What is our primary use case?
In Pakistan, the telecom sector requires centralized monitoring for all telecom operators and ISPs. All cellular mobile operators or internet service providers have their own SOCs or
SIEM solutions, and we have integrated their security solutions with
Elastic Security.
What is most valuable?
The processing part of
Elastic Security is very interesting for us since we handle almost 7,000 to 8,000 alerts per minute. We require rapid processing speed for alerts and event data, and Elastic Security is very efficient at handling this level of data. Additionally, Elastic Security helps improve the security posture of Pakistan through centralized visibility and real-time processing.
What needs improvement?
Continuous upgrades can be quite inconvenient. My security testing team continuously reports vulnerabilities, and we have to fix and update the versions frequently. This involves addressing three to four vulnerabilities every month.
For how long have I used the solution?
We have been using Elastic Security for almost three years.
What was my experience with deployment of the solution?
I am not directly involved in the installation process, but the installation part typically takes one to two hours, maybe one and a half hours at max.
What do I think about the scalability of the solution?
Elastic Security handles our data analysis needs well. It allows us to think about specific use cases, such as gathering malicious IPs in a single view and analyzing threats based on geolocation.
How are customer service and support?
The technical support for Elastic Security is quite responsive. Most of the time when my team encounters issues, they receive responses within 24 hours.
How would you rate customer service and support?
How was the initial setup?
The initial setup is quite straightforward. It takes about one to two hours for installation.
What about the implementation team?
I have a dedicated deployment team consisting of a senior and a junior resource and four resources on an ad hoc basis for systems configuration, networking, and installation.
What was our ROI?
Elastic Security is community-based and particularly beneficial for security scholars and SMEs. It does not require hefty security budgets and can be deployed for enterprise security effectively.
What's my experience with pricing, setup cost, and licensing?
Since Elastic Security is community-based, it does not require significant costs. This is beneficial for SMEs as they do not need extensive budgets for security solutions.
What other advice do I have?
We have almost four hundred fifty licenses, and every time I visit PTA licensees, I recommend they research and develop on Elastic Security for deployment. The overall product rating I would give Elastic Security is nine.
Which deployment model are you using for this solution?
On-premises