Try our new research platform with insights from 80,000+ expert users
reviewer1602072 - PeerSpot reviewer
AVP, Site Reliability Engineer at a financial services firm with 10,001+ employees
Real User
Good monitoring and behavior prediction; troubleshooting tool could be improved
Pros and Cons
  • "Enables monitoring of application performance and the ability to predict behaviors."
  • "Upgrades currently released as stacks when it should be a plugin or an extension to save removal and reinstallation."

What is our primary use case?

Our primary use case of this solution is for application performance monitoring. We are customers of ELK.

What is most valuable?

This solution enables us to monitor application performance from Elasticsearch and we can predict some behaviors for applications using ELK. This product is distributed and scalable which is good for us.

What needs improvement?

The troubleshooting or diagnostic tool can be improved to provide a better understanding of internal behavior and how data is stored. It would also be helpful if they were to release the next version as a plugin or an extension, or as a JAR file, for the latest features. When releasing a new version they currently provide a new stack which means everything needs to be removed before the new version is installed. 

For how long have I used the solution?

I've been using this solution for five years. 

Buyer's Guide
Elastic Security
June 2025
Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is generally stable, although with each new upgrade there is an adjustment period. They upgrade versions very regularly and it's hard to keep up. By the time my environment is stable with the previous versions, they are already bringing out a new version. 

What do I think about the scalability of the solution?

Scalability is very good with this product. 

How are customer service and support?

I'm not satisfied with technical support because whenever you raise a case, it goes to some random support person who asks questions about the architecture. It's a waste of time. I'm a platinum customer so each time I raise a request, it should go to a dedicated customer support representative who knows my case. It's very difficult when you work in a highly secure environment to get all the logs and send the logs to them each time. 

How was the initial setup?

The initial setup is easy, but as you begin using the more advanced features like security and authentication with an AM and LM, then it becomes a bit tricky.

What's my experience with pricing, setup cost, and licensing?

Licensing costs are high, they charge based on the nodes and the RAM. If I purchase a license for a 64GB RAM node and then want to have 128GB RAM, I can't because it's not in the contract so I have to pay on top of that. They removed a feature that allows me to provide multiple disks for one node so if I now want to add an extra disk to the volume, I have to buy a license for one extra node. It's very unfair. 

What other advice do I have?

I would recommend this solution for an organization that doesn't require a highly secured environment, because they'll have to deal with the issues of VM upgrades and installations. If it's a highly secured environment like a bank, then I suggest ELK cloud instead of on-prem.

I rate this solution a seven out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1393731 - PeerSpot reviewer
Consultant at a computer software company with 5,001-10,000 employees
Real User
Fast, highly scalable, and agents don't overload the terminals, but needs a simulation environment, a mobile app, and better documentation
Pros and Cons
  • "It is very quick to react. I can set it to check anomalies or suspicious behavior every 30 seconds. It is very fast."
  • "Elastic has a lot of beats, such as Winlogbeat and Filebeat. Beats are the agents that have to be installed on the terminals to send the data. When we install beats or Elastic agents on every terminal, they don't overload the terminals. In other SIEM solutions such as Splunk or QRadar, when beats or agents are installed on endpoints, they are very heavy for the terminals. They consume a lot of power of the terminals, whereas Elastic agents hardly consume any power and don't overload the terminals."
  • "There should be a simulation environment to check whether my Elastic implementation is functioning perfectly fine. Other solutions have their own Android and iOS applications that I can install on my mobile so that I am continuously connected to the SIEM."
  • "Its documentation should be a bit better. I have to spend at least a couple of hours to find the solution for a simple thing. When we buy Elastic, training is not included for free with Elastic. We have to pay extra for the training. They should include training in the price."

What is our primary use case?

There are around 150 pre-built use cases. One of the major use cases is when somebody tries to fiddle with logs, Elastic SIEM creates an alert because logs are the most critical things from the security aspect. For example, I have more than 1,000 terminals, which can be desktops, laptops, or any sort of servers. If somebody tries to delete Windows logs, Elastic SIEM immediately generates an alert indicating that somebody is trying to fiddle with the logs. Elastic SIEM sends me a pop-up message as well as an email.

What is most valuable?

It is very quick to react. I can set it to check anomalies or suspicious behavior every 30 seconds. It is very fast.

Elastic has a lot of beats, such as Winlogbeat and Filebeat. Beats are the agents that have to be installed on the terminals to send the data. When we install beats or Elastic agents on every terminal, they don't overload the terminals. In other SIEM solutions such as Splunk or QRadar, when beats or agents are installed on endpoints, they are very heavy for the terminals. They consume a lot of power of the terminals, whereas Elastic agents hardly consume any power and don't overload the terminals. 

What needs improvement?

There should be a simulation environment to check whether my Elastic implementation is functioning perfectly fine. Other competitors provide a simulation environment so that I can simulate an IT attack and see how my solution is reacting or giving me alerts. I have not found any such feature in Elastic.

Other solutions have their own Android and iOS applications that I can install on my mobile so that I am continuously connected to the SIEM. This is something missing in Elastic. There is no mobile app.

Its documentation should be a bit better. I have to spend at least a couple of hours to find the solution for a simple thing. The documentation should be more precise and much better than what their counterparts are offering.

When we buy Elastic, training is not included for free with Elastic. We have to pay extra for the training. They should include training in the price.

What do I think about the stability of the solution?

It is, for sure, reliable.

What do I think about the scalability of the solution?

It is highly scalable. We at least have two dozen people who are using it. Some people may be using only a part of it, and some may be fully involved in it.

We have plans to increase its usage. We are ready with a running full-fledged server, and we can even handle data for potential customers. We are definitely planning to widen its usage.

How are customer service and technical support?

I have interacted with them. They are quite responsive, and they do respond within the SLA.

How was the initial setup?

I was not there when the deployment was done, but based on what I have heard, it was complex because of the server deployment and cluster formation, and it took at least two months.

What's my experience with pricing, setup cost, and licensing?

Its price is fine. Its licensing works on a yearly basis. We have to renew the license every year.

I also have a good experience with Darktrace. When we buy Darktrace, we get training free of cost, which is not there in Elastic. We have to pay extra for training. There is certainly room for improvement.

Which other solutions did I evaluate?

I was not in this company when this was chosen.

What other advice do I have?

I would advise going for the latest version, but it may or may not be backward compatible. Nowadays, version 7.12 is the latest version, and I see that it is actually not compatible with the older versions. 

I would rate Elastic SIEM a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Elastic Security
June 2025
Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
Vikas Dusa - PeerSpot reviewer
Cyber Security Trainer and Programmer at Freelancer
Real User
Top 5Leaderboard
Traces ransomware and manages threat scenarios
Pros and Cons
    • "Improvements in Elastic Security could include refining and normalizing queries to make them more user-friendly, enhancing the user experience with better documentation, and addressing any latency issues."

    What is our primary use case?

    My use case for the product revolved around conducting demonstrations and testing. It also helped me with tracing ransomware and managing threat scenarios.

    What is most valuable?

    The integration with Siemens Endpoint Security in Elastic Security has been beneficial for security. The provided rules are good, making it easy to create and understand rules. Patterns and detections are made through index patterns, requiring some follow-up steps.

    In real-time, the impact of Elastic Security on ransomware is significant. For known and repeated ransomware, it can detect and prevent effectively using established signatures and behavioral patterns. However, for new types of ransomware with less complex behaviors or those that modify files minimally, conventional detection methods may struggle. Elastic Security proves to be effective even in challenging cases.

    On the cloud, it allows testing of SaaS-based applications, performance evaluations using CDMs and APIs, incident detection within company network infrastructures, and comprehensive management of security services.

    What needs improvement?

    Improvements in Elastic Security could include refining and normalizing queries to make them more user-friendly, enhancing the user experience with better documentation, and addressing any latency issues.

    For how long have I used the solution?

    I have utilized Elastic Security for approximately three to four months.

    What do I think about the stability of the solution?

    I rate the product’s stability an eight out of ten.

    What do I think about the scalability of the solution?

    Scaling Elastic Security is relatively easy, with a rating of seven out of ten.

    How was the initial setup?

    The tool's deployment is straightforward. 

    What other advice do I have?

    I rate the overall product an eight out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Head of Platform Development at Patrianna
    Real User
    Top 20
    An easy-to-adapt solution that needs to improve scalability
    Pros and Cons
    • "Elastic Security is very easy to adapt."
    • "The tool should improve its scalability."

    What is most valuable?

    Elastic Security is very easy to adapt. 

    What needs improvement?

    The tool should improve its scalability. 

    For how long have I used the solution?

    I have been working with the product for seven years. 

    What do I think about the stability of the solution?

    The solution is stable. 

    What do I think about the scalability of the solution?

    Our DevOps uses the product regularly. 

    What other advice do I have?

    I would rate the solution a seven out of ten. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Lead Enterprise Architect at DigyCorp
    Real User
    Top 5
    A flexible and open solution that supports varieties of integrations
    Pros and Cons
    • "The product has huge integration varieties available."
    • "The tool needs to integrate with legacy servers. Big companies can have legacy servers that may not always be updated."

    What is most valuable?

    The product has huge integration varieties available. 

    What needs improvement?

    The tool needs to integrate with legacy servers. Big companies can have legacy servers that may not always be updated. 

    For how long have I used the solution?

    I have been working with the solution for the last eight months. 

    What do I think about the scalability of the solution?

    The solution is scalable and flexible. My company has 20 users for the product. 

    How are customer service and support?

    We had relied on in-house support initially. However, we understand now that there are a few areas where we need to have vendor support. So we have contacted a few different companies and contractors for it. In the beginning, it may be possible to do support in-house. However, if you have a lot of commercial production environment services, then it is very hard to do without vendor support. 

    Which solution did I use previously and why did I switch?

    We decided to use the solution because it was a very promising tool and other alternatives had limitations. The tool has availability, data infrastructure, data uptime, etc. The solution is quite flexible in terms of cost. You don't need to buy a license for each and everything. Whenever you require a license, you can just buy it. I think these are the two main drivers. The product is quite open in terms of integration with machine learning which helps us with proactive monitoring. 

    How was the initial setup?

    The product's initial setup is very easy. I think the most important point is how you design your infrastructure because the solution is quite open. So you have to design it based on the nature of the data. You also need to get a life cycle so that there is no load on the storage. The solution's flexibility depends on how you design it. 

    What's my experience with pricing, setup cost, and licensing?

    The tool's pricing is flexible and comes at unit cost. You don't have to pay for everything. 

    What other advice do I have?

    I would rate the product an eight out of ten. You should use the solution if you want to have a very detailed machine-learning artificial intelligence. However, for certain production licenses, you need to prepare. It is open to different configurations and can just fit according to your requirements. This is one of the solution's good parts. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2198715 - PeerSpot reviewer
    DevOps Engineer at a tech services company with 51-200 employees
    Real User
    Efficiently handle millions of loads simultaneously
    Pros and Cons
    • "It can handle millions of loads at a time, and you can always use the filters to find exactly what you are looking for and detect errors in every log message you are searching for, basically."
    • "There is an area of improvement in the Logs list. The load list may need to be paginated as there are limits."

    What is our primary use case?

    We are using Elastic Security for logging the application logs, as we use a microservice architecture. So all application logs are saved to this LogSpot.

    How has it helped my organization?

    It helps us detect errors and keep an eye on the application in both the development and production environments.

    What is most valuable?

    It can handle millions of loads at a time, and you can always use the filters to find exactly what you are looking for and detect errors in every log message you are searching for, basically.

    What needs improvement?

    There is an area of improvement in the Logs list. The load list may need to be paginated as there are limits. So if you are looking for logs for a specific application, you may get 50 lines of logs, but then you are lost. You need to add more features to specify your request so you can get the final result. It would be better to have additional features to specify your request and get the complete result.

    For how long have I used the solution?

    I have been using this solution for nine months. Although, I am not using the latest version. 

    What do I think about the stability of the solution?

    I would rate the stability a nine out of ten. 

    What do I think about the scalability of the solution?

    I would rate the scalability an eight out of ten. 

    What was our ROI?

    We definitely saw an ROI. It quickly finds the bugs.

    What other advice do I have?

    I would recommend using it, especially if you have a microservice architecture. I also have a friend who has been using it for some big data projects, so I would recommend it for that as well. 

    Overall, I would rate the solution a nine out of ten. 

    Which deployment model are you using for this solution?

    Private Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2125281 - PeerSpot reviewer
    Intern Cybersecurity at a computer software company with 10,001+ employees
    Real User
    It's a highly flexible platform you can implement anywhere, but the setup is complex and difficult
    Pros and Cons
    • "Elastic Security is a highly flexible platform that can be implemented anywhere."
    • "The setup process is complex. You need a solid working knowledge of networking, operating systems, and a little programming."

    What is our primary use case?

    I use Elastic Search to collect logs from an Active Directory server and forward the incidents to the SOAR solution.

    What is most valuable?

    Elastic Security is a highly flexible platform that can be implemented anywhere. 

    What needs improvement?

    The setup process is complex. You need a solid working knowledge of networking, operating systems, and a little programming. 

    For how long have I used the solution?

    I have used Elastic Security for three or four months.

    What do I think about the stability of the solution?

    I rate Elastic Security seven out of 10 for stability. It isn't very stable. 

    How was the initial setup?

    The setup process is highly complex because you need to configure every agent separately and then connect them to each other and the system architecture. It would be difficult for the average user. I had a cybersecurity consultant to help me set up some of the agents. It took about three days to deploy. Maintaining Elastic Search is also challenging.

    What other advice do I have?

    I rate Elastic Search seven out of 10. I would recommend it for people who are using it to learn about solutions, but I don't think it's capable of doing the work on an enterprise level. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    HamadaElewa - PeerSpot reviewer
    Technical Sales Manager at Spire Solutions
    Reseller
    Top 5Leaderboard
    A unified SIEM platform that is supported by a large community of users
    Pros and Cons
    • "I like that it's a SIEM platform. I like that I can sell Elastic Security quickly. Elastic Security has a large community that can support users."
    • "It would be better if Elastic Security had less storage for data. My customers do not like this. Other vendors have local support in different countries, but Elastic Security doesn't. I would like to have Operational Technology (OT) security in the next release."

    What is our primary use case?

    I sell Elastic Security to my customers. Almost all my customers use the free version, but some use the enterprise version.

    What is most valuable?

    I like that it's a SIEM platform. I like that I can sell Elastic Security quickly. Elastic Security has a large community that can support users.

    What needs improvement?

    It would be better if Elastic Security had less storage for data. My customers do not like this. Other vendors have local support in different countries, but Elastic Security doesn't. I would like to have Operational Technology (OT) Security in the next release.

    For how long have I used the solution?

    I have been working with this Elastic Security for about ten months.

    What do I think about the stability of the solution?

    Elastic Security is a stable solution. It's the most stable solution I have ever seen.

    How was the initial setup?

    The initial setup is straightforward. Anyone who knows the basic features can implement this product. Elastic Security has a large community that can support users.

    What about the implementation team?

    We implement this solution for our customers. We present and demonstrate the POC, and we support them. After the implementation, we provide the provisioning service. Deployment time depends on the business size, but it usually takes about 20 days to a month. 

    What's my experience with pricing, setup cost, and licensing?

    The price is reasonable. It probably costs the same as ArcSight and LogRhythm SIEM. FortiSIEM might cost less than Elastic Security. There are no hidden or additional costs.

    What other advice do I have?

    This product is better suited for large enterprises. It's one of the best options in the marketplace. I would tell potential users to use all the features because they are already collecting all the logs and data in one place.

    On a scale from one to ten, I would give Elastic Security an eight.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor
    PeerSpot user
    Buyer's Guide
    Download our free Elastic Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: June 2025
    Buyer's Guide
    Download our free Elastic Security Report and get advice and tips from experienced pros sharing their opinions.