Great if you have the engineering to run it
3.8/5overall, average of the five axes
Deployment effort3
Support quality3
Features vs promises4
Pricing transparency5
Return on investment4
What happened
We already ran Elastic for logs so extending into security was a small step and the cost model is much kinder than per-GB SIEMs. Detection rules are open and readable, which our detection engineers love. It is not managed for you: cluster sizing, ILM policies and upgrades are your problem, and that is a real staffing cost people forget when they compare the licence line.
Worked well
Cost model. Open detection rules. Same stack as our observability data.
Did not
You operate the cluster. Upgrades need care. Fewer out-of-box integrations than commercial SIEMs.
0 found this helpful