2026 Best Software Awards are here!See the list
Elastic Security

By Elastic

4.4 out of 5 stars
3 star
0%
2 star
0%
1 star
0%

How would you rate your experience with Elastic Security?

Elastic Security Reviews & Product Details

Pricing

Pricing provided by Elastic Security.

Elastic Cloud Serverless

Pay As You Go
Per Month
Product Avatar Image

Have you used Elastic Security before?

Answer a few questions to help the Elastic Security community

Elastic Security Reviews (21)

Reviews

Elastic Security Reviews (21)

4.4
21 reviews

Review Summary

Generated using AI from real user reviews
Users consistently praise the software for its reliable performance and ease of setup, making it effective for protecting sensitive data and aggregating logs. The extensive community support and numerous plugins enhance its versatility, although some users note a steep learning curve for initial setup.
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
JS
Senior Cybersecurity Engineer
Small-Business (50 or fewer emp.)
"Powerful, Customisable Security Platform for Complex Environments"
What do you like best about Elastic Security?

What I like best about Elastic Security is the flexibility and depth it gives across SIEM, endpoint, and observability in a single platform. I can ingest almost any data source, normalize it to ECS, and build detections that actually reflect how our environment works—rather than forcing our workflows to fit a rigid tool. The visibility, correlation, and customisation make it especially powerful for real-world SOC operations and complex environments. Review collected by and hosted on G2.com.

What do you dislike about Elastic Security?

What I dislike about Elastic Security is the learning curve and operational overhead, especially for teams new to the Elastic Stack. Getting the most value requires strong knowledge of ECS, ingest pipelines, and cluster tuning, and some advanced use cases still involve a fair amount of manual configuration. The flexibility is powerful, but it can be overwhelming without experienced resources or good upfront design. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
II
Small-Business (50 or fewer emp.)
"Powerful Detection and Deep Visibility with Practical Usability in Elastic Security"
What do you like best about Elastic Security?

Elastic Security stands out for its powerful detection capabilities and deep visibility across endpoints and logs, while still being relatively easy to use once the workflows are understood. Implementation is smooth in environments already using the Elastic stack, and integrations with existing tools are flexible and well-documented. The platform offers a rich set of features for threat detection, hunting, and response that scales well for SOC operations. Customer support and community resources are strong, making troubleshooting manageable. Overall, it’s a feature-dense, frequently used platform that balances advanced capability with practical usability. Review collected by and hosted on G2.com.

What do you dislike about Elastic Security?

The learning curve can be steep at the beginning, especially when tuning detections and managing advanced features without prior Elastic experience. Review collected by and hosted on G2.com.

hector g.
HG
Security Consultant
Mid-Market (51-1000 emp.)
"Prebuilt Rules and Easy Integrations Make Elastic a Strong Choice"
What do you like best about Elastic Security?

I think one of the best things about Elastic is the large set of prebuilt rules created by Elastic themselves.

I also like how the parsing and mapping are really easy to follow and implement, especially when you can find an integration that’s already created for the technology you need to monitor. Review collected by and hosted on G2.com.

What do you dislike about Elastic Security?

What I was missing most was a proper SOAR. I haven’t tried the workflows yet, but I have high expectations for them.

In the past, we tested the AI assistant in the first version and were a bit disappointed. Nowadays, I think it has improved quite a lot.

Another thing I’ve noticed lately is that when using and correlating different log sources, especially through the integrations by Elastic, I sometimes find fields that should match but don’t. For example, Source.ip vs client.ip, or user.name vs source.user.name. This inconsistency has made it quite difficult to correlate threat intelligence with the dashboards. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
AI
Small-Business (50 or fewer emp.)
"Blazing-Fast KQL/ES|QL and Unified Telemetry with Elastic Defend"
What do you like best about Elastic Security?

The standout feature of Elastic Security is the speed and flexibility of KQL and ES|QL. In high-stakes threat hunts, being able to pivot through massive datasets with near-instant results is critical. The native integration of Elastic Defend is a close second; having endpoint telemetry and SIEM logs in a single schema (ECS) eliminates the "translation tax" usually required when mapping disparate data sources. While the AI Assistant is a great efficiency booster for generating complex queries, the true value lies in the platform’s customizability. Review collected by and hosted on G2.com.

What do you dislike about Elastic Security?

One of the primary challenges with Elastic Security is the heavy administrative overhead required to maintain a healthy environment. Unlike "set-and-forget" SaaS solutions, Elastic requires constant "care and feeding" of ingest pipelines, index lifecycle management (ILM), and shard mapping. If the mapping isn't perfect, you run into mapping explosions or unparsed fields that can render critical logs invisible during a hunt. This complexity often turns a Threat Analyst into a part-time Data Engineer just to ensure the data is searchable.

Another significant pain point is the steep learning curve of the newer query languages. While ES|QL is powerful, the transition from KQL or Lucene creates a temporary efficiency gap for the team. Additionally, the licensing and resource consumption can be unpredictable; since pricing is based on compute and storage (RAM/CPU) rather than just data volume or seats, a poorly written query by a junior analyst or a sudden spike in log volume can lead to performance degradation or unexpected scaling costs that are difficult to budget for in a large-scale SOC.

Finally, the native SOAR capabilities still feel somewhat immature compared to dedicated platforms. While basic automated actions exist, building complex, multi-step response playbooks—especially those involving third-party integrations outside the Elastic ecosystem—can be clunky and often requires external tools to achieve true automation. For a high-tier DFIR workflow, the built-in case management also lacks some of the deeper forensic documentation features needed for evidence chain-of-custody, forcing us to rely on external platforms for formal reporting. Review collected by and hosted on G2.com.

"Essential for Our Linux Security"
What do you like best about Elastic Security?

I really appreciate that Elastic Security provides great insight into our system. We can perform good analyses because we run a SOC without direct access to the machines, and for that, the defend function is very useful. Also, the initial installation of Elastic Security was very simple and straightforward. All in all, I am very satisfied and would definitely give Elastic Security a score of 10 as a recommendation to a friend or colleague. Review collected by and hosted on G2.com.

What do you dislike about Elastic Security?

Inventory of the machine which patches are installed Review collected by and hosted on G2.com.

Delonte J.
DJ
Director of Security Engineering and Operations
"Streamlined Security Investigations with Elastic"
What do you like best about Elastic Security?

I appreciate the ability to visualize data and turn it into actionable intelligence with Elastic Security. We use it to create dashboards that monitor our security posture, attack surface, and threat landscape. The integration with our incident management system is seamless, and the setup was simple and straightforward. Elastic Security has allowed our team to conduct investigations more efficiently. Review collected by and hosted on G2.com.

What do you dislike about Elastic Security?

I find building sequencing rules where multiple events must occur in order over a given time challenging. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
CI
Mid-Market (51-1000 emp.)
"Easy Alert Management and Powerful Cases for Security Investigations"
What do you like best about Elastic Security?

You can manage the alerts in an easy way. From alerts panel you can have all the information needed for a security investigation. Also, with the cases feature, you can create your own database of alerts Review collected by and hosted on G2.com.

What do you dislike about Elastic Security?

Sometimes, charging is slow, and it's difficult to copy fileds and values from timelines Review collected by and hosted on G2.com.

Verified User in Government Administration
AG
Mid-Market (51-1000 emp.)
"Flexible, Preconfigured Rules with Integrated Case Management"
What do you like best about Elastic Security?

I like its flexibility, the preconfigured rules, and the integrated case management for sharing information. Review collected by and hosted on G2.com.

What do you dislike about Elastic Security?

It feels a bit complex at first. It’s a large, heavy, and fairly complex infrastructure to maintain on-prem. Review collected by and hosted on G2.com.

AG
Devops engineer
Mid-Market (51-1000 emp.)
"Great Authentication Flexibility, but Anonymous Login Needs Manual Disabling"
What do you like best about Elastic Security?

Elastic xpack secqurity is great for connecting with multipule domain controller or various authentication methord Review collected by and hosted on G2.com.

What do you dislike about Elastic Security?

its still have some drawback like anonymous login ,sepratly need to disable otherwise it will be vernable Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Mid-Market (51-1000 emp.)
"Its good tool with good interface for SIEM"
What do you like best about Elastic Security?

EDR Capability and K8 support along with SIEM Review collected by and hosted on G2.com.

What do you dislike about Elastic Security?

Elastic agent issues, some times seems unhealthy or blocking bussiness actions Review collected by and hosted on G2.com.

No Discussions for This Product Yet

Be the first to ask a question and get answers from real users and experts.

Start a discussion

Pricing Options

Pricing provided by Elastic Security.

Elastic Cloud Serverless

Pay As You Go
Per Month

Elastic Self-managed

Contact Us

Elastic Cloud Hosted

Starting at $99.00
Per Month
Elastic Security Comparisons
Product Avatar Image
Apache NiFi
Compare Now
Product Avatar Image
AWS Glue
Compare Now
Product Avatar Image
Azure Data Factory
Compare Now
Product Avatar Image
Elastic Security