Elastic Security Initial Setup

Don Jarmon - PeerSpot reviewer
Information Security Manager at Huntsville Utilities

The ease or complexity a user may experience during the product's initial setup phase depends on that user's experience with the platform. As I am a person who is familiar with log formats and different systems, along with the experience of having done previous integrations on different systems, it helped me deal with the implementation part of the product. I would say that the initial deployment process is a bit complex in general.

The solution is deployed on the cloud.

View full review »
Nikhil-Kumar - PeerSpot reviewer
Assistant Manager - IT Security at Photon inc

The initial setup can be complex if you don't have technical knowledge. However, once it is deployed, it works well. 

I'm not sure how long it took to deploy. I wasn't there when it was set up and configured. 

We have an internal team that handles deployment and maintenance. It doesn't require too many people to deploy. Five or six people would be enough. However, for 24/7 monitoring, you need to have someone always on it. 

View full review »
CC
Cyber Security Engineer II at a healthcare company with 10,001+ employees

Elastic Security's initial setup is not easy. We've had to hire an entire team, and it's taken over a year and a half to set up the solution.

View full review »
Buyer's Guide
Elastic Security
May 2024
Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
770,292 professionals have used our research since 2012.
Matthew DeGrandis - PeerSpot reviewer
System Administrator at a financial services firm with 11-50 employees

Setting up Elastic Security is complex in some ways. Getting the solution to ingest your logs is the most difficult part. If the logs are of little value or you're holding on to those events for too long, they're not really worth as much. They're not as actionable if they're a month or a year old.

View full review »
SA
Consultant at a computer software company with 5,001-10,000 employees

I was not there when the deployment was done, but based on what I have heard, it was complex because of the server deployment and cluster formation, and it took at least two months.

View full review »
Janis Cimins - PeerSpot reviewer
Information Technology Security Specialist at IPro SIA

Elastic Security's initial setup is easy.

View full review »
. - PeerSpot reviewer
Governance and Compliance Manager at NBS Bank

The initial setup is straightforward. The deployment is fast. It only takes a few seconds to get up and running. 

View full review »
Prasanth Prasad - PeerSpot reviewer
Director of Technology at a tech vendor with 11-50 employees

I rate the initial setup phase a six or seven on a scale of one to ten, where one is difficult and ten is easy.

The product's initial setup phase is neither easy nor difficult. It is easy to manage the setup phase if you know how to do it correctly. Complexity comes along as a part of the tool, especially if it is powerful and has a lot of capabilities. If it is very easy to manage the setup phase of a tool, then it is bound to have some limitations.

The solution is deployed on the cloud, on-premises model, or a hybrid cloud.

It can take a few days to get the product up and running. The time required to deploy the tool depends on the use cases of the user.

View full review »
Sinan ŞENGÖR - PeerSpot reviewer
Solutions Consultant at a tech services company with 5,001-10,000 employees

The solution is straightforward to set up. They have documentation on their site that shows how to do everything step by step. Everything is very clear and easy to understand. I'd rate the overall ease of implementation nine out of ten. 

The deployment is fast and only takes hours, not days. 

View full review »
MF
Chief Operating Officer / SR. Project Manager at SCS

In certain respects, the setup of this solution is more straightforward than other solutions, but in other respects, it's more complex because it needs more fine-tuning than Splunk or AlienVault.

View full review »
Giuseppe Ragazzini - PeerSpot reviewer
Project Delivery Manager at Spindox

It's not very complicated to install Elastic, but I didn't deploy it.

View full review »
Haitham AL-Sarmi - PeerSpot reviewer
Information Security Analyst at a financial services firm with 1,001-5,000 employees

The initial setup is pretty simple and straightforward. It's not overly complex. 

That said, it does require trained specialists, and there just aren't that many in our area. 

Overall, I would rate the setup process at a two out of five. 

The configuration must be done correctly, and that depends on who is configuring it. If the person configuring it, for example, only has an administrator background, he will configure the administrator stuff. If he has a security background, he will configure for security.

View full review »
SC
AVP, Site Reliability Engineer at a financial services firm with 10,001+ employees

The initial setup is easy, but as you begin using the more advanced features like security and authentication with an AM and LM, then it becomes a bit tricky.

View full review »
Vikas Dusa - PeerSpot reviewer
Cyber Security Trainer and Programmer at Freelancer

The tool's deployment is straightforward. 

View full review »
SK
Executive Cybersecurity at a computer software company with 11-50 employees

The initial setup is easy. 

View full review »
CN
Senior DevOps Engineer at a financial services firm with 10,001+ employees

With ELK, installation is not really straightforward. There are about three applications to consider. It's quite intense in terms of set up, but once you've done the setup, then it's nice and smooth. The implementation took about 3 weeks, but that is because I was doing it in between other projects. We used an implementation plan. It was deployed to the development environment, then the Point of Concept (POC) environments. It was then deployed into the production environment.

View full review »
AM
Intern Cybersecurity at a computer software company with 10,001+ employees

The setup process is highly complex because you need to configure every agent separately and then connect them to each other and the system architecture. It would be difficult for the average user. I had a cybersecurity consultant to help me set up some of the agents. It took about three days to deploy. Maintaining Elastic Search is also challenging.

View full review »
HamadaElewa - PeerSpot reviewer
Technical Sales Manager at Spire Solutions

The initial setup is straightforward. Anyone who knows the basic features can implement this product. Elastic Security has a large community that can support users.

View full review »
SoheylNorozi - PeerSpot reviewer
IT Consultant at a tech services company with 51-200 employees

The product's initial setup is straightforward but experts need to do it. 

View full review »
PC
Consultant at RIPEN

The initial setup for Elastic Security is quite straightforward. For the cloud version of the solution, it's easy because it requires no installation. If you're setting up the on-premises version of Elastic Security, then it would take around three to four days to complete.

View full review »
LM
Devops/SRE tech lead at a transportation company with 201-500 employees

The first time, it was very hard to deploy on Kubernetes. However, as we reached version seven, they are now an operator. Now it's very easy to deploy. We no longer have any issues.

View full review »
SA
Consultant at a computer software company with 5,001-10,000 employees

The initial setup is easy. The length of time for deployment on a machine depends on the configuration that is required. If it uses all 145 use cases then it will take a long time. If on the other hand there are only a small set of use cases, it will be very quick. I would say that it takes no more than 30 minutes to install one.

View full review »
Saad Leghari - PeerSpot reviewer
Lead Enterprise Architect at a tech consulting company with 51-200 employees

The product's initial setup is very easy. I think the most important point is how you design your infrastructure because the solution is quite open. So you have to design it based on the nature of the data. You also need to get a life cycle so that there is no load on the storage. The solution's flexibility depends on how you design it. 

View full review »
Tiodor Jovovic - PeerSpot reviewer
Chief Business Officer at Sky Express

The initial setup wasn't overly complex or difficult. That said, it wasn't simple either. It's somewhat moderate in terms of implementation.

I'd rate the solution three out of five in terms of ease of setup. 

View full review »
Sudeera Mudugamuwa - PeerSpot reviewer
Co-Founder at a tech vendor with 51-200 employees

The setup is comparable to similar products. It isn't too easy or hard. We deployed it in-house. 

View full review »
SD
VP Platform Engineering at Hydrogen

The initial setup is not overly complex. It's pretty straightforward. A company shouldn't have any issues with the implementation process overall. Everything in AWS has gotten pretty straightforward.

The maintenance of the solution is minimal. It would only take one person to maintain it.

View full review »
it_user782697 - PeerSpot reviewer
Security Operation Center Analyst at Sadad

The initial setup of this solution was complex.

We have an enterprise structure and we cannot just install this solution, Logstash, and Kibana (the data visualization plugin for this solution), to have a good experience. For example, we had to set up the SQL database.

We now have nine Elasticsearch nodes in the company that all work together in a cluster. It is not simple, but rather, an enterprise structure.

View full review »
MU
Lead Security Engineer at a tech services company with 201-500 employees

The initial setup is straightforward. But since I've been using it for seven years, I could be comfortable with the solution, so I'm saying it's straightforward. However, my team, including new people, found that the documentation was not complex. They find it easy to understand and deploy the solution.

The time it takes to deploy the solution depends on the kind of resources you will utilize. For a basic deployment, I don't think it should take more than one day. Also, consider that if you face any error, you must troubleshoot, even basic errors. It should not take more than one day. I'm only talking about basic deployment, not integration, fine-tuning, or configuration.

The steps taken during the deployment process depend on various factors. If you're deploying the cluster base, you must deploy Elasticsearch and Logstash. If you're using it, you can even deploy Wazuh, and on top of it, Kibana which would be used for all your graphical user interfaces. If it is an all-in-one deployment, the steps taken are simple. Just a bunch of commands from the documentation you can see. But if it is a cluster deployment, it's different. If it's on a cloud, you have to deploy different instances for each server, like Logstash, Elasticsearch, and Kibana. But if you're using the solution on the cloud, you will use different instances. Or, if you're going to deploy a cluster on-prem, you might want different servers or VMs.

View full review »
RJ
Big Data Team Leader at a tech services company with 51-200 employees

The initial setup depends on what you were expecting, but since we have experience with it and know what it's good for, it's an eight out of ten. The initial deployment typically takes about a day. Then there's an initial stage of the project to integrate some of the client's specific requirements, which can take additional time depending on the complexity of their environment.

When it comes to maintenance, it depends on the project, and sometimes one person can support all roles.

Usually, it's enough to have one engineer with deep technical knowledge of the operating system and the deployment and configuration of the system. The other role is an analytical role with project management and coordination skills to communicate with customers and drive delivery.

View full review »
KF
Engineer at a tech services company with 501-1,000 employees

The Endgame itself is extremely straightforward to set up and you just filled out the ISO and you follow a couple of wizards you're done. It's very easy. I would say the ELK Stack is a little more complicated, however, that's due to the way we implement PKI in our environment. The product in itself is fairly straightforward to implement. It's our choice of certificate implementation that's making it a little more complicated.

We targeted it to be able to be maintained by one person. In a lot of cases, our scenario is that we only have one person available to maintain the product. It's very easy to maintain. There's not a ton going on. In a scene, you always have to have somebody watching the log of traffic if you want it to be effective. However, outside of that, there's no extreme maintenance associated with the product.

View full review »
WI
Principal Cyber Security Manager at Ask4key

The setup can sometimes be quite complex for the backend team. It all depends on the client's environment, so we have to be flexible.

View full review »
ER
IT at a tech vendor with 10,001+ employees

The initial setup as I recall was pretty easy. However, I moved to an infrastructure that had a connection to a second ELK instance that I am not managing.

The settings on that instance are more complex than my initial setup. 

I am not a specialist in big data infrastructure. I am a process engineer. You need some dedicated and well-trained people as soon as you have a large infrastructure and you are sending a lot of events to the elastic instance so that it is performed correctly. That's always the challenge you have with on-premise infrastructure.

View full review »
TV
Manager- Information Security at a tech services company with 51-200 employees

The initial setup is straightforward. Deployment can take up to four days.

View full review »
GA
Presales Solutions Architect (Cyber Security) at a tech services company with 11-50 employees

The setup process is very complex if you are new to it. But if you already understand how Elastic Security works and how the architect works, I think it is quite simple.

View full review »
TW
I.T. Manager at a healthcare company with 51-200 employees

The initial setup was pretty straightforward.

View full review »
FB
Technical Team Lead at Quester

I did not do the initial setup myself.

View full review »
MA
Junior System Engineer at Efficom-lille

I'm a system engineer. The architects who set up these solutions did it before I worked here.

I learned how to use it by doing searches and finding information about it.  I learned to use it very quickly. The documentation is very simple to use, as long as you have some technical background in computers.

View full review »
MR
Cloud Engineer at GARR

The initial setup is pretty straightforward.

Our deployment took quite some time but it was not because of Logstash issues. It was a more complex situation because we didn't have access to all of the nodes that we wanted to forward. So, it took between 10 and 15 months to deploy, although it was for administrative reasons as opposed to technical ones.

View full review »
Mustafa Husny - PeerSpot reviewer
Senior System Engineer at Techline-eg

The initial setup of Elastic Security is straightforward. However, the documentation could improve. The deployment can be done in approximately 15 minutes.

View full review »
YS
DevOps Engineer at a computer software company with 1,001-5,000 employees

Complex. We needed to analyze multiple factors, like benchmarking, performance of Logstash.

View full review »
PP
Programmer at a tech services company

Slightly complex, especially when you are configuring machines which are on a separate IP rather than on a single machine. In my case Elasticsearch, Kibana, and Logstash were on different machines. Along with that, we added a proxy server (nginx) ahead of the Kibana server. We used the proxy server for user authentication so that only known users should be able to access the Kibana dashboard. ELK didn’t have a free version for user authentication and that made us go for the alternative. We have, in total, four machines.

View full review »
RG
Desarrollador Java Senior Full Stack at Optimissa Capital Markets Consulting

The initial setup wasn't difficult, but that varies depending on the number of servers you have.

View full review »
SM
Associate Director - Solutions at a comms service provider with 1,001-5,000 employees

I do not think that we had any issues with the deployment. Overall, I would say that the process is of medium complexity.

View full review »
it_user771693 - PeerSpot reviewer
Works at a comms service provider with 51-200 employees

On week is enough for the deployment.

View full review »
TB
Professional Services Manager at PT Korelasi Persada Indonesia

Elastic's initial setup is quite straightforward. 

View full review »
JC
Senior Tech Engineer at a tech services company with 1,001-5,000 employees

The initial setup is easy. It's not complex or difficult. It's pretty straightforward.

It's very easy to set everything up and configure it on-premises.

The deployment only took an hour or two. We only deployed to one environment. It was pretty fast.

View full review »
AR
Founder & Chief Executive Officer at a consultancy with 11-50 employees

The initial setup was very straightforward for us because we are a software development company. We understand how to compile the source code. We can compile the source code, and we can deploy it. It was pretty straightforward for us.

View full review »
it_user1247235 - PeerSpot reviewer
Cyber Security Consultant at a tech services company with 51-200 employees

The initial setup is complex and it is not easy to deploy.

It is also possible to have a cloud-based deployment.

View full review »
JJ
CEO at a tech services company with 51-200 employees

The initial setup is quite complex. Starting from the point where we were collecting the data, the deployment probably took about a month. However, simply installing the applications only takes a few days.

View full review »
KL
DevOps Manager at a tech services company with 11-50 employees

When doing the installation, the ELK is working well but sometimes when we search for specific words there is no longer any inception throughout. This issue has been difficult to debug or fix.

The index is very important when using this solution. We encountered a couple of issues when we set up the wrong index, it causes everything to go down. That means if we set up something incorrectly with the index, the solution will be down and we do not know why.

View full review »
SN
Associate Delivery Lead at a tech services company with 1,001-5,000 employees

We have done both setups, on-premise as well as on AWS.

The installation is quite okay. We have done three or four installations and it's fine. We have deployed on Windows as well as on Linux platforms.

I don't get involved in the installation, but I have a small team who does it and based on their experience, we have installed in one day.

The installation of full-frame solutions is quite smooth.

View full review »
JM
Director of Engineering at a tech services company with 201-500 employees

Because I come from a technical background, I find the setup to be easy. It would also be easy for admins, like a manager or somebody who is on DevOps. But somebody without a background could find it complex. Overall, if you asked me to describe it is easy.

If we have to customizations, we can close it in a week's time, max, okay. So as he said to whatever that is, they're magnificent customizations that they want to do and internally what they want. But if we want to add certain rules or connection with the rules. 

View full review »
it_user1071018 - PeerSpot reviewer
Former CISO | Cyber Security Enthusiast at a tech services company with 51-200 employees

The initial setup was a little complex.

View full review »
Buyer's Guide
Elastic Security
May 2024
Learn what your peers think about Elastic Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
770,292 professionals have used our research since 2012.