's my experience with pricing, setup cost, and licensing?
The pricing is in the middle. I think it is not an expensive experience if we compare it with big names, for example, QRadar, and also Oxide. I think Elastic Security is quite cheap. I would rate the pricing of this solution a five out of ten.
What other advice do I have?
I think they are doing a pretty good job in terms of the user interface and also the user experience. I think in terms of the basic features and also the user experience, it is enough for us to support our daily operations.
Overall, I would rate the solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Principal Cyber Security Manager at Ask4key
Valuable prevention methods and asset alerts, but room for improvement in the Kibana dashboard and asset management
Pros and Cons
- "The most valuable features of the solution are the prevention methods and the incident alerts."
- "There is room for improvement in the Kibana dashboard and in the asset management for the program."
What is our primary use case?
My clients use this solution for security purposes and SIEM and log management.
What is most valuable?
The most valuable features of the solution are the prevention methods and the incident alerts.
What needs improvement?
There is room for improvement in the Kibana dashboard and in the asset management for the program.
For how long have I used the solution?
I've been working with Elastic Security for almost two years now.
What do I think about the stability of the solution?
The solution is stable if you don't touch it too much. Meaning, it's technically stable, but if there is a period of downtime, you will face quite a big hiccup in getting it running again and stabilized.
What do I think about the scalability of the solution?
The scalability of Elastic is amazing.
How are customer service and support?
I would say the technical support isn't really good or bad. On a scale of one to ten, I would give it a five.
How would you rate customer service and support?
Neutral
How was the initial setup?
The setup can sometimes be quite complex for the backend team. It all depends on the client's environment, so we have to be flexible.
What about the implementation team?
My company provides a team for deployment, which usually consists of at least three or four engineers. Deployment generally takes six months to one year.
What was our ROI?
I would say that, on average, a good ROI can be seen within one and a half to two years after deploying Elastic Security.
What's my experience with pricing, setup cost, and licensing?
Licensing for the solution is available as a one-year or three-year plan, and all of the features are included.
What other advice do I have?
I would rate this solution as a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Elastic Security
January 2025
Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
Senior Manager Analytics at a financial services firm with 501-1,000 employees
A simple and easy-to-use solution for IT monitoring and anomaly detection
Pros and Cons
- "It's simple and easy to use."
- "This solution cannot do predictive maintenance, so we have to build our own modules for doing it."
What is our primary use case?
The primary use case of this solution is for IT monitoring, predictive maintenance, and anomaly detection.
What is most valuable?
It's simple and easy to use.
What needs improvement?
This solution cannot do predictive maintenance, so we have to build our own modules for doing it.
It doesn't do advanced analytics. They should have some advance analytics in this solution.
With Kibana, we wanted it to be easier to use. The data visualization is there but it should be easier to use.
Also, they should start proving APIs for doing ML and AI.
For how long have I used the solution?
I have been using this solution for two months.
What do I think about the stability of the solution?
This solution is stable and so far, we have had no issues.
What do I think about the scalability of the solution?
The scalability is very good. We are running it on an eight-node machine so far, and with eight nodes we have had no issues.
How are customer service and technical support?
We haven't contacted support. They do have the support and we have spoken with them over email. We might need their assistance next month.
What other advice do I have?
Anyone who wants to do IT log monitoring, realtime and who wants to do the anomaly detection, should go with this solution.
So far from what we have seen, I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Works at a comms service provider with 51-200 employees
Good visualization, but more automation is needed
Pros and Cons
- "The visualization is very good."
- "There are connectors to gather logs for Windows PCs and Linux PCs, but if we have to get the logs from Syslog then we have to do it manually, and this should be automated."
What is our primary use case?
We are a service provider, and use this solution to work with our customers.
We use this solution for collecting firewall logs and then supplying them to the log analyzer.
We are running Fortinet FortiGate for our firewall, and these are the logs that we are analyzing. Normally, we have a problem with the visualization part.
How has it helped my organization?
This solution helps us because we can find all of the logs in one place. We can easily find a specific log in a specific time period.
What is most valuable?
The visualization is very good.
What needs improvement?
There are connectors to gather logs for Windows PCs and Linux PCs, but if we have to get the logs from Syslog then we have to do it manually, and this should be automated.
It would be good if I could get technical support for specific devices. I think that Windows should have some specific connectors. When we implemented a new product, we had to create it manually.
What do I think about the stability of the solution?
The stability of this solution is fine.
What do I think about the scalability of the solution?
This solution is scalable.
We have approximately two hundred users and we do not plan to increase usage at this time.
How are customer service and technical support?
We had not contacted technical support for this solution.
Which solution did I use previously and why did I switch?
We have used other SIEM solutions in our company.
How was the initial setup?
On week is enough for the deployment.
What about the implementation team?
We performed the integration ourselves.
What's my experience with pricing, setup cost, and licensing?
We are using the free, open-source version of this solution.
Which other solutions did I evaluate?
We did not evaluate other options before choosing this solution.
What other advice do I have?
We are interested in learning more about plugins for specific firewalls or other products.
The only problem with this solution is the development part, where we have to do it manually.
I would rate this solution a six out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Tech Engineer at a tech services company with 1,001-5,000 employees
Easy to set up, reasonably priced, and offers good integration
Pros and Cons
- "The cost is reasonable. It's not overly pricey."
- "This type of monitoring is not very mature just yet. We need more real-time information in a way that's easier to manage."
What is our primary use case?
In general, the solution is working together with Open Shift's deployment for the continuous delivery of many projects. This product takes the metrics and checks the log for components that Open Shift deploys. We work with the observation team that monitors the entire company to understand what can be observed and analyzed.
What is most valuable?
The solution is able to handle searches quickly and efficiently. It's much faster than other solutions we've tried. It spends far less time on searches related to capacity and indexing information.
The possibility to stack, locate, and search with your indexing feature at a high rate of speed is its best feature.
It helps that the solution can work together with the infrastructure agents to get the metrics we need.
The integration is quite good.
The initial setup is not difficult. It's easy to set up and customize. It's a strong selling point for the solution.
It's easy to collect the data.
The documentation is big. It's very well documented.
It's working and easy to work with.
The cost is reasonable. It's not overly pricey.
What needs improvement?
This type of monitoring is not very mature just yet. We need more real-time information in a way that's easier to manage.
We need to be able to monitor from any location in the world and any location in the company. We find that solutions such as Dynatrace and Datadog offer much more functionality, perhaps due to the fact that they are more mature.
The solution needs to integrate more AI capabilities, specifically to assist in anomaly detection.
The instrumentation of APM can be enhanced; can be better. It's not automated. It's a very manual process. This ends up being more costly for us. Dynatrace and Datadog are better in this area.
The support on offer could be much better.
For how long have I used the solution?
I've been using the solution for the last six months at this point. It hasn't been an extremely long amount of time just yet.
What do I think about the stability of the solution?
The stability has been pretty good. It's reliable. There aren't bugs or glitches. it doesn't crash or freeze. I'd describe it as 95% stable overall.
What do I think about the scalability of the solution?
We haven't really done any scaling. We only have had an environment with a small cluster on-premises and we can't really test it for scalability. We have no more than four servers for the platform and never really needed to expand anything.
The solution may be used by around 1,000 people in our organization.
How are customer service and technical support?
Technical support could be a lot better. They should offer online chat functionality so that we can get answers to questions right away. It would make troubleshooting a lot faster and less cumbersome.
We've had some troubles, and when we do, we need to open a ticket to get it resolved, which takes some time.
That said, it does offer very good documentation and their knowledge is very good when you do interact with them.
How was the initial setup?
The initial setup is easy. It's not complex or difficult. It's pretty straightforward.
It's very easy to set everything up and configure it on-premises.
The deployment only took an hour or two. We only deployed to one environment. It was pretty fast.
What's my experience with pricing, setup cost, and licensing?
The cost is pretty low. It is not open-source, however.
What other advice do I have?
We are just customers and end-users.
I would advise others to use this solution. It's relatively low cost and the implementation is quick, giving you results faster.
I would rate the solution at an eight out of ten overall.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Desarrollador Java Senior Full Stack at Optimissa Capital Markets Consulting
Strong search function improved our speed
Pros and Cons
- "The most valuable feature is the search function, which allows me to go directly to the target to see the specific line a customer is searching for."
- "The price of this product could be improved, especially the additional costs. I would also like to see better-quality graphics."
What is our primary use case?
My primary use case is to check market prices.
How has it helped my organization?
The main benefit of using this solution is that it improves your speed as you don't have to waste time searching for answers.
What is most valuable?
The most valuable feature is the search function, which allows me to go directly to the target to see the specific line a customer is searching for.
What needs improvement?
The price of this product could be improved, especially the additional costs. I would also like to see better-quality graphics.
What do I think about the stability of the solution?
I have found some bugs, but overall the stability is fine.
What do I think about the scalability of the solution?
The scalability is fine.
How are customer service and support?
Technical support is good, they're able to answer all of our questions.
How was the initial setup?
The initial setup wasn't difficult, but that varies depending on the number of servers you have.
What's my experience with pricing, setup cost, and licensing?
This tool is affordable, and its price is ok.
What other advice do I have?
I would rate this solution eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Associate Delivery Lead at a tech services company with 1,001-5,000 employees
Fast, easy and offers easy infrastructure monitoring abilities
Pros and Cons
- "ELK Logstash is easy and fast, at least for the initial setup with the out of box uses."
- "In terms of what could be improved with Elastic, in some use cases, especially on the advanced level, they are not ready made, so you'll have to write some scripts."
What is our primary use case?
The primary use cases are for infrastructure monitoring networks, security analytics, and SIEM.
We are evaluating it for business analytics as well.
What is most valuable?
The feature that I have found most valuable is the infrastructure monitoring part because it is quite easy. If you want to get up and running, we could create use cases in four to five days. So the initial infrastructure for simple analytics is quite easy.
ELK Logstash is easy and fast, at least for the initial setup with the out of box uses. I'm not talking about advanced use cases, but the basic ones are quite easy to configure.
What needs improvement?
In terms of what could be improved with Elastic, in some use cases, especially on the advanced level, they are not ready-made, so you'll have to write some scripts. This is the case, especially with a trade. If you are comparing it with a SIEM tool, you don't have ready-made use cases.
I would say that to have a better place in the market they should have more built-in use cases so that rather than people creating them, the prime uses had inbuilt use cases. It could even include more templates or automation.
For how long have I used the solution?
I have been using this solution almost 10 - 11 months.
What do I think about the stability of the solution?
In terms of stability, as a starting point with simple use cases, it's quite easy and fast to deploy.
What do I think about the scalability of the solution?
In terms of assessing its scalability, we have not gone with a very huge amount of data yet so it is early to comment on that. We started with three node architecture and I think slowly we'll scale up.
It is suitable for small to large businesses. We have started small but we plan to scale it up.
Currently, we are using the solution between 16 and 24 hours a day, 7 days a week for live monitoring.
How are customer service and technical support?
We have been in touch with support and raised tickets a couple of times, especially when we get stuck with respect to some advanced level issues.
Sometimes the reply has been quite fast and sometimes it has taken maybe 24 to 48 hours. They could definitely improve a bit on their support.
How was the initial setup?
We have done both setups, on-premise as well as on AWS.
The installation is quite okay. We have done three or four installations and it's fine. We have deployed on Windows as well as on Linux platforms.
I don't get involved in the installation, but I have a small team who does it and based on their experience, we have installed in one day.
The installation of full-frame solutions is quite smooth.
What about the implementation team?
We implement it ourselves in-house. We have a technical team that does it. We can refer to blogs in case we get stuck, but so far it's been smooth.
If you have a basically knowledgeable person, even without a lot of experience, as we had on our team, people with only two months' experience, they have been able to do it quite well in a day or two.
Which other solutions did I evaluate?
Until now, we have not evaluated the Elastic cloud version, which is the fast kind of solution. But we have deployed the on-premise as well as the AWS options.
What other advice do I have?
Based on my experience, it's quite easy and manageable with small scale implementations, and the time to market is quite fast. I can have good monitoring with a couple of use cases set up in less than four weeks.
In terms of other advice, it depends what I am looking for. Am I looking at this as a platform or for a specific use case? If I see it as a platform, I would definitely say it's a good platform to work on. In that case, I would rate it an eight on a scale of one to ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Former CISO | Cyber Security Enthusiast at a tech services company with 51-200 employees
The system intelligence gives you good detail for creating intelligence reports
Pros and Cons
- "The intelligence of the system has been very impressive. It's not quite AI, but the technical bit where it correlates information, based on the seen attacks within an organization is good."
- "The solution could also use better dashboards. They need to be more graphical, more matrix-like."
What is most valuable?
The intelligence of the system has been very impressive. It's not quite AI, but the technical bit where it correlates information, based on the attacks within an organization is good. The intelligence bit that it gathers from within itself is really good. It's pretty accurate and gives you good details to create an intelligence report and present that to your C-level management.
What needs improvement?
I think user interface could be improved. They should introduce a hybrid model, because for now, Endgame is purely on premises. They do not have a full-blown model. They don't market themselves that way, which is why customers lose out on a lot of information. They don't know if the product is worth the trial or not because it's an organization that is going completely in the direction of digital transformation on the cloud and then Endgame's automatically removed as an option for them. They wouldn't even know Endgame goes on the cloud, because the company does not market it.
The solution could also use better dashboards. They need to be more graphical, more matrix-like.
For how long have I used the solution?
I've been using the solution for a few months.
What do I think about the stability of the solution?
The solution is pretty stable.
What do I think about the scalability of the solution?
I don't think I can comment on the scalability, because it wasn't in my use case. I was the only primary user; I was testing it because I was testing it against a competitor.
How are customer service and technical support?
I haven't had to reach out to technical support.
How was the initial setup?
The initial setup was a little complex.
What about the implementation team?
We used a deployment consultant, but I installed it on my own.
What other advice do I have?
It works well offline. It works on the cloud as well, but I doubt that it has 100% capability as it does on-premise. There's a difference. Endgame works very well when it's not connected to the internet as well. For example, if it's installed on a computer and the person's out on the road, it's still going to protect. Go through a good assessment of the Endpoint from an Endpoint security assessment methodology perspective.
I would rate this solution 7.5 out of 10 because I know of a solution that does better.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Elastic Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Log Management Security Information and Event Management (SIEM) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Extended Detection and Response (XDR)Popular Comparisons
Splunk Enterprise Security
Datadog
IBM Security QRadar
Elastic Observability
Graylog
LogRhythm SIEM
Sumo Logic Security
Security Onion
Fortinet FortiAnalyzer
syslog-ng
Elastic Stack
Google Cloud's operations suite (formerly Stackdriver)
SolarWinds Kiwi Syslog Server
USM Anywhere
Buyer's Guide
Download our free Elastic Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- What are the advantages of ELK over Splunk?
- What would you choose for observability: Grafana observability platform or ELK stack?
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?