No more typing reviews! Try our Samantha, our new voice AI agent.

Elastic Security vs ReliaQuest GreyMatter comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
5th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
110
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (6th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Elastic Security
Ranking in Extended Detection and Response (XDR)
12th
Average Rating
7.8
Reviews Sentiment
6.8
Number of Reviews
66
Ranking in other categories
Log Management (12th), Security Information and Event Management (SIEM) (8th), Endpoint Detection and Response (EDR) (20th), Security Orchestration Automation and Response (SOAR) (10th)
ReliaQuest GreyMatter
Ranking in Extended Detection and Response (XDR)
27th
Average Rating
9.6
Reviews Sentiment
8.1
Number of Reviews
2
Ranking in other categories
Digital Risk Protection (10th), Managed Detection and Response (MDR) (18th)
 

Mindshare comparison

As of May 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.7%, down from 5.1% compared to the previous year. The mindshare of Elastic Security is 3.4%, down from 5.1% compared to the previous year. The mindshare of ReliaQuest GreyMatter is 0.9%, up from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks4.7%
Elastic Security3.4%
ReliaQuest GreyMatter0.9%
Other91.0%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Laurentiu Popescu - PeerSpot reviewer
Chief Product Officer at ClusterPower
Has improved threat detection with deep log analysis and streamlined investigation workflows
The most useful features I find in Elastic Security are the forensic ones that allow us to carry deeper analysis into the logs for in-depth investigations, and the dashboards, with the reporting dashboard being quite user-friendly. Elastic Security is quite good at identifying threats, as it is part of the deep investigation tool that I mentioned before. Unless we need to look further into a certain log, we can carry out a deeper analysis and forensics on those particular logs. I can assess the impact of Elastic Security's real-time data analysis on our threat response efficiency as working pretty good. We are looking for real-time analysis because we have a continuous inflow of logs from different sources: from our cloud, from Active Directory, from our network. So it works pretty well.
MK
Senior Security Analyst at Tata Consultancy
Unified security monitoring has reduced alert fatigue and improves proactive threat hunting
I use real-time monitoring in ReliaQuest GreyMatter, which significantly improves my security posture. The unified interface helps reduce alert fatigue. I would estimate it saves around 20% in alert fatigue reduction. The automated threat hunting capabilities in ReliaQuest GreyMatter help me stay ahead of threats. The machine learning algorithm benefits my threat intelligence by providing deeper insights and predictions. I use various metrics to rate the success of the predictive threat intelligence in ReliaQuest GreyMatter.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Traps is quite a stable product. Once it was properly deployed and configured, you have nothing to be worried about."
"It has pretty much everything we need and works well within the Palo Alto ecosystem."
"The most valuable features of this product are the management capabilities, which allow an IT organization to get quite a good picture of attempted cyber attacks, and its out-of-the-box investigation capabilities."
"Cortex covers everything I need. It's a perfect solution. Cortex provides a different level of visibility because it's an extended EDR, allowing you to grab logs from the network and firewalls. Palo Alto invented the concept of the extended EDR or XDR."
"It's a nice product that's stable and scalable."
"The initial setup is pretty easy."
"The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better."
"The stability of this product is very good."
"The stability of the solution is good."
"The most valuable features of the solution are the prevention methods and the incident alerts."
"The product in general has come very far and it's gotten a lot better over the years."
"We like the detailed investigation features of the platform as you're able to get a lot of detail as to what's going on on the host when you do investigations."
"The best part about this solution is that it is open-source and free to use."
"It's a good platform and the very best in the current market. We looked at the Forester report from December 2022 where it was said to be a leader."
"In my previous organization, I used this for central log management, increasing developer productivity."
"Elastic Security actually has a very good cost-benefit ratio compared to other vendors in the market."
"ReliaQuest GreyMatter saves around 60% of time or resources."
"ReliaQuest GreyMatter has helped us to reduce security incidents by 89%, which is a significant amount of incidents we have seen."
 

Cons

"The downside to the solution is that there are a large number of false positives."
"Previously, the endpoint would leave the environment, not being on our VPN, essentially unable to interact with the server to upload files."
"If you compare it to SentinelOne, which has more functionalities and detection capabilities on an open platform, the pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks."
"In terms of areas of improvement, we have not completed our review of the product. We're also looking at other products. So, it's a little bit hard to tell what could be different because we have not completed the review of this product, but based on our experience so far, its implementation is quite complex."
"Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth."
"The technical support is not very good. I find the process difficult."
"We have found that there are times Cortex XDR by Palo Alto Networks does not detect some of the viruses, we have to use another protection solution called Kaspersky."
"The onboarding process could be better."
"In terms of what could be improved with Elastic, in some use cases, especially on the advanced level, they are not ready made, so you'll have to write some scripts."
"The solution's basic setup takes time, and a lot of effort is required from the beginning to make it actually work."
"Technical support could respond faster."
"The price of this product could be improved, especially the additional costs."
"Its documentation should be a bit better. I have to spend at least a couple of hours to find the solution for a simple thing. When we buy Elastic, training is not included for free with Elastic. We have to pay extra for the training. They should include training in the price."
"I would like the process of retrieving archived data and viewing it in Kibana to be simplified."
"The solution could offer better reporting features."
"There is an area of improvement in the Logs list. The load list may need to be paginated as there are limits."
"Areas that have room for improvement include user interface and integration."
 

Pricing and Cost Advice

"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"Every customer has to pay for a license because it doesn't work with what you get from a managed services provider."
"When we first bought it, it was a bit expensive, but it was worth it. The licensing was straightforward."
"It's about $55 per license on a yearly basis."
"It has reasonable pricing for the use cases it provides to the company."
"The solution is expensive. It's pricing is on a yearly-basis."
"I am using the Community edition."
"Our license will require renewal in August, after which the maintenance will continue as usual."
"The licensing cost of Elastic Security is based on the daily ingestion rate. I can't recall the exact figure, but for 10GB of log action daily, it would cost around $20,000."
"There is no charge for using the open-source version."
"Its price is fine. Its licensing works on a yearly basis. We have to renew the license every year. I also have a good experience with Darktrace. When we buy Darktrace, we get training free of cost, which is not there in Elastic. We have to pay extra for training. There is certainly room for improvement."
"I can say that the product is cheaply priced."
"Compared to other products such as Dynatrace, this is one of the cheaper options."
"The pricing is in the middle. I think it is not an expensive experience if we compare it with big names, for example, QRadar, and also Oxide. I think Elastic Security is quite cheap. I would rate the pricing of this solution a five out of ten."
"Affordable but with additional costs"
"The product offers an amazing pricing structure. Price-wise, the product is very competitive."
Information not available
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
894,738 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Construction Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Comms Service Provider
9%
Computer Software Company
9%
Government
9%
Financial Services Firm
8%
Financial Services Firm
11%
Manufacturing Company
9%
Construction Company
7%
Retailer
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise20
Large Enterprise49
By reviewers
Company SizeCount
Small Business40
Midsize Enterprise12
Large Enterprise15
No data available
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
With Datadog, we have near-live visibility across our entire platform. We have seen APM metrics impacted several time...
What do you like most about Elastic Security?
Elastic provides the capability to index quickly due to the reverse indexes it offers. This data is crucial as it con...
What is your experience regarding pricing and costs for Elastic Security?
I am satisfied with the pricing, setup cost, and licensing cost. It is a pure 10.
What needs improvement with ReliaQuest GreyMatter?
Areas that have room for improvement include user interface and integration.
What is your primary use case for ReliaQuest GreyMatter?
I use ReliaQuest GreyMatter for detection and response, XDR, and SIEM. The best features I like about GreyMatter the ...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Elastic SIEM, ELK Logstash
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Texas A&M, U.S. Air Force, NuScale Power, Martin's Point Health Care
Information Not Available
Find out what your peers are saying about Elastic Security vs. ReliaQuest GreyMatter and other solutions. Updated: April 2026.
894,738 professionals have used our research since 2012.