It unifies SIEM, endpoint protection, and threat hunting on one platform, backed by Elasticsearch's fast search across huge volumes of security data. Hundreds of prebuilt, open detection rules mapped to MITRE ATT&CK, built-in ML anomaly detection, and AI-assisted investigation help us detect and respond to threats quickly without juggling multiple tools. Review collected by and hosted on G2.com.
Detection rules need significant tuning to cut false positives, and setup and cluster management demand strong expertise. The interface can feel complex for new analysts, and resource and storage costs rise quickly as log ingestion grows. Review collected by and hosted on G2.com.