We are using the solution for log management. We use it for monitoring and observing.
Solutions Consultant at a tech services company with 5,001-10,000 employees
Easy to use and set up with good documentation
Pros and Cons
- "It's very stable and reliable."
- "Their visuals and graphs need to be better."
What is our primary use case?
What is most valuable?
Its search engine is great, and it is really quick. In the beginning, we wanted to search through terabytes of log data, and after that, we decided to search using the solution.
The initial setup is very easy.
It can scale well.
It's very stable and reliable.
We use it as an open-source product and do not have to pay for licensing.
There is a lot of good documentation online if you need to troubleshoot. Everything is clear and easy to follow.
What needs improvement?
The solution wasn't designed for monitoring at first. It was for search and stack logs and for working with solutions like Kibana. Therefore, they are a bit weak when compared to traditional monitoring tools.
They should work to improve their integration and graphical interfaces. Their visuals and graphs need to be better. They need better charts. These already exist in Kibana and should be in this solution as well.
For how long have I used the solution?
I've been using the solution for two years.
Buyer's Guide
Elastic Security
June 2025

Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is very stable. There are no bugs or glitches, and it doesn't crash or freeze. it is reliable, and the performance is good. It'd rate the general stability ten out of ten.
What do I think about the scalability of the solution?
We can easily scale up, according to our needs. It's easy to expand.
I'd rate the overall ability to scale up eight out of ten.
How are customer service and support?
They do not have technical support. They have community support and documentation to help with troubleshooting. We've been happy with the amount of detail we can find online if we need assistance.
Which solution did I use previously and why did I switch?
I have not used any other products that are the same. I only use Micro Focus Ops Bridge and SiteScope, which are traditional monitoring tools, so I can't categorize them. They are slow yet they can handle big networks.
How was the initial setup?
The solution is straightforward to set up. They have documentation on their site that shows how to do everything step by step. Everything is very clear and easy to understand. I'd rate the overall ease of implementation nine out of ten.
The deployment is fast and only takes hours, not days.
What about the implementation team?
One person helped me deploy the solution. However, we did not need outside assistance. We did it ourselves.
What's my experience with pricing, setup cost, and licensing?
The solution is open-source and, therefore, free to use.
What other advice do I have?
I'm a partner.
I'd advise others to take advantage of the documentation of the solution in order to get the most out of the product.
In general, I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Chief Business Officer at Sky Express
Open-source with a good knowledge base and a helpful community
Pros and Cons
- "It's open-source and free to use."
- "We'd like to see some more artificial intelligence capabilities."
What is our primary use case?
Basically, we are using this product for monitoring and for developing the processes for our company.
What is most valuable?
I like that there is a knowledge base. There's the possibility for technical people to develop this product and to know much more. However, they do not need additional certifications from the vendor side or to pay a lot of money for their courses and certifications. We don't need to rely on vendors. We can handle the product ourselves.
It's open-source and free to use.
What needs improvement?
The solution isn't really recognized in the market. They need to do a better job when they are marketing the solution. We'd like customers to have more visibility of it, and we'd like them to see how secure and highly effective it is. There needs to be more brand awareness.
We have faced some obstacles when handling the implementation process.
There are no templates available when integrating with other products. We sometimes need to find some workarounds.
We'd like to see some more artificial intelligence capabilities.
For how long have I used the solution?
I've been using the solution for four and a half years.
What do I think about the stability of the solution?
The solution is stable and reliable. We found the product to be very usable. There are no bugs or glitches, and it doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution can scale. Integration with other products may be a bit difficult, yet it is doable.
How are customer service and support?
If we need assistance, we tend to use the community. There is always somebody in the world who can help us if we have a question. There are many people that can provide good tips and useful advice. Typically, many people have faced the same problems and they can help us solve things.
Which solution did I use previously and why did I switch?
I'm also aware of Curator.
Compared to Curator, customer awareness isn't as strong. From the price perspective, this product is better, however, many customers don't want to change their own CM and their products if they already have something in place.
How was the initial setup?
The initial setup wasn't overly complex or difficult. That said, it wasn't simple either. It's somewhat moderate in terms of implementation.
I'd rate the solution three out of five in terms of ease of setup.
What's my experience with pricing, setup cost, and licensing?
This is an open-source solution. It is free to use.
What other advice do I have?
For new customers, this is a perfect choice. For older customers, it's very difficult to change solutions.
I'd rate the solution eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Elastic Security
June 2025

Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
Engineer at a tech services company with 501-1,000 employees
Integrates into the overall ELK Stack, scans for vulnerabilities well and offers good performance
Pros and Cons
- "We chose the product based on the ability to scan for malware using a malware behavioral model as opposed to just a traditional hash-based antivirus. Therefore, it's not as intensive."
- "It could use maybe a little more on the Linux side."
What is most valuable?
We really like that it integrates into the overall ELK Stack, and we're using that as our theme. We were looking for a product compatible with that. We like the detailed investigation features of the platform as you're able to get a lot of detail as to what's going on on the host when you do investigations. We like the quarantine feature.
We chose the product based on the ability to scan for malware using a malware behavioral model as opposed to just a traditional hash-based antivirus. Therefore, it's not as intensive. We have a lot of satellite communications, and it's not as intensive since we don't require updates to calm down on a regular basis for updated DAT files for hashes on a regular basis. We only have to update quarterly against the new malware model. It's also a lot less impactful from a performance perspective on a machine.
What needs improvement?
It's a pretty solid product. It's pretty easy to use as it's not a full endpoint protection suite. We're actually dependent on using Windows Defender for a firewall and traditional antivirus when it's required. It could use maybe a little more on the Linux side. Now that the product line is getting picked up by Elastic, they're going to continue to build out and make the Linux feature set more robust. However, I would say that right now the Linux feature set is a little limited.
For how long have I used the solution?
I've been using the solution for about a year.
What do I think about the stability of the solution?
Stability is very good. It's a very stable product. We haven't had any issues with stability at all.
What do I think about the scalability of the solution?
For what we use it for, scalability has been great. Our environments tend to be smaller. We're only talking about 200 to 1,000 systems. Therefore, I don't know that I could speak to a real large scale since that's not our implementation level.
We are kind of in an interesting use case as we're not actually using it on a day-to-day basis. We are a production house, and we shift suites out to customers to use. As far as what the user feedback is on a regular basis, we don't really see a ton of that unless we kind of go out and hunt for it.
Which solution did I use previously and why did I switch?
We're using the Microsoft Defender product. It's just what's embedded inside of the operating system. It's not the full Defender for Endpoint. It's just Windows and antivirus.
How was the initial setup?
The Endgame itself is extremely straightforward to set up and you just filled out the ISO and you follow a couple of wizards you're done. It's very easy. I would say the ELK Stack is a little more complicated, however, that's due to the way we implement PKI in our environment. The product in itself is fairly straightforward to implement. It's our choice of certificate implementation that's making it a little more complicated.
We targeted it to be able to be maintained by one person. In a lot of cases, our scenario is that we only have one person available to maintain the product. It's very easy to maintain. There's not a ton going on. In a scene, you always have to have somebody watching the log of traffic if you want it to be effective. However, outside of that, there's no extreme maintenance associated with the product.
What's my experience with pricing, setup cost, and licensing?
I do not know approximately how much it costs per month or per year. I'm not the one who makes the purchases.
What other advice do I have?
We are just customers.
I'd rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Operating Officer / SR. Project Manager at SCS
A flexible, cost-effective, and reliable solution
Pros and Cons
- "One of the most valuable features of this solution is that it is more flexible than AlienVault."
- "It is difficult to anticipate and understand the space utilization, so more clarity there would be great."
What is our primary use case?
We use it as a SIEM for monitoring a client's environment.
What is most valuable?
One of the most valuable features of this solution is that it is more flexible than AlienVault.
What needs improvement?
It is difficult to anticipate and understand the space utilization, so more clarity there would be great.
For how long have I used the solution?
My company has been using this solution for two years.
What do I think about the stability of the solution?
It is a very stable solution.
What do I think about the scalability of the solution?
The solution is very scalable.
How are customer service and support?
The technical support is adequate.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We currently use AlienVault for some clients and Elastic Security for others. We chose Elastic Security because we felt it was the most flexible, cost-effective solution to provide the results needed.
How was the initial setup?
In certain respects, the setup of this solution is more straightforward than other solutions, but in other respects, it's more complex because it needs more fine-tuning than Splunk or AlienVault.
What about the implementation team?
We implemented through an in-house team and it took about two months.
What's my experience with pricing, setup cost, and licensing?
The licensing cost depends on the size of the environment it's monitoring. Everything is based on volume, as with all SIEMs. When compared to other products, the price is average or on the low side.
Which other solutions did I evaluate?
We evaluated several options, including Monster SIEM, Splunk, and Wazuh.
What other advice do I have?
There's a lot of fine-tuning involved with this solution. When you go to a diner, and the menu has everything on it, and you can't figure out which part to look at first, it's a double-edged sword. You can do everything with this solution, which means you have to figure out which part of "everything" makes sense for your company to do.
I would rate this solution as an eight out of ten. It's a good value for money and a reliable solution, but it's heavily reliant on appropriate configuration.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Project Delivery Manager at Spindox
A good SIEM solution but doesn't have as many features as its competitors
Pros and Cons
- "It's not very complicated to install Elastic."
- "With Elastic, you have to build the use cases for the specific requirement. Other products have a simple integration and more use cases to integrate out-of-the-box solutions for SIEM."
What is our primary use case?
I worked for a telco client for the security model of Elastic, but my role was unit manager. I don't have a lot of technical expertise, but I decided on the solution for a client, and I was responsible for the delivery.
I worked with the security of the mobile app. I see all the logs in Elastic for SIEM. I monitored the logging and some logs from the machine for a UNIX system with some use cases like the machine's file system.
This solution is deployed on-premise.
We provide this solution to our customers, which are telcos, in the finance industry, and in retail.
What is most valuable?
I think that it's a good solution for a SIEM.
What needs improvement?
Elastic doesn't have the features like other competitors in SIEM. For example, Dynatrace as a solution for SIEM has features that Elastic actually don't have.
With Elastic, you have to build the use cases for the specific requirement. Other products have a simple integration and more use cases to integrate out-of-the-box solutions for SIEM. That's the improvement I would like to see.
What do I think about the stability of the solution?
The product is stable.
Which solution did I use previously and why did I switch?
Other products like Splunk are better than Elastic for a SIEM because there are some use cases already available for a client. Elastic doesn't have this, so the user must build the SIEM solution. I think that Elastic has to increase the features for the SIEM.
How was the initial setup?
It's not very complicated to install Elastic, but I didn't deploy it.
What other advice do I have?
I would rate this solution 7 out of 10.
It's a good solution and I would recommend it, but there are other products that have more features that Elastic doesn't have.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Devops/SRE tech lead at a transportation company with 201-500 employees
Scalable with good logging functionality and good stability
Pros and Cons
- "The solution is quite stable. The performance has been good."
- "The problem with ELK is it's difficult to administer. When you have a problem, it can be very, very difficult to rebuild indexes."
What is our primary use case?
We do not use monitoring due to the fact that we use Prometheus for monitoring. We don't use APM and so on. We use ELK only for logging.
What is most valuable?
The solution has very good logging functionality.
The aggregation capability is quite useful.
The solution is quite stable. The performance has been good.
The solution scales well.
The solution has gotten easier to deploy since the 2019 version.
What needs improvement?
Using ELK the first time there was a lack of security. We had to buy the paid version due to the fact that we needed to secure access to Kubernetes.
The problem with ELK is it's difficult to administer. When you have a problem, it can be very, very difficult to rebuild indexes. In fact, you have to monitor the stack and it's very, very difficult. Sometimes we lose indexes or we have nothing on the dashboard.
For how long have I used the solution?
I've been using the solution for about two years at this point. It hasn't been an extremely long amount of time.
What do I think about the stability of the solution?
The solution is stable. It's reliable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution can scale. If a company needs to expand it, it can do so pretty easily.
We use the solution for quite a small team. Ten people work on it.
How are customer service and technical support?
Due to the fact that we have a paid version of the product, technical support has been fine. We've been satisfied with the level of service provided to us. They are quite helpful and responsive.
Which solution did I use previously and why did I switch?
Previously, we were on Datadog, Kubernetes Logs. It was not very easy to debug incidents and so on. If I had to compare, I'd say that Datadog is very easy to implement and it's such a fast solution.
How was the initial setup?
The first time, it was very hard to deploy on Kubernetes. However, as we reached version seven, they are now an operator. Now it's very easy to deploy. We no longer have any issues.
What's my experience with pricing, setup cost, and licensing?
The solution is a bit expensive. I don't know the pricing of Datadog, which is what we used to use, however, it's my understanding that it is very expensive also.
What other advice do I have?
We are a customer and an end-user. We do not have a business relationship with ELK.
The solution is deployed on Kubernetes in Azure.
I would advise other companies and users not to mix monitoring and logging. It's not the same purpose. Many people do monitoring by scanning logs. It's not a good idea. The good idea is to monitor separately. In case of incidents, you have to monitor metrics and logins for the root cause. It's important to separate this, and not treat them as the same thing.
I'd rate the solution at an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior DevOps Engineer at a financial services firm with 10,001+ employees
It is quite comprehensive and you're able to do a lot of tasks
Pros and Cons
- "The indexes allow you to get your results quickly. The filtering and log passing is the advantage of Logstash."
- "We're using the open-source edition, for now, I think maybe they can allow their OLED plugin to be open source, as at the moment it is commercialised."
What is our primary use case?
It is currently deployed as a single instance, but we are currently looking at clusters. We are using it for a logging solution. I'm a developer and act as a server engineer for DevOps Engineers. It's used by developers and mobile developers. It could be used by quite a few different teams.
How has it helped my organization?
It is quite comprehensive, and you're able to do a lot of tasks. It has dashboards and we're able to create a lot of search queries. It is not easy to use, but once you get the hang of it, then it provides good graphs and visuals such as these. The indexes allow you to get your results quickly. The filtering and log passing is the advantage of Logstash.
What is most valuable?
In terms of query resolution, error searching finding and production issues, we're able to find issues quicker. We don't need to manually obtain the logging reports. All bugs in code are quickly identified in the logs as they are in one centralized logging location.
What needs improvement?
We're using the open-source edition, for now, I think maybe they can allow their OLED plugin to be open source, as at the moment it is commercialised. We are planning to go into the production to use the enterprise edition, we just wanted to check how this one works first. I think maybe on the last exercise part, I think the index rotation can be improved. It's something that they need to work on. It can be complex on how the index, all the logs that have been ingested, the index rotation can be challenging, so if they can work on that. In terms of ingestion, I think they should look at incorporating all operating systems. It should be easy to collect logs from different sources without a workaround to push the logs into the system. For example, in AIX, there's no direct log shipper so you do need to do a bit of tweaking there.
For how long have I used the solution?
We have been using ELK Logstash for three years or so. We believe we are using the latest version.
What do I think about the stability of the solution?
The solution is quite stable, although it does need a bit of maintenance, and because there is quite a lot of plugins that come with it. There's a lot of testing that is involved to ensure that nothing breaks.
What do I think about the scalability of the solution?
The solution is scalable. So you're able to extend it and grow it. For example, you're able to put it in a cluster, so it is quite scalable.
How are customer service and technical support?
I have used the technical support. Their forums are quite good in terms of response. There is quite a big community of forums, where you can get similar question or issues that others have experienced issues previously. Even then direct support is quite good. They also have regional support.
Which solution did I use previously and why did I switch?
Logging solution previously, but mainly I've been using Graylog and ELK. Graylog gives you centralized logging. It's built for a logging solution, whereas ELK is designed and built for more big data. If you want to go in deeper into analytics, ELK gives you that flexibility and out of the box models. The two solutions are widely used by a lot of bigger clients in the industry and they've been tried and tested.
How was the initial setup?
With ELK, installation is not really straightforward. There are about three applications to consider. It's quite intense in terms of set up, but once you've done the setup, then it's nice and smooth. The implementation took about 3 weeks, but that is because I was doing it in between other projects. We used an implementation plan. It was deployed to the development environment, then the Point of Concept (POC) environments. It was then deployed into the production environment.
What about the implementation team?
We implemented the solution in-house. There were no third parties involved. For deployment and maintenance, we just need about two to three people and the role is known as maintenance and installation.
What's my experience with pricing, setup cost, and licensing?
We're using the open-source solution, So there are no-cost implications on it, but we are planning to use it throughout the organization. So, we will soon adopt the open-source model and depending on if there is a need for enterprise then we'll go down the enterprise route. If you need a lasting solution, you do need to buy the license for the OLED plugin. The free version comes fully standard and has everything that you need. It is easy to deploy, easy to use, and you get everything you need to become operational with it, and have nothing further to pay unless you want the OLED plugin.
Which other solutions did I evaluate?
We also have Graylog, for Graylog we're using it in parallel for a similar solution. At the moment, we're basically just comparing the two and see which one is preferred.
What other advice do I have?
Do a POC first. They should compare solutions and also look at different log formats they're trying to ingest. See how it really fits with the use case. This goes for ELK and Graylog. You can trial the enterprise version. In terms of lessons learned it does need some time and resources. It also needs adequate planning. You need to follow the documentation clearly and properly. I would give this solution 8 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
I.T. Manager at a healthcare company with 51-200 employees
Analyses your security data quickly and effectively
Pros and Cons
- "Just the ability to do a lot more than just up-down is nice, which a lot of people take for granted."
- "The biggest challenge has been related to the implementation."
What is our primary use case?
We plan to use it to analyze the data that we're pumping into it from Active Directory and from firewalls, then we'll pass that information onto our own external SOC.
What is most valuable?
We really haven't had any significant SIEM solutions, so it's all new to us, other than a simple up-down solution. Just the ability to do a lot more than just up-down is nice, which a lot of people take for granted.
What needs improvement?
The biggest challenge has been related to the implementation. It's a very complex product which, without a lot of knowledge or a lot of training, it's very difficult to get into and make use of. They try and make a lot of the general features very simple to access; a lot of the dashboards are very simple to use and so forth, but a lot of the refined capabilities take serious skills. They're not necessarily the easiest to implement.
For how long have I used the solution?
We've been trying to implement it and get it up and going for a good three to four months now.
What do I think about the stability of the solution?
Elastic SIEM is pretty stable. I did have a problem during one of the upgrades, but customer support was able to resolve it for me quickly. Other than that, it's been very reliable and stable.
How are customer service and technical support?
The customer service is great; not a whole lot of back-and-forth going on.
How was the initial setup?
The initial setup was pretty straightforward.
What's my experience with pricing, setup cost, and licensing?
It's a monthly cost with Elastic SIEM, but I am not sure of the exact cost.
What other advice do I have?
In our case, being a medium-sized business, it takes a lot of resources to learn how to properly use and implement it — you need to have a good understanding. They give you a very good framework and a very good solution to work with, but there's a lot of intuition that's required to actually make it work well. It requires a lot more effort than they would lead you to believe or that you would even expect.
On a scale from one to ten, I would give this solution a rating of eight. This is based on my experiences from the past as we're still implementing it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Elastic Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Log Management Security Information and Event Management (SIEM) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Fortinet FortiEDR
Datadog
Microsoft Sentinel
Splunk Enterprise Security
SentinelOne Singularity Complete
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
IBM Security QRadar
Trellix Endpoint Security Platform
Elastic Observability
Graylog
Buyer's Guide
Download our free Elastic Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- What are the advantages of ELK over Splunk?
- What would you choose for observability: Grafana observability platform or ELK stack?
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?