No more typing reviews! Try our Samantha, our new voice AI agent.
SoheylNorozi - PeerSpot reviewer
IT Consultant at a tech services company with 51-200 employees
Real User
Top 20
Jul 19, 2023
A cloud-native compatible solution that has challenges with scaling and upgrading
Pros and Cons
  • "The solution is compatible with the cloud-native environment and they can adapt to it faster."
  • "Elastic Security's maintenance is hard and its scalability is a challenge. There are complications in scaling and upgrading. The solution needs to also provide periodic upgrade checks."

What is most valuable?

The solution is compatible with the cloud-native environment and they can adapt to it faster. 

What needs improvement?

Elastic Security's maintenance is hard and its scalability is a challenge. There are complications in scaling and upgrading. The solution needs to also provide periodic upgrade checks. 

For how long have I used the solution?

I have been working with the solution for four years. 

What do I think about the stability of the solution?

The product is stable. 

Buyer's Guide
Elastic Security
September 2026
Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
912,930 professionals have used our research since 2012.

How was the initial setup?

The product's initial setup is straightforward but experts need to do it. 

What's my experience with pricing, setup cost, and licensing?

The base product is open-source but if you need advanced security features then you need to pay for the subscription. Elastic Security's price is reasonable in some cases and in other cases it's not. 

What other advice do I have?

I would rate the tool a seven out of ten. The solution has a very active community with troubleshooting cases. You need to consider the growth rate and environmental complexity when buying the product. If you need to use a multi-node or cluster version, then install it during initiation itself. So that you don't need to do the same procedure in the next three to six months. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Lead Enterprise Architect at DigyCorp
Real User
Top 10
Jul 4, 2023
A flexible and open solution that supports varieties of integrations
Pros and Cons
  • "The product has huge integration varieties available."
  • "The tool needs to integrate with legacy servers. Big companies can have legacy servers that may not always be updated."

What is most valuable?

The product has huge integration varieties available. 

What needs improvement?

The tool needs to integrate with legacy servers. Big companies can have legacy servers that may not always be updated. 

For how long have I used the solution?

I have been working with the solution for the last eight months. 

What do I think about the scalability of the solution?

The solution is scalable and flexible. My company has 20 users for the product. 

How are customer service and support?

We had relied on in-house support initially. However, we understand now that there are a few areas where we need to have vendor support. So we have contacted a few different companies and contractors for it. In the beginning, it may be possible to do support in-house. However, if you have a lot of commercial production environment services, then it is very hard to do without vendor support. 

Which solution did I use previously and why did I switch?

We decided to use the solution because it was a very promising tool and other alternatives had limitations. The tool has availability, data infrastructure, data uptime, etc. The solution is quite flexible in terms of cost. You don't need to buy a license for each and everything. Whenever you require a license, you can just buy it. I think these are the two main drivers. The product is quite open in terms of integration with machine learning which helps us with proactive monitoring. 

How was the initial setup?

The product's initial setup is very easy. I think the most important point is how you design your infrastructure because the solution is quite open. So you have to design it based on the nature of the data. You also need to get a life cycle so that there is no load on the storage. The solution's flexibility depends on how you design it. 

What's my experience with pricing, setup cost, and licensing?

The tool's pricing is flexible and comes at unit cost. You don't have to pay for everything. 

What other advice do I have?

I would rate the product an eight out of ten. You should use the solution if you want to have a very detailed machine-learning artificial intelligence. However, for certain production licenses, you need to prepare. It is open to different configurations and can just fit according to your requirements. This is one of the solution's good parts. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Elastic Security
September 2026
Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
912,930 professionals have used our research since 2012.
reviewer2198715 - PeerSpot reviewer
DevOps Engineer at a tech services company with 51-200 employees
Real User
Jun 7, 2023
Efficiently handle millions of loads simultaneously
Pros and Cons
  • "It can handle millions of loads at a time, and you can always use the filters to find exactly what you are looking for and detect errors in every log message you are searching for, basically."
  • "There is an area of improvement in the Logs list. The load list may need to be paginated as there are limits."

What is our primary use case?

We are using Elastic Security for logging the application logs, as we use a microservice architecture. So all application logs are saved to this LogSpot.

How has it helped my organization?

It helps us detect errors and keep an eye on the application in both the development and production environments.

What is most valuable?

It can handle millions of loads at a time, and you can always use the filters to find exactly what you are looking for and detect errors in every log message you are searching for, basically.

What needs improvement?

There is an area of improvement in the Logs list. The load list may need to be paginated as there are limits. So if you are looking for logs for a specific application, you may get 50 lines of logs, but then you are lost. You need to add more features to specify your request so you can get the final result. It would be better to have additional features to specify your request and get the complete result.

For how long have I used the solution?

I have been using this solution for nine months. Although, I am not using the latest version. 

What do I think about the stability of the solution?

I would rate the stability a nine out of ten. 

What do I think about the scalability of the solution?

I would rate the scalability an eight out of ten. 

What was our ROI?

We definitely saw an ROI. It quickly finds the bugs.

What other advice do I have?

I would recommend using it, especially if you have a microservice architecture. I also have a friend who has been using it for some big data projects, so I would recommend it for that as well. 

Overall, I would rate the solution a nine out of ten. 

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sudeera Mudugamuwa - PeerSpot reviewer
Co-Founder at a tech vendor with 51-200 employees
Real User
Jun 2, 2023
It's a scalable REST API-based solution
Pros and Cons
  • "We like Elastic Security because it's a REST API-based solution. That's the primary reason we use it."
  • "I would like more ways to manage permissions and restrict access to certain users."

What is our primary use case?

We use Elastic Security to manage logs and time series data. More recently, we have used it for NetFlow data. 

What is most valuable?

We like Elastic Security because it's a REST API-based solution. That's the primary reason we use it. 

What needs improvement?

I would like more ways to manage permissions and restrict access to certain users. 

For how long have I used the solution?

We started using Elastic Security four years ago. 

How was the initial setup?

The setup is comparable to similar products. It isn't too easy or hard. We deployed it in-house. 

Which other solutions did I evaluate?

We tried Graylog and a few other things, but I found Elastic Security is easier to understand. There's a lot of documentation available, and their forums are great. Another advantage is greater scalability. 

What other advice do I have?

I rate Elastic Security nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1411278 - PeerSpot reviewer
Big Data Team Leader at a tech services company with 51-200 employees
Real User
Apr 10, 2023
Easy to use across different use cases but stability depends on your design of implementation
Pros and Cons
  • "The most valuable thing is that this solution is widely used for work management and research. It's easy to jump into the security use case with the same technology."
  • "In terms of improvement, there could be more automation in responding to and evaluating detections."

What is our primary use case?

Elastic Security is usually used to deliver and analyze logs for security teams. Some common use cases include search and analytics of log data from the system and sending it to other components. We are using features like point security and detection of gathering data.

How has it helped my organization?

The most valuable thing is that this solution is widely used for work management and research. It's easy to jump into the security use case with the same technology. Also, it's valuable from an operational point of view as you have the same knowledge of how to operate it, how to work management, search, and security instance.

What is most valuable?

The important part is that it's free of charge usage. For our use case, it's enough, and it's for a good cost because the basic level of the solution is free.

What needs improvement?

In terms of improvement, there could be more automation in responding to and evaluating detections. Additionally, there could be some sort of intelligent database checking for better effects. Overall, I think there could be more automation.

For how long have I used the solution?

I have been using Elastic Security for four years now. When it started because we were working with Endgame before it merged with Elastic.

What do I think about the stability of the solution?

I rate the stability an eight out of ten because it depends on the design and how well you monitor it.

What do I think about the scalability of the solution?

I would rate the scalability a ten out of ten; it is a very scalable solution. We work with enterprise-level companies.

How are customer service and support?

The customer support is good. You have support from all project stages, beginning with the architecture. And after you roll out the solution, you have dedicated technical staff for the project.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup depends on what you were expecting, but since we have experience with it and know what it's good for, it's an eight out of ten. The initial deployment typically takes about a day. Then there's an initial stage of the project to integrate some of the client's specific requirements, which can take additional time depending on the complexity of their environment.

When it comes to maintenance, it depends on the project, and sometimes one person can support all roles.

Usually, it's enough to have one engineer with deep technical knowledge of the operating system and the deployment and configuration of the system. The other role is an analytical role with project management and coordination skills to communicate with customers and drive delivery.

What about the implementation team?

We implement Elastic Security in our customer's environment. We are like a consulting company. Depending on their preference, the initial deployment could be on their internal cloud, on-premises, or on hardware visualization. The advantage of this solution is that it can be deployed anywhere, including public clouds, private clouds, on-premises, bare metal, and even on Kubernetes.

The deployment takes a few days, and in the initial stage of projects, it could take two months with some integrations to the system, setting some rules, and so on. But it also depends on our customers and how familiar they are with it and what they want.

Usually, we start with a small installation with a bit fewer sources, install the initial setup, and gather information from selected systems such as legacy systems, infrastructure systems, custom applications, and so on running in the customer environment. Then we show how our solution behaves, how it grows, and what is the expected volume of data. We plan the next iterations to extend the hardware deployment. As users start using the platform and become familiar with it, they can set their requirements for implementing iterations. Then we shape the infrastructure and implement some rules, detections, machine learning, and other features.

We prefer to move forward very fast with no big analytics because customers usually don't know what is happening in their systems, and with this approach, we are showing them what they need to focus on.

What other advice do I have?

I would say you don't spend too much time evaluating and comparing it with other products. Just start with it because you can begin for free and gain knowledge. It's the best approach.

It's also a good idea to run it next to other solutions, like Splunk or QRadar, or something else, and compare how you can use this platform. We have also done some migration projects from these platforms to Elastic Security. Initially, some expectations were that it could not be as good for the price because it's free or cheaper, but surprisingly, we found it valuable and easy to use.

Overall, I rate it a seven out of ten because some features are still missing. However, it's a developing platform and technology that is a good investment for the future. Every release adds new features, and the platform fits future requests and changing IT landscapes, like cloud environments. There are no limits, and it's an open platform that can serve all needs.

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Mustafa Husny - PeerSpot reviewer
Senior System Engineer at Techline-eg
Real User
Jan 31, 2023
High level security, open-source, but lacking documentation
Pros and Cons
  • "The most valuable features of Elastic Security are it is open-source and provides a high level of security."
  • "Elastic Security could improve the documentation. It would help if they were more simple and clean."

What is our primary use case?

We are using Elastic Security as part of the Elastic Search component. The solution provides us with security, such as threat protection.

What is most valuable?

The most valuable features of Elastic Security are it is open-source and provides a high level of security.

What needs improvement?

Elastic Security could improve the documentation. It would help if they were more simple and clean.

For how long have I used the solution?

I have used Elastic Security for approximately two years.

What do I think about the scalability of the solution?

We have one person using this solution.

How are customer service and support?

I have used the community support for Elastic Security. Sometimes the support is helpful and sometimes it is not.

Which solution did I use previously and why did I switch?

I have used other similar solutions in the past.

How was the initial setup?

The initial setup of Elastic Security is straightforward. However, the documentation could improve. The deployment can be done in approximately 15 minutes.

What was our ROI?

I have seen a return on investment using this solution.

What other advice do I have?

The solution can take up to 20 minutes to maintain when needed.

I rate Elastic Security a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Tiodor Jovovic - PeerSpot reviewer
Chief Business Officer at Sky Express
Real User
Dec 12, 2022
Open-source with a good knowledge base and a helpful community
Pros and Cons
  • "It's open-source and free to use."
  • "We'd like to see some more artificial intelligence capabilities."

What is our primary use case?

Basically, we are using this product for monitoring and for developing the processes for our company.

What is most valuable?

I like that there is a knowledge base. There's the possibility for technical people to develop this product and to know much more. However, they do not need additional certifications from the vendor side or to pay a lot of money for their courses and certifications. We don't need to rely on vendors. We can handle the product ourselves. 

It's open-source and free to use.

What needs improvement?

The solution isn't really recognized in the market. They need to do a better job when they are marketing the solution. We'd like customers to have more visibility of it, and we'd like them to see how secure and highly effective it is. There needs to be more brand awareness. 

We have faced some obstacles when handling the implementation process. 

There are no templates available when integrating with other products. We sometimes need to find some workarounds. 

We'd like to see some more artificial intelligence capabilities.

For how long have I used the solution?

I've been using the solution for four and a half years. 

What do I think about the stability of the solution?

The solution is stable and reliable. We found the product to be very usable. There are no bugs or glitches, and it doesn't crash or freeze. 

What do I think about the scalability of the solution?

The solution can scale. Integration with other products may be a bit difficult, yet it is doable. 

How are customer service and support?

If we need assistance, we tend to use the community. There is always somebody in the world who can help us if we have a question. There are many people that can provide good tips and useful advice. Typically, many people have faced the same problems and they can help us solve things. 

Which solution did I use previously and why did I switch?

I'm also aware of Curator. 

Compared to Curator, customer awareness isn't as strong. From the price perspective, this product is better, however, many customers don't want to change their own CM and their products if they already have something in place.

How was the initial setup?

The initial setup wasn't overly complex or difficult. That said, it wasn't simple either. It's somewhat moderate in terms of implementation.

I'd rate the solution three out of five in terms of ease of setup. 

What's my experience with pricing, setup cost, and licensing?

This is an open-source solution. It is free to use. 

What other advice do I have?

For new customers, this is a perfect choice. For older customers, it's very difficult to change solutions.

I'd rate the solution eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Consultant at a tech services company with 51-200 employees
Real User
Top 20
Oct 19, 2022
Straightforward to set up, and has a good search capability, in particular, its way of writing the search query and the speed of searching for results
Pros and Cons
  • "What customers found most valuable in Elastic Security feature-wise is the search capability, in particular, the way of writing the search query and the speed of searching for results."
  • "In comparison with other similar solutions in the market, customers go with Elastic Security because of its scalability and its good performance."
  • "An area for improvement in Elastic Security is the pricing. It could be better. Right now, when you increase the volume of logs to be collected, the price also increases a lot."

What is our primary use case?

My customers use Elastic Security for security monitoring, threat hunting, and threat identification.

What is most valuable?

What customers found most valuable in Elastic Security feature-wise is the search capability, in particular, the way of writing the search query and the speed of searching for results.

What needs improvement?

An area for improvement in Elastic Security is the pricing. It could be better. Right now, when you increase the volume of logs to be collected, the price also increases a lot.

For how long have I used the solution?

I've been working with Elastic Security for four to five years now.

What do I think about the stability of the solution?

Elastic Security is a stable solution.

What do I think about the scalability of the solution?

In terms of scalability, Elastic Security is pretty scalable.

How are customer service and support?

I haven't escalated any issues with the Elastic Security technical support team.

Which solution did I use previously and why did I switch?

In comparison with other similar solutions in the market, customers go with Elastic Security because of its scalability and its good performance. The solution has a good search feature, especially when a large volume of logs needs to be collected. Elastic Security also gives you pretty good results compared to other solutions.

How was the initial setup?

The initial setup for Elastic Security is quite straightforward. For the cloud version of the solution, it's easy because it requires no installation. If you're setting up the on-premises version of Elastic Security, then it would take around three to four days to complete.

What's my experience with pricing, setup cost, and licensing?

The licensing cost of Elastic Security is based on the daily ingestion rate. I can't recall the exact figure, but for 10GB of log action daily, it would cost around $20,000.

What other advice do I have?

I've had customers for Elastic Security in the last twelve months.

Elastic Security requires maintenance, especially in a scaled-up environment, because you have multiple machines that work in a cluster environment, so you'll need some advanced skills to maintain that cluster. The solution becomes harder to maintain once it's scaled up.

Elastic Security is a pretty straightforward solution I'd recommend to others, though you'd need a person who'll pick up the query or search language because Elastic Security requires a lot of query language, so you can search for data on it. There's a special search query pattern you have to remember before you can do the search or for you to do a better search. You can always do a normal search on Elastic Security, but if you want to have better search results or more accurate results, you need to learn the query language first.

My rating for Elastic Security is eight out of ten because of its good performance and scalability. Its good search feature is very important for the use cases of my customers, but I deducted two points because the pricing for Elastic Security could still be improved.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1596219 - PeerSpot reviewer
Engineer at a tech services company with 501-1,000 employees
Real User
Jul 14, 2022
Integrates into the overall ELK Stack, scans for vulnerabilities well and offers good performance
Pros and Cons
  • "We chose the product based on the ability to scan for malware using a malware behavioral model as opposed to just a traditional hash-based antivirus. Therefore, it's not as intensive."
  • "We like the detailed investigation features of the platform as you're able to get a lot of detail as to what's going on on the host when you do investigations."
  • "It could use maybe a little more on the Linux side."
  • "I would say that right now the Linux feature set is a little limited."

What is most valuable?

We really like that it integrates into the overall ELK Stack, and we're using that as our theme. We were looking for a product compatible with that. We like the detailed investigation features of the platform as you're able to get a lot of detail as to what's going on on the host when you do investigations. We like the quarantine feature.

We chose the product based on the ability to scan for malware using a malware behavioral model as opposed to just a traditional hash-based antivirus. Therefore, it's not as intensive. We have a lot of satellite communications, and it's not as intensive since we don't require updates to calm down on a regular basis for updated DAT files for hashes on a regular basis. We only have to update quarterly against the new malware model. It's also a lot less impactful from a performance perspective on a machine.

What needs improvement?

It's a pretty solid product. It's pretty easy to use as it's not a full endpoint protection suite. We're actually dependent on using Windows Defender for a firewall and traditional antivirus when it's required. It could use maybe a little more on the Linux side. Now that the product line is getting picked up by Elastic, they're going to continue to build out and make the Linux feature set more robust. However, I would say that right now the Linux feature set is a little limited.

For how long have I used the solution?

I've been using the solution for about a year.

What do I think about the stability of the solution?

Stability is very good. It's a very stable product. We haven't had any issues with stability at all.

What do I think about the scalability of the solution?

For what we use it for, scalability has been great. Our environments tend to be smaller. We're only talking about 200 to 1,000 systems. Therefore, I don't know that I could speak to a real large scale since that's not our implementation level.

We are kind of in an interesting use case as we're not actually using it on a day-to-day basis. We are a production house, and we shift suites out to customers to use. As far as what the user feedback is on a regular basis, we don't really see a ton of that unless we kind of go out and hunt for it.

Which solution did I use previously and why did I switch?

We're using the Microsoft Defender product. It's just what's embedded inside of the operating system. It's not the full Defender for Endpoint. It's just Windows and antivirus.

How was the initial setup?

The Endgame itself is extremely straightforward to set up and you just filled out the ISO and you follow a couple of wizards you're done. It's very easy. I would say the ELK Stack is a little more complicated, however, that's due to the way we implement PKI in our environment. The product in itself is fairly straightforward to implement. It's our choice of certificate implementation that's making it a little more complicated.

We targeted it to be able to be maintained by one person. In a lot of cases, our scenario is that we only have one person available to maintain the product. It's very easy to maintain. There's not a ton going on. In a scene, you always have to have somebody watching the log of traffic if you want it to be effective. However, outside of that, there's no extreme maintenance associated with the product.

What's my experience with pricing, setup cost, and licensing?

I do not know approximately how much it costs per month or per year. I'm not the one who makes the purchases.

What other advice do I have?

We are just customers. 

I'd rate the solution an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Principal Cyber Security Manager at Ask4key
Real User
Jun 28, 2022
Valuable prevention methods and asset alerts, but room for improvement in the Kibana dashboard and asset management
Pros and Cons
  • "The most valuable features of the solution are the prevention methods and the incident alerts."
  • "I would say that, on average, a good ROI can be seen within one and a half to two years after deploying Elastic Security."
  • "There is room for improvement in the Kibana dashboard and in the asset management for the program."
  • "The solution is stable if you don't touch it too much. Meaning, it's technically stable, but if there is a period of downtime, you will face quite a big hiccup in getting it running again and stabilized."

What is our primary use case?

My clients use this solution for security purposes and SIEM and log management.

What is most valuable?

The most valuable features of the solution are the prevention methods and the incident alerts. 

What needs improvement?

There is room for improvement in the Kibana dashboard and in the asset management for the program.

For how long have I used the solution?

I've been working with Elastic Security for almost two years now.

What do I think about the stability of the solution?

The solution is stable if you don't touch it too much. Meaning, it's technically stable, but if there is a period of downtime, you will face quite a big hiccup in getting it running again and stabilized.

What do I think about the scalability of the solution?

The scalability of Elastic is amazing. 

How are customer service and support?

I would say the technical support isn't really good or bad. On a scale of one to ten, I would give it a five. 

How would you rate customer service and support?

Neutral

How was the initial setup?

The setup can sometimes be quite complex for the backend team. It all depends on the client's environment, so we have to be flexible.

What about the implementation team?

My company provides a team for deployment, which usually consists of at least three or four engineers. Deployment generally takes six months to one year.

What was our ROI?

I would say that, on average, a good ROI can be seen within one and a half to two years after deploying Elastic Security. 

What's my experience with pricing, setup cost, and licensing?

Licensing for the solution is available as a one-year or three-year plan, and all of the features are included.

What other advice do I have?

I would rate this solution as a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Elastic Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free Elastic Security Report and get advice and tips from experienced pros sharing their opinions.