No more typing reviews! Try our Samantha, our new voice AI agent.

Elastic Security vs SentinelOne Singularity AI SIEM comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.0
Elastic Security provides satisfactory ROI and cost savings, though users experience varied support levels and payback periods.
Sentiment score
5.2
SentinelOne SIEM enhances SOC efficiency, reduces investigation times over 50%, and offers value despite higher pricing.
It does not require hefty security budgets and can be deployed for enterprise security effectively.
Assistant Director at PTA
SentinelOne Singularity AI SIEM has reduced our response time to true positive alerts by approximately forty percent through automation.
IT Security Analyst at a tech consulting company with 11-50 employees
At the moment, I feel the pricing is a little bit on the higher side, but the tool is positioned in a place where risk is very high, and we do not want to take chances, so we are prepared to pay the premium.
Group Chief Information Officer at NeST Information Technologies Pvt Ltd
The effect of SentinelOne Singularity AI SIEM on our customers' SOC efficiency in investigating alerts and responding to incidents is significant.
Vice President Cyber Security Practice Head at orbit techsol w pvt.ltd
 

Customer Service

Sentiment score
6.4
Elastic Security support is inconsistent; users favor community and documentation, while premium users seek more responsive and personalized help.
Sentiment score
7.6
SentinelOne Singularity AI SIEM's support is highly rated for responsiveness, AI-based help, and effective problem resolution.
Support is prompt and helpful.
Senior Cyber Security Manager at a tech services company with 11-50 employees
Most of the time when my team encounters issues, they receive responses within 24 hours.
Assistant Director at PTA
I have not faced any difficulties with Elastic Security, as we have a pretty good support service from them.
Chief Product Officer at ClusterPower
SentinelOne Singularity AI SIEM has AI-based technical support available.
IT Security Analyst at a tech consulting company with 11-50 employees
Based on my experience with the technical support of SentinelOne Singularity AI SIEM, I would rate them a ten.
Vice President Cyber Security Practice Head at orbit techsol w pvt.ltd
I would rate the technical support of SentinelOne Singularity AI SIEM a nine.
IT Security Consultant at Systemhaus for you GmbH
 

Scalability Issues

Sentiment score
7.3
Elastic Security offers scalable solutions adaptable to various environments, praised for flexibility and requiring careful planning for integration.
Sentiment score
5.7
SentinelOne Singularity AI SIEM scales efficiently with proper configuration and management, though implementation can be challenging.
It allows us to think about specific use cases, such as gathering malicious IPs in a single view and analyzing threats based on geolocation.
Assistant Director at PTA
Elastic Security is quite scalable.
Chief Product Officer at ClusterPower
With any AI adoption, the end goal should be more governance and data security and safety.
Associate Vice President at Novac Technology Solutions
The performance depends on the configuration.
IT Security Analyst at a tech consulting company with 11-50 employees
It is scalable, and we can increase the compute size. It can scale. There are no challenges.
Vice President Cyber Security Practice Head at orbit techsol w pvt.ltd
 

Stability Issues

Sentiment score
7.7
Elastic Security is generally stable and reliable but can face challenges with big data and requires careful configuration.
Sentiment score
7.7
SentinelOne Singularity AI SIEM is generally praised for stability and fast log searches, though some report past issues.
In terms of stability, I would rate Elastic a solid eight out of ten.
Senior Cyber Security Manager at a tech services company with 11-50 employees
When it comes to stability, I would give SentinelOne Singularity AI SIEM a nine.
IT Security Consultant at Systemhaus for you GmbH
In terms of performance stability, I have never had any crashes, downtimes, or performance issues.
Cyber Security Engineer at a retailer with 201-500 employees
Even the data lake feature they have, in terms of keeping all the logs intact, those log searches are extremely fast on SentinelOne Singularity AI SIEM, even though the data is very high.
Technical Lead at CloudBolt Software
 

Room For Improvement

Elastic Security needs improvements in authentication, usability, automation, scalability, integration, and pricing, with user-friendly dashboards and documentation.
SentinelOne Singularity AI SIEM struggles with stability, integrations, UI issues, high pricing, and requires improved support and automation.
CrowdStrike and Defender have more established threat intelligence integration due to having a larger client base.
Senior Cyber Security Manager at a tech services company with 11-50 employees
My security testing team continuously reports vulnerabilities, and we have to fix and update the versions frequently.
Assistant Director at PTA
Machine learning algorithms become better with time; as they ingest a huge volume of data, they become better.
Chief Product Officer at ClusterPower
The adoption rate will be less compared to other products, as this can be a time-taken process because all my data needs to be offloaded and the system needs to understand my existing alerts, logs, and other things.
Associate Vice President at Novac Technology Solutions
The interface flickers frequently, and sometimes it does not load properly.
IT Security Analyst at a tech consulting company with 11-50 employees
Whenever OT security comes into the picture, the customers do not allow us to integrate their OT devices on a cloud. It should be available on-premises because the OT SIEM market, in the India market for instance, is something around a four to eight billion dollar market.
Vice President Cyber Security Practice Head at orbit techsol w pvt.ltd
 

Setup Cost

Elastic Security provides a free open-source option, competitive pricing, and subscription plans, appealing to cost-conscious enterprises.
The pricing is reasonable, especially for Small Medium Enterprises (SMEs), making it a viable option for businesses building their security infrastructure.
Senior Cyber Security Manager at a tech services company with 11-50 employees
This is beneficial for SMEs as they do not need extensive budgets for security solutions.
Assistant Director at PTA
Elastic Security is considered cost-effective, especially at lower EPS levels.
Performance Practice Specialist at a local government with 10,001+ employees
I find SentinelOne's pricing to be reasonable and competitive.
Information Security Principal at a venture capital & private equity firm with 1,001-5,000 employees
 

Valuable Features

Elastic Security provides scalable, customizable threat response with fast search, real-time analysis, and strong community support for actionable insights.
SentinelOne Singularity AI SIEM enhances threat detection and response efficiency with AI-driven insights and flexible integrations.
Elastic Security offers good insight regarding alerts, reports, and cases.
Senior Cyber Security Manager at a tech services company with 11-50 employees
Elastic Security offers advanced features such as machine learning and integration with ChatGPT.
Performance Practice Specialist at a local government with 10,001+ employees
We require rapid processing speed for alerts and event data, and Elastic Security is very efficient at handling this level of data.
Assistant Director at PTA
We finally have visibility into things that were never visible before.
IT Security Consultant at Systemhaus for you GmbH
It employs a combination of AI and ML to check for viruses or any other malicious processes, including fileless attacks.
Cyber Security Engineer at a retailer with 201-500 employees
The AI-driven threat detection capabilities improve our overall security posture.
Associate Vice President at Novac Technology Solutions
 

Categories and Ranking

Elastic Security
Ranking in Security Information and Event Management (SIEM)
7th
Average Rating
7.8
Reviews Sentiment
6.8
Number of Reviews
66
Ranking in other categories
Log Management (13th), Endpoint Detection and Response (EDR) (19th), Security Orchestration Automation and Response (SOAR) (11th), Extended Detection and Response (XDR) (12th)
SentinelOne Singularity AI ...
Ranking in Security Information and Event Management (SIEM)
13th
Average Rating
8.8
Reviews Sentiment
6.5
Number of Reviews
8
Ranking in other categories
AI Observability (10th)
 

Mindshare comparison

As of June 2026, in the Security Information and Event Management (SIEM) category, the mindshare of Elastic Security is 3.5%, down from 5.9% compared to the previous year. The mindshare of SentinelOne Singularity AI SIEM is 1.4%, up from 0.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Elastic Security3.5%
SentinelOne Singularity AI SIEM1.4%
Other95.1%
Security Information and Event Management (SIEM)
 

Featured Reviews

Laurentiu Popescu - PeerSpot reviewer
Chief Product Officer at ClusterPower
Has improved threat detection with deep log analysis and streamlined investigation workflows
The most useful features I find in Elastic Security are the forensic ones that allow us to carry deeper analysis into the logs for in-depth investigations, and the dashboards, with the reporting dashboard being quite user-friendly. Elastic Security is quite good at identifying threats, as it is part of the deep investigation tool that I mentioned before. Unless we need to look further into a certain log, we can carry out a deeper analysis and forensics on those particular logs. I can assess the impact of Elastic Security's real-time data analysis on our threat response efficiency as working pretty good. We are looking for real-time analysis because we have a continuous inflow of logs from different sources: from our cloud, from Active Directory, from our network. So it works pretty well.
MM
Information Security Principal at a venture capital & private equity firm with 1,001-5,000 employees
Consolidated security operations have improved detection speed and reduced SOC costs
There is room for improvement when it comes to the technical support quality and expertise of SentinelOne. Sometimes, the technical support team does not know how to resolve certain issues and takes time to respond, often requiring follow-up interactions within 24 hours. SentinelOne Singularity AI SIEM can be improved in terms of support capabilities. Some logs from the server side need to be ingested. Secureworks was integrating with domain controllers and other systems, but SentinelOne still has some gaps. Some vendors cannot be integrated directly. For example, we are using Cisco Umbrella for DNS security, and we have to integrate it through an Amazon S3 bucket where we dump the logs and SentinelOne reads them from that location. For some Microsoft integrations, we must enable certain storage components and pay Microsoft directly to retrieve logs. There is no direct integration, so we must access the logs through that workaround. Previously with Secureworks, we had direct integration with Microsoft. Direct integration with Microsoft is not available now. SentinelOne needs to work on many product integrations to enable direct connectivity.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
9%
Financial Services Firm
9%
Government
8%
Computer Software Company
8%
Outsourcing Company
11%
Construction Company
8%
Manufacturing Company
8%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business40
Midsize Enterprise12
Large Enterprise15
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise3
Large Enterprise3
 

Questions from the Community

Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
With Datadog, we have near-live visibility across our entire platform. We have seen APM metrics impacted several times lately using the dashboards we have created with Datadog; they are very good c...
What is your experience regarding pricing and costs for Elastic Security?
I am satisfied with the pricing, setup cost, and licensing cost. It is a pure 10.
What needs improvement with Elastic Security?
I do not have any specific recommendations for improvements in Elastic Security, but I feel that the AI module should get more mature. These machine learning algorithms become better with time; as ...
What needs improvement with SentinelOne Singularity AI SIEM?
I would want the false positive ratio to be lower and would want to improve that aspect so the true will be more, and the false will be lesser. Other than false positives, the true will be increase...
What is your primary use case for SentinelOne Singularity AI SIEM?
We discuss with customers whether they want to go on a cloud or on-premises for the usual use cases of SentinelOne Singularity AI SIEM that I work with mostly. If a customer has a SentinelOne EDR, ...
What advice do you have for others considering SentinelOne Singularity AI SIEM?
Correlation, alerting, reporting, and helping with the AI-based alerts generated by the AI are the usual use cases. The parsing is already built into SentinelOne Singularity AI SIEM. There is no ch...
 

Also Known As

Elastic SIEM, ELK Logstash
No data available
 

Overview

 

Sample Customers

Texas A&M, U.S. Air Force, NuScale Power, Martin's Point Health Care
Information Not Available
Find out what your peers are saying about Elastic Security vs. SentinelOne Singularity AI SIEM and other solutions. Updated: June 2026.
900,747 professionals have used our research since 2012.