Try our new research platform with insights from 80,000+ expert users
Vikas Dusa - PeerSpot reviewer
Cyber Security Trainer and Programmer at Freelancer
Real User
Top 20
Mar 10, 2024
Traces ransomware and manages threat scenarios
Pros and Cons
    • "Improvements in Elastic Security could include refining and normalizing queries to make them more user-friendly, enhancing the user experience with better documentation, and addressing any latency issues."

    What is our primary use case?

    My use case for the product revolved around conducting demonstrations and testing. It also helped me with tracing ransomware and managing threat scenarios.

    What is most valuable?

    The integration with Siemens Endpoint Security in Elastic Security has been beneficial for security. The provided rules are good, making it easy to create and understand rules. Patterns and detections are made through index patterns, requiring some follow-up steps.

    In real-time, the impact of Elastic Security on ransomware is significant. For known and repeated ransomware, it can detect and prevent effectively using established signatures and behavioral patterns. However, for new types of ransomware with less complex behaviors or those that modify files minimally, conventional detection methods may struggle. Elastic Security proves to be effective even in challenging cases.

    On the cloud, it allows testing of SaaS-based applications, performance evaluations using CDMs and APIs, incident detection within company network infrastructures, and comprehensive management of security services.

    What needs improvement?

    Improvements in Elastic Security could include refining and normalizing queries to make them more user-friendly, enhancing the user experience with better documentation, and addressing any latency issues.

    For how long have I used the solution?

    I have utilized Elastic Security for approximately three to four months.

    Buyer's Guide
    Elastic Security
    March 2026
    Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
    885,286 professionals have used our research since 2012.

    What do I think about the stability of the solution?

    I rate the product’s stability an eight out of ten.

    What do I think about the scalability of the solution?

    Scaling Elastic Security is relatively easy, with a rating of seven out of ten.

    How was the initial setup?

    The tool's deployment is straightforward. 

    What other advice do I have?

    I rate the overall product an eight out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Prasanth Prasad - PeerSpot reviewer
    Chief Technology Officer at a tech vendor with 51-200 employees
    Real User
    Top 20
    Feb 29, 2024
    Offers great capabilities to detect and respond to threats
    Pros and Cons
    • "It is an extremely stable solution. Stability-wise, I rate the solution a ten out of ten."
    • "Elastic Security can be a bit difficult to use if a person only has experience in SMBs with tools like Zoho. The product can also be difficult for those who have never dealt with query language."

    What is our primary use case?

    The product is for use cases involving observability, visualization, dashboards, analytics, and security.

    What needs improvement?

    There is a constant evolution in the product. I think that the solution has a strong roadmap in place. I believe that the tool is going to be a leader in a lot of spaces, considering that it is evolving at a fast rate.

    From an improvement perspective, the product should be easier to use for those who don't know query language and have experience with only some basic products in the market.

    For how long have I used the solution?

    I have been using Elastic Security for more than three years. My company has a partnership with Elastic Security. My company operates as the solution's reseller, and we also manage the tool's implementation.

    What do I think about the stability of the solution?

    It is an extremely stable solution. Stability-wise, I rate the solution a ten out of ten.

    What do I think about the scalability of the solution?

    It is an extremely scalable solution. Scalability-wise, I rate the solution a ten out of ten.

    Whether the product suits small, medium, or enterprise-sized businesses is something that would depend on how you quantify your risks. Elastic Security is an ideal solution for anybody and everybody because it offers a free version of the solution. Small or medium businesses can use the free version of the tool. The solution has very comprehensive capabilities in the free version itself. Enterprises, large corporations, and government organizations can use the tool's paid version because it supports a lot of features from an analytical perspective. The free version doesn't have many analytical features in it. People who want to have a cybersecurity solution in their environment, which may not be specifically Elastic Security, should know the roadmap and the vision, along with a plan on what they want and how they want to go about with the product they want in their company to see where they want to end up in their cybersecurity journey. Your investments will make a lot of sense if you have a clear vision in mind.

    Elastic Security is not an ideal product if you are trying to do something very simple or basic with some check mark activities or an audit to show someone that there is some technology used in the company.

    How are customer service and support?

    I haven't had any single customer of my company telling me that the support of the product is not good. I believe that the product offers great support. I rate the technical support a nine out of ten.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have experience with Elastic Security, Rapid7, and IBM.

    How was the initial setup?

    I rate the initial setup phase a six or seven on a scale of one to ten, where one is difficult and ten is easy.

    The product's initial setup phase is neither easy nor difficult. It is easy to manage the setup phase if you know how to do it correctly. Complexity comes along as a part of the tool, especially if it is powerful and has a lot of capabilities. If it is very easy to manage the setup phase of a tool, then it is bound to have some limitations.

    The solution is deployed on the cloud, on-premises model, or a hybrid cloud.

    It can take a few days to get the product up and running. The time required to deploy the tool depends on the use cases of the user.

    What's my experience with pricing, setup cost, and licensing?

    The product offers an amazing pricing structure. Price-wise, the product is very competitive.

    What other advice do I have?

    The product has made amazing developments and has gone miles ahead in a short span of time when it comes to its enhanced threat detection and threat response capabilities.

    The product has helped manage endpoint security since it serves as a single tool that provides all the functionalities together. After you deploy Elastic Security, you can do everything with it, and there is no need to buy separate products or licenses. Through the setup of Elastic ELK Stack, you can get all the functionalities like SIEM, SOC, threat detection, endpoint detection, user behavior analytics, data analytics, data lake analytics, virtualization, dashboarding, cross-referencing, and threat response.

    Elastic Security's most beneficial for security needs steps from the tool's openness. The tool is a highly customizable product, allowing you to play with it as much as you want.

    Speaking about real-time data analytics features in Elastic Security improve security posture, the real-time is not real-time natively. You need real-time streaming capabilities, for which you need something like Apache Kafka to stream data. The analytical power of Elastic Security is extremely high. If you can get me data in real-time, I can analyze data in real time with Elastic Security.

    The product has introduced generative AI in the tool.

    The product has covered all technological advancements a person can think of, and it also has a lot of roadmap for the future development of the solution. The tool is strong and capable.

    Elastic Security offers one of the highest integration capabilities I have seen in any kit in the market. The tool offers a lot of out-of-the-box connectors and a lot of certification from a lot of providers across different areas. From a workflow perspective, if you are a customer using a proprietary tool with proprietary mechanisms to manage how work is done, then the integration offered by Elastic Security wouldn't be great. If you have an enterprise-grade product involving firewall solutions, SOC tools, endpoint tools, privilege access management solutions, or any other cybersecurity tools, Elastic Security's integration capabilities would work and help manage your workflows seamlessly.

    One of my company's customers told me that the incident response time after the implementation of the product was reduced by half within the first few weeks of the rolling out of the solution in the company.

    The product is very user-friendly since it offers generative AI in the dashboard. If you don't know how to do something on the dashboard, you can ask a question, and the solution will guide you. From a user perspective, I would say that the person using the product should be knowledgeable and should know what he wants. The product is not for someone who is a novice. The cybersecurity analyst working on the tool should have a fair understanding of what he wants to achieve with the product. It is okay if a cybersecurity analyst does not know how to write a query in the tool since the product offers help through generative AI. You can ask generative AI how to write a query, and it helps you. Elastic Security can be a bit difficult to use if a person only has experience in SMBs with tools like Zoho. The product can also be difficult for those who have never dealt with query language. It would be easy to move to Elastic Security for those who use Splunk, IBM QRadar, or other enterprise-grade tools.

    I rate the overall tool a ten out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Buyer's Guide
    Elastic Security
    March 2026
    Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
    885,286 professionals have used our research since 2012.
    reviewer2285439 - PeerSpot reviewer
    Executive Cybersecurity at a computer software company with 11-50 employees
    Real User
    Oct 13, 2023
    Dashboard offers different types of reports, including a list of alerts and easy to setup
    Pros and Cons
    • "The scalability is good. It can be scaled easily in the production environment."
    • "One limitation of Elastic Security is that it does not have built-in workflows for all tasks. For example, if you need a workflow for compliance, you will need to create a custom workflow."

    What is our primary use case?

    We are looking for the same tool on-premises that we can provide to our client as an MSSP. We're evaluating different types of tools in the market.

    Although, we have a premium version, and I was checking the functions and features here.

    We have some questions about the query language. So that also from this console and so that we can actually want to have a demonstration session where we can clarify this thing query to manage.

    What is most valuable?

    The interesting thing is about the dashboard. There are available widgets for the dashboards, along with specific features like different types of reports, such as a list of alerts. This helps to remind us which events are happening most often.

    We are still evaluating the solution, but the dashboard is something good. And one more thing, it also has anomaly reports. I like that there is a report that is only based on anomaly-related activity.

    What needs improvement?

    One limitation of Elastic Security is that it does not have built-in workflows for all tasks. For example, if you need a workflow for compliance, you will need to create a custom workflow.

    Sometimes, different types of clients require different workflows. And it absolutely varies from context to context. So that is often not available in [Elastic Security].

    Additionally, the list of data sources that Elastic Security supports is limited. If you need to collect data from a system or application that is not on the list, you will need to develop a custom integration.

    For how long have I used the solution?

    We have been evaluating it for the last two months.  

    What do I think about the stability of the solution?

    It works fine on the few devices we have deployed this solution. 

    What do I think about the scalability of the solution?

    The scalability is good. It can be scaled easily in the production environment. 

    How was the initial setup?

    The initial setup is easy. 

    What's my experience with pricing, setup cost, and licensing?

    The pricing is fine. But the basic pricing should cover all the features you need.  Elastic needs to add more features, which are available as subscription-based add-ons. So more features may need to be added.

    What other advice do I have?

    Overall, I would rate the solution an eight out of ten. We are still evaluating Elastic Security, but we are interested in learning more about its capabilities.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Head of Platform Development at Patrianna
    Real User
    Jul 26, 2023
    An easy-to-adapt solution that needs to improve scalability
    Pros and Cons
    • "Elastic Security is very easy to adapt."
    • "The tool should improve its scalability."

    What is most valuable?

    Elastic Security is very easy to adapt. 

    What needs improvement?

    The tool should improve its scalability. 

    For how long have I used the solution?

    I have been working with the product for seven years. 

    What do I think about the stability of the solution?

    The solution is stable. 

    What do I think about the scalability of the solution?

    Our DevOps uses the product regularly. 

    What other advice do I have?

    I would rate the solution a seven out of ten. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Lead Enterprise Architect at DigyCorp
    Real User
    Top 10
    Jul 4, 2023
    A flexible and open solution that supports varieties of integrations
    Pros and Cons
    • "The product has huge integration varieties available."
    • "The tool needs to integrate with legacy servers. Big companies can have legacy servers that may not always be updated."

    What is most valuable?

    The product has huge integration varieties available. 

    What needs improvement?

    The tool needs to integrate with legacy servers. Big companies can have legacy servers that may not always be updated. 

    For how long have I used the solution?

    I have been working with the solution for the last eight months. 

    What do I think about the scalability of the solution?

    The solution is scalable and flexible. My company has 20 users for the product. 

    How are customer service and support?

    We had relied on in-house support initially. However, we understand now that there are a few areas where we need to have vendor support. So we have contacted a few different companies and contractors for it. In the beginning, it may be possible to do support in-house. However, if you have a lot of commercial production environment services, then it is very hard to do without vendor support. 

    Which solution did I use previously and why did I switch?

    We decided to use the solution because it was a very promising tool and other alternatives had limitations. The tool has availability, data infrastructure, data uptime, etc. The solution is quite flexible in terms of cost. You don't need to buy a license for each and everything. Whenever you require a license, you can just buy it. I think these are the two main drivers. The product is quite open in terms of integration with machine learning which helps us with proactive monitoring. 

    How was the initial setup?

    The product's initial setup is very easy. I think the most important point is how you design your infrastructure because the solution is quite open. So you have to design it based on the nature of the data. You also need to get a life cycle so that there is no load on the storage. The solution's flexibility depends on how you design it. 

    What's my experience with pricing, setup cost, and licensing?

    The tool's pricing is flexible and comes at unit cost. You don't have to pay for everything. 

    What other advice do I have?

    I would rate the product an eight out of ten. You should use the solution if you want to have a very detailed machine-learning artificial intelligence. However, for certain production licenses, you need to prepare. It is open to different configurations and can just fit according to your requirements. This is one of the solution's good parts. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2198715 - PeerSpot reviewer
    DevOps Engineer at a tech services company with 51-200 employees
    Real User
    Jun 7, 2023
    Efficiently handle millions of loads simultaneously
    Pros and Cons
    • "It can handle millions of loads at a time, and you can always use the filters to find exactly what you are looking for and detect errors in every log message you are searching for, basically."
    • "There is an area of improvement in the Logs list. The load list may need to be paginated as there are limits."

    What is our primary use case?

    We are using Elastic Security for logging the application logs, as we use a microservice architecture. So all application logs are saved to this LogSpot.

    How has it helped my organization?

    It helps us detect errors and keep an eye on the application in both the development and production environments.

    What is most valuable?

    It can handle millions of loads at a time, and you can always use the filters to find exactly what you are looking for and detect errors in every log message you are searching for, basically.

    What needs improvement?

    There is an area of improvement in the Logs list. The load list may need to be paginated as there are limits. So if you are looking for logs for a specific application, you may get 50 lines of logs, but then you are lost. You need to add more features to specify your request so you can get the final result. It would be better to have additional features to specify your request and get the complete result.

    For how long have I used the solution?

    I have been using this solution for nine months. Although, I am not using the latest version. 

    What do I think about the stability of the solution?

    I would rate the stability a nine out of ten. 

    What do I think about the scalability of the solution?

    I would rate the scalability an eight out of ten. 

    What was our ROI?

    We definitely saw an ROI. It quickly finds the bugs.

    What other advice do I have?

    I would recommend using it, especially if you have a microservice architecture. I also have a friend who has been using it for some big data projects, so I would recommend it for that as well. 

    Overall, I would rate the solution a nine out of ten. 

    Which deployment model are you using for this solution?

    Private Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2125281 - PeerSpot reviewer
    Intern Cybersecurity at a computer software company with 10,001+ employees
    Real User
    May 24, 2023
    It's a highly flexible platform you can implement anywhere, but the setup is complex and difficult
    Pros and Cons
    • "Elastic Security is a highly flexible platform that can be implemented anywhere."
    • "The setup process is complex. You need a solid working knowledge of networking, operating systems, and a little programming."

    What is our primary use case?

    I use Elastic Search to collect logs from an Active Directory server and forward the incidents to the SOAR solution.

    What is most valuable?

    Elastic Security is a highly flexible platform that can be implemented anywhere. 

    What needs improvement?

    The setup process is complex. You need a solid working knowledge of networking, operating systems, and a little programming. 

    For how long have I used the solution?

    I have used Elastic Security for three or four months.

    What do I think about the stability of the solution?

    I rate Elastic Security seven out of 10 for stability. It isn't very stable. 

    How was the initial setup?

    The setup process is highly complex because you need to configure every agent separately and then connect them to each other and the system architecture. It would be difficult for the average user. I had a cybersecurity consultant to help me set up some of the agents. It took about three days to deploy. Maintaining Elastic Search is also challenging.

    What other advice do I have?

    I rate Elastic Search seven out of 10. I would recommend it for people who are using it to learn about solutions, but I don't think it's capable of doing the work on an enterprise level. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    HamadaElewa - PeerSpot reviewer
    Technical Sales Manager at Spire Solutions
    Reseller
    Apr 16, 2023
    A unified SIEM platform that is supported by a large community of users
    Pros and Cons
    • "I like that it's a SIEM platform. I like that I can sell Elastic Security quickly. Elastic Security has a large community that can support users."
    • "It would be better if Elastic Security had less storage for data. My customers do not like this. Other vendors have local support in different countries, but Elastic Security doesn't. I would like to have Operational Technology (OT) security in the next release."

    What is our primary use case?

    I sell Elastic Security to my customers. Almost all my customers use the free version, but some use the enterprise version.

    What is most valuable?

    I like that it's a SIEM platform. I like that I can sell Elastic Security quickly. Elastic Security has a large community that can support users.

    What needs improvement?

    It would be better if Elastic Security had less storage for data. My customers do not like this. Other vendors have local support in different countries, but Elastic Security doesn't. I would like to have Operational Technology (OT) Security in the next release.

    For how long have I used the solution?

    I have been working with this Elastic Security for about ten months.

    What do I think about the stability of the solution?

    Elastic Security is a stable solution. It's the most stable solution I have ever seen.

    How was the initial setup?

    The initial setup is straightforward. Anyone who knows the basic features can implement this product. Elastic Security has a large community that can support users.

    What about the implementation team?

    We implement this solution for our customers. We present and demonstrate the POC, and we support them. After the implementation, we provide the provisioning service. Deployment time depends on the business size, but it usually takes about 20 days to a month. 

    What's my experience with pricing, setup cost, and licensing?

    The price is reasonable. It probably costs the same as ArcSight and LogRhythm SIEM. FortiSIEM might cost less than Elastic Security. There are no hidden or additional costs.

    What other advice do I have?

    This product is better suited for large enterprises. It's one of the best options in the marketplace. I would tell potential users to use all the features because they are already collecting all the logs and data in one place.

    On a scale from one to ten, I would give Elastic Security an eight.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Distributor
    PeerSpot user
    Buyer's Guide
    Download our free Elastic Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: March 2026
    Buyer's Guide
    Download our free Elastic Security Report and get advice and tips from experienced pros sharing their opinions.