Elastic Security

By Elastic

4.5 out of 5 stars
3 star
0%
2 star
0%
1 star
0%

How would you rate your experience with Elastic Security?

Elastic Security Pricing Overview

Free Trial

Elastic Security Pricing Reviews

(2)
Verified User in Information Technology and Services
AI
Small-Business (50 or fewer emp.)
"Blazing-Fast KQL/ES|QL and Unified Telemetry with Elastic Defend"
What do you like best about Elastic Security?

The standout feature of Elastic Security is the speed and flexibility of KQL and ES|QL. In high-stakes threat hunts, being able to pivot through massive datasets with near-instant results is critical. The native integration of Elastic Defend is a close second; having endpoint telemetry and SIEM logs in a single schema (ECS) eliminates the "translation tax" usually required when mapping disparate data sources. While the AI Assistant is a great efficiency booster for generating complex queries, the true value lies in the platform’s customizability. Review collected by and hosted on G2.com.

What do you dislike about Elastic Security?

One of the primary challenges with Elastic Security is the heavy administrative overhead required to maintain a healthy environment. Unlike "set-and-forget" SaaS solutions, Elastic requires constant "care and feeding" of ingest pipelines, index lifecycle management (ILM), and shard mapping. If the mapping isn't perfect, you run into mapping explosions or unparsed fields that can render critical logs invisible during a hunt. This complexity often turns a Threat Analyst into a part-time Data Engineer just to ensure the data is searchable.

Another significant pain point is the steep learning curve of the newer query languages. While ES|QL is powerful, the transition from KQL or Lucene creates a temporary efficiency gap for the team. Additionally, the licensing and resource consumption can be unpredictable; since pricing is based on compute and storage (RAM/CPU) rather than just data volume or seats, a poorly written query by a junior analyst or a sudden spike in log volume can lead to performance degradation or unexpected scaling costs that are difficult to budget for in a large-scale SOC.

Finally, the native SOAR capabilities still feel somewhat immature compared to dedicated platforms. While basic automated actions exist, building complex, multi-step response playbooks—especially those involving third-party integrations outside the Elastic ecosystem—can be clunky and often requires external tools to achieve true automation. For a high-tier DFIR workflow, the built-in case management also lacks some of the deeper forensic documentation features needed for evidence chain-of-custody, forcing us to rely on external platforms for formal reporting. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
CI
Mid-Market (51-1000 emp.)
"Easy Alert Management and Powerful Cases for Security Investigations"
What do you like best about Elastic Security?

You can manage the alerts in an easy way. From alerts panel you can have all the information needed for a security investigation. Also, with the cases feature, you can create your own database of alerts Review collected by and hosted on G2.com.

What do you dislike about Elastic Security?

Sometimes, charging is slow, and it's difficult to copy fileds and values from timelines Review collected by and hosted on G2.com.

Elastic Security Comparisons
Product Avatar Image
Apache NiFi
Compare Now
Product Avatar Image
AWS Glue
Compare Now
Product Avatar Image
Azure Data Factory
Compare Now
Product Avatar Image
Elastic Security