No more typing reviews! Try our Samantha, our new voice AI agent.

Elastic Observability vs Security Onion comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Elastic Observability
Ranking in Log Management
14th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
29
Ranking in other categories
Application Performance Monitoring (APM) and Observability (10th), IT Infrastructure Monitoring (13th), Container Monitoring (6th), Cloud Monitoring Software (11th)
Security Onion
Ranking in Log Management
22nd
Average Rating
7.8
Reviews Sentiment
7.2
Number of Reviews
4
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Log Management category, the mindshare of Elastic Observability is 1.3%, down from 1.3% compared to the previous year. The mindshare of Security Onion is 1.7%, down from 4.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
Elastic Observability1.3%
Security Onion1.7%
Other97.0%
Log Management
 

Featured Reviews

Stefan Decuypere - PeerSpot reviewer
Technology Consultant at Hybrid software
Real-time dashboards and visual insights have streamlined issue analysis and monitoring
After careful consideration about areas for improvement in Elastic Observability, aspects such as pricing, customization, implementation, and scalability could be improved. As a user of the system, I know what it costs but am not directly involved in cost-benefit evaluations or maintenance, which is handled by another team. I develop the visual representation of the data and frankly, I don't see major gaps in my application or anything I would really miss; I appreciate the fast pace of the developments that have occurred in the last couple of years. Regarding room for improvement in Elastic Observability, I would have preferred built-in tools to manage the indexes on deployment for better visual representation, as the initial feedback regarding system performance and data storage was fairly primitive and lacking.
Hiten Nandasana - PeerSpot reviewer
Angular developer at Flourish software
Centralized monitoring has strengthened threat detection and supports faster incident investigations
Security Onion is a completely open-source and free platform, making it a cost-effective solution that works smoothly and effectively for our organization. Security Onion integrates well with our existing tools, primarily using Linux systems in our organization, allowing us to monitor logs and manage threat detection and operations in the public cloud effectively. Security Onion is very helpful in meeting compliance requirements and supports regular standards for our environment. I advise organizations that use Linux or have network security knowledge to consider Security Onion, as it satisfies requirements such as threat detection and log management systems. I would rate this review eight out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its diverse set of features available on the cloud is of significant importance."
"The customizable dashboards in Elastic Observability allow us to group relevant data to specific aspects of our solution, giving us around 20 interlinked dashboards which provide an overview, and if one aspect shows weird behavior, we can focus on that specific aspect of our software with a dedicated dashboard."
"For full stack observability, Elastic is the best tool compared with any other tool like New Relic or AppDynamics or Dynatrace."
"Elastic APM has plenty of features, such as the Elastic server for Kibana and many additional plugins. It's a comprehensive tool when used as a logging platform."
"All the features that we use, such as monitoring, dashboarding, reporting, the possibility of alerting, and the way we index the data, are important."
"The solution allows us to track performance via metrics and we're able to see where latency is happening."
"The tool's most valuable feature is centralized logging. Elastic Common Search helps us to search for the logs across the organization."
"Elastic Observability is highly stable; we ingested nearly 170 million records in the system and we have tested it, and you get your reports and dashboards within a few seconds, so it doesn't take much time."
"The most valuable feature of Security Onion for security monitoring is its ability to find infected ports."
"We use Security Onion for internal vulnerability assessment."
"Security Onion is the most mature solution in the market."
"Security Onion is a completely open-source and free platform, making it a cost-effective solution that works smoothly and effectively for our organization."
 

Cons

"More web features could be added to the product."
"It lacked some capabilities when handling on-prem devices, like network observability, package flow analysis, and device performance data on the infrastructure side."
"When I go to the portal, I do not see many insights on the endpoints or where there could be latencies."
"The solution would be better if it was capable of more automation, especially in a monitoring capacity or for the response to abnormalities."
"Elastic Observability could improve asset discovery as the current requirement to push the agent is not ideal."
"Improving code insight related to infrastructure and network, particularly focusing on aspects such as firewalls, switches, routers, and testing would be beneficial."
"The auto-discovery isn't nearly as good. That's a big portion of it. When you drop the agent onto the JVM and you're trying to figure things out, having to go through and manually do all that is cumbersome."
"I would advise others to use a different solution than Elastic APM."
"Security Onion's user interface could be improved."
"The product is not easy to learn."
"Security Onion can be made easier to set up initially, as it is somewhat difficult at the start, but once configured, it becomes a great tool to use."
"The initial setup of the solution is a little bit difficult."
 

Pricing and Cost Advice

"Elastic Observability's pricing could be better for small-scale users."
"Elastic Observability is cheaper than other similar solutions, such as Dynatrace. Its license calculation is based on various factors like data volume and physical infrastructure, particularly related to RAM capacity."
"We have been using the open-source version."
"The product’s pricing needs improvement."
"We will buy a premium license after POC."
"Pricing is one of those situations where the more you use it, the more you pay."
"One needs to pay for the licenses, and it is an annual subscription model right now."
"Since we are a huge company, Elastic Observability is an affordable solution for us."
"Security Onion is an open-source solution."
"It is an open-source solution."
"Security Onion is a free solution."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
914,322 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
9%
Comms Service Provider
7%
Government
7%
Comms Service Provider
12%
University
12%
Government
10%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise4
Large Enterprise16
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Elastic Observability?
The problem is their licensing model, which is a bit confusing. Many customers struggle to understand their total cost of ownership because Elastic licensing is not dependent on easy, quantifiable ...
What needs improvement with Elastic Observability?
After careful consideration about areas for improvement in Elastic Observability, aspects such as pricing, customization, implementation, and scalability could be improved. As a user of the system,...
What is your primary use case for Elastic Observability?
My use case for Elastic Observability is observability, as we upload our customers' data, including logs, and when there is an issue, we can analyze what went wrong.
What is your experience regarding pricing and costs for Security Onion?
Security Onion does not require any cost, as it is open-source and free.
What needs improvement with Security Onion?
Security Onion can be made easier to set up initially, as it is somewhat difficult at the start, but once configured, it becomes a great tool to use. I assigned a rating of eight out of ten because...
What advice do you have for others considering Security Onion?
Security Onion is a completely open-source and free platform, making it a cost-effective solution that works smoothly and effectively for our organization. Security Onion integrates well with our e...
 

Overview

 

Sample Customers

PSCU, Entel, VITAS, Mimecast, Barrett Steel, Butterfield Bank
Information Not Available
Find out what your peers are saying about Elastic Observability vs. Security Onion and other solutions. Updated: September 2026.
914,322 professionals have used our research since 2012.