No more typing reviews! Try our Samantha, our new voice AI agent.

Elastic Observability vs Security Onion comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Elastic Observability
Ranking in Log Management
16th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
29
Ranking in other categories
Application Performance Monitoring (APM) and Observability (11th), IT Infrastructure Monitoring (13th), Container Monitoring (5th), Cloud Monitoring Software (11th)
Security Onion
Ranking in Log Management
24th
Average Rating
7.4
Reviews Sentiment
7.2
Number of Reviews
5
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Log Management category, the mindshare of Elastic Observability is 1.2%, down from 1.4% compared to the previous year. The mindshare of Security Onion is 1.8%, down from 4.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
Elastic Observability1.2%
Security Onion1.8%
Other97.0%
Log Management
 

Featured Reviews

Mohammed-Abdelalim - PeerSpot reviewer
Assistant Vice President at QualityKiosk Technologies Pvt. Ltd.
Has provided powerful customization for unique monitoring needs but needs more out-of-the-box capabilities
In my opinion, the best features of Elastic Observability are their flexibility to integrate with other existing systems and the ability to build a unified monitoring tool that can integrate with existing ones and end-to-end user journeys which require a lot of customizations. The greatest feature in Elastic is the ability to customize. This is similar to my comments about customizable dashboards in Elastic because it's visible to the analyst. However, it's very great. Customizing these dashboards can meet the customer's specific use cases and specific stories that they have in their environment, their special environment that doesn't look like other environments. The dashboarding in Elastic is highly customizable to the level of logos. If the customer wants his company logo in the dashboard, it can be done.
HJ
Manager at teshama
Centralized threat monitoring has improved visibility but demands complex setup and configuration
The best features Security Onion offers include acting as the intrusion detection system in my organization and helping me to address traffic, logs, and events happening within the organization. Since Security Onion is an open-source system that integrates with tools like Suricata and Zeek with the ELK stack, it enables threat detection and response capabilities, delivering high-level security measures at a cost, making it suitable for businesses of varying skill levels. These integrations with Suricata and Zeek have greatly impacted our workflow and our team's effectiveness by helping us address issues such as identifying intrusions, evaluating threats, and overseeing log files. This tool is very cost-effective, making it suitable for any size of organization wanting to use it.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"From my experience with several major customers, the most valued feature of Elastic is its log analytics capabilities."
"Elastic APM has plenty of features, such as the Elastic server for Kibana and many additional plugins. It's a comprehensive tool when used as a logging platform."
"The tool's most valuable feature is centralized logging. Elastic Common Search helps us to search for the logs across the organization."
"It has always been a stable solution."
"In addition to the fact that we are more proactive in the detection of incident before they occur, we can on one click see the request path from the customer to the backend."
"The architecture and system's stability are simple."
"The solution has been stable in our usage."
"For full stack observability, Elastic is the best tool compared with any other tool like New Relic or AppDynamics or Dynatrace."
"The most valuable feature of Security Onion for security monitoring is its ability to find infected ports."
"Security Onion is a completely open-source and free platform, making it a cost-effective solution that works smoothly and effectively for our organization."
"Security Onion has positively impacted my organization by greatly improving our security posture, making alert triage easier to handle, simplifying the analysis of threats, and decreasing the cost of threat analysis and detection."
"We use Security Onion for internal vulnerability assessment."
"Security Onion is the most mature solution in the market."
 

Cons

"When I go to the portal, I do not see many insights on the endpoints or where there could be latencies."
"There's a steep learning curve if you've never used this solution before."
"Elastic Observability is difficult to use. There are only three options for customization but this can be difficult for our use case. We do not have other options to choose the metrics shown, such as CPU or memory usage."
"The tool's scalability involves a more complex implementation process. It requires careful calculations to determine the number of nodes needed, the specifications of each node, and the configuration of hot, warm, and cold zones for data storage. Additionally, managing log retention policies adds further complexity. The solution's pricing also needs to be cheaper."
"The only challenging aspect for new users is often writing the query language."
"There is room for improvement regarding its APM capabilities."
"They need more skills in the market. There are not enough skills in the market. It is not pervasive enough on the market, in my opinion. In other words, there isn't a big enough user base."
"The price is the only issue in the solution. It can be made better and cheaper."
"The initial setup of the solution is a little bit difficult."
"Security Onion can be made easier to set up initially, as it is somewhat difficult at the start, but once configured, it becomes a great tool to use."
"Security Onion's user interface could be improved."
"The product is not easy to learn."
"For Security Onion, setting up and configuring the system can be quite challenging for newcomers due to the need for a grasp of networking and security concepts."
 

Pricing and Cost Advice

"We will buy a premium license after POC."
"One needs to pay for the licenses, and it is an annual subscription model right now."
"Elastic Observability's pricing could be better for small-scale users."
"Since we are a huge company, Elastic Observability is an affordable solution for us."
"Users have to pay for some features, like the alerts on different channels, because they are unavailable in different source versions."
"Elastic Observability is cheaper than other similar solutions, such as Dynatrace. Its license calculation is based on various factors like data volume and physical infrastructure, particularly related to RAM capacity."
"So far, there are just the standard licensing fees. Several of the components are embedded in the license or are even open source. They're even free depending on what you use, which makes it even more appealing to someone that is discussing pricing of the solution."
"The price of Elastic Observability is expensive."
"Security Onion is a free solution."
"Security Onion is an open-source solution."
"It is an open-source solution."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
909,099 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
10%
Government
7%
Manufacturing Company
7%
University
12%
Comms Service Provider
12%
Government
10%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise4
Large Enterprise16
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Elastic Observability?
The problem is their licensing model, which is a bit confusing. Many customers struggle to understand their total cost of ownership because Elastic licensing is not dependent on easy, quantifiable ...
What needs improvement with Elastic Observability?
After careful consideration about areas for improvement in Elastic Observability, aspects such as pricing, customization, implementation, and scalability could be improved. As a user of the system,...
What is your primary use case for Elastic Observability?
My use case for Elastic Observability is observability, as we upload our customers' data, including logs, and when there is an issue, we can analyze what went wrong.
What is your experience regarding pricing and costs for Security Onion?
Security Onion does not require any cost, as it is open-source and free.
What needs improvement with Security Onion?
Security Onion can be made easier to set up initially, as it is somewhat difficult at the start, but once configured, it becomes a great tool to use. I assigned a rating of eight out of ten because...
What advice do you have for others considering Security Onion?
Security Onion is a completely open-source and free platform, making it a cost-effective solution that works smoothly and effectively for our organization. Security Onion integrates well with our e...
 

Overview

 

Sample Customers

PSCU, Entel, VITAS, Mimecast, Barrett Steel, Butterfield Bank
Information Not Available
Find out what your peers are saying about Elastic Observability vs. Security Onion and other solutions. Updated: August 2026.
909,099 professionals have used our research since 2012.