
Elasticsearch is a fantastic search and analytics platform. It’s easy to use as a SIEM tool, and creating exceptions is straightforward. I really appreciate the ECS field schemes, the agent/fleet/integrations setup, and the quality of support. These features make the platform flexible and enjoyable to work with.
i use elastic every day with our siem
it's easy to setup without certificates Review collected by and hosted on G2.com.
The documentation could be improved—especially around “detection as code,” which is difficult to set up and barely documented. Having “exceptions as code” would also be a great addition. I miss certain features that competitors like Wazuh provide, such as a built-in vulnerability scanner. Another gap is the lack of community-driven blogs and integration examples (like those published on Medium by SOCFortress for Wazuh). Finally, I find it strange that certain wildcard searches (e.g., *test* across large datasets like Palo Alto logs) can crash the entire stack.
i would expect for small bussiness, there should be an automatic rotation and trust for certificates between clients and fleet server, our between nodes. Review collected by and hosted on G2.com.