

Elastic Security and SentinelOne Singularity AI SIEM are leading competitors in the cybersecurity market. Among these, SentinelOne is perceived as superior due to its comprehensive features, which justify its higher pricing.
Features: Elastic Security offers advanced threat hunting, integration with existing infrastructure, and scalability with open-source components. SentinelOne Singularity AI SIEM provides AI-powered automation, deep visibility, hyper-automation, and strong endpoint protection, setting it apart with broader AI-driven capabilities.
Room for Improvement: Elastic Security could benefit from enhancing user-friendliness for non-technical users, introducing more intuitive dashboards, and simplifying configuration for advanced use cases. SentinelOne can improve by expanding its integration catalog, refining the interface for ease of use, and enhancing its documentation for better user guidance.
Ease of Deployment and Customer Service: Elastic Security is recognized for its flexible deployment models and community support, though it requires some technical expertise. SentinelOne offers streamlined deployment and comprehensive customer support, praised for its intuitive setup process.
Pricing and ROI: Elastic Security offers a lower initial setup cost, yielding significant ROI through its scalable architecture and open-source elements. SentinelOne, despite being more costly upfront, is seen as providing strong ROI due to its extensive features and threat management efficiency.
It does not require hefty security budgets and can be deployed for enterprise security effectively.
SentinelOne Singularity AI SIEM has reduced our response time to true positive alerts by approximately forty percent through automation.
At the moment, I feel the pricing is a little bit on the higher side, but the tool is positioned in a place where risk is very high, and we do not want to take chances, so we are prepared to pay the premium.
The effect of SentinelOne Singularity AI SIEM on our customers' SOC efficiency in investigating alerts and responding to incidents is significant.
Support is prompt and helpful.
Most of the time when my team encounters issues, they receive responses within 24 hours.
I have not faced any difficulties with Elastic Security, as we have a pretty good support service from them.
SentinelOne Singularity AI SIEM has AI-based technical support available.
Based on my experience with the technical support of SentinelOne Singularity AI SIEM, I would rate them a ten.
I would rate the technical support of SentinelOne Singularity AI SIEM a nine.
It allows us to think about specific use cases, such as gathering malicious IPs in a single view and analyzing threats based on geolocation.
Elastic Security is quite scalable.
With any AI adoption, the end goal should be more governance and data security and safety.
The performance depends on the configuration.
It is scalable, and we can increase the compute size. It can scale. There are no challenges.
In terms of stability, I would rate Elastic a solid eight out of ten.
When it comes to stability, I would give SentinelOne Singularity AI SIEM a nine.
In terms of performance stability, I have never had any crashes, downtimes, or performance issues.
Even the data lake feature they have, in terms of keeping all the logs intact, those log searches are extremely fast on SentinelOne Singularity AI SIEM, even though the data is very high.
CrowdStrike and Defender have more established threat intelligence integration due to having a larger client base.
My security testing team continuously reports vulnerabilities, and we have to fix and update the versions frequently.
Machine learning algorithms become better with time; as they ingest a huge volume of data, they become better.
The adoption rate will be less compared to other products, as this can be a time-taken process because all my data needs to be offloaded and the system needs to understand my existing alerts, logs, and other things.
The interface flickers frequently, and sometimes it does not load properly.
Whenever OT security comes into the picture, the customers do not allow us to integrate their OT devices on a cloud. It should be available on-premises because the OT SIEM market, in the India market for instance, is something around a four to eight billion dollar market.
The pricing is reasonable, especially for Small Medium Enterprises (SMEs), making it a viable option for businesses building their security infrastructure.
This is beneficial for SMEs as they do not need extensive budgets for security solutions.
Elastic Security is considered cost-effective, especially at lower EPS levels.
I find SentinelOne's pricing to be reasonable and competitive.
Elastic Security offers good insight regarding alerts, reports, and cases.
Elastic Security offers advanced features such as machine learning and integration with ChatGPT.
We require rapid processing speed for alerts and event data, and Elastic Security is very efficient at handling this level of data.
We finally have visibility into things that were never visible before.
It employs a combination of AI and ML to check for viruses or any other malicious processes, including fileless attacks.
The AI-driven threat detection capabilities improve our overall security posture.
| Product | Mindshare (%) |
|---|---|
| Elastic Security | 3.5% |
| SentinelOne Singularity AI SIEM | 1.4% |
| Other | 95.1% |

| Company Size | Count |
|---|---|
| Small Business | 40 |
| Midsize Enterprise | 12 |
| Large Enterprise | 15 |
| Company Size | Count |
|---|---|
| Small Business | 5 |
| Midsize Enterprise | 3 |
| Large Enterprise | 3 |
Elastic Security stands out for its speed, scalability, and intuitive interface. It integrates seamlessly with Elasticsearch and Kibana, providing efficient data indexing, centralized log management, and intelligent threat identification, all while being open-source.
Elastic Security offers robust capabilities in security monitoring, threat identification, and SIEM functionalities. Its open-source nature enhances scalability, facilitating log aggregation and infrastructure monitoring. Users appreciate the intuitive dashboards and machine learning integration, which aid in proactive security measures and anomaly detection. Despite its strengths, improvements are needed in documentation, scalability, and configuration complexity. High data volume pricing and limited machine learning support are concerns, while dashboard enhancement and seamless integration with existing systems are desirable. The platform is widely used for alerting suspicious activities, analyzing logs from firewalls and Active Directory, and providing endpoint protection. It serves as a key tool for security awareness and auditing, integrating effectively with technologies like Kibana and OpenShift.
What are the most notable features of Elastic Security?Organizations deploy Elastic Security across industries for log aggregation and security monitoring, detecting unauthorized access, and analyzing system logs. It is essential for infrastructure monitoring and integrates effectively with systems such as Fluentd and OpenShift, supporting comprehensive security views across enterprise environments.
SentinelOne Singularity AI SIEM offers comprehensive security information and incident management designed to enhance threat detection, response, and investigation capabilities within enterprise environments.
SentinelOne Singularity AI SIEM is known for its robust capabilities in the realm of cybersecurity, providing organizations with an advanced tool to combat modern threats. The platform integrates machine learning and artificial intelligence to automate threat identification and streamline incident response processes. Its intuitive interface allows teams to manage security events efficiently, ensuring rapid reaction to potential vulnerabilities. As a scalable tool, it adapts to evolving security demands, providing valuable insights to safeguard critical business operations.
What are the important features of SentinelOne Singularity AI SIEM?In industries such as finance and healthcare, implementation of SentinelOne Singularity AI SIEM often means tailored solutions to protect sensitive data, meeting regulatory compliance. These sectors appreciate its capability to provide detailed insights and reduce the risk of data breaches, thus preserving stakeholder trust.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.