ELK Logstash Reviews

ELK Logstash is the #6 ranked solution of our top Log Management tools. It's rated 4.1 out of 5 stars, and is most commonly compared to Graylog - ELK Logstash vs Graylog

Filter by:
Industry
Loading...
Filter Unavailable
Company Size
Loading...
Filter Unavailable
Job Level
Loading...
Filter Unavailable
Rating
Loading...
Filter Unavailable
Considered
Loading...
Filter Unavailable
Order by:
Loading...
  • Date
  • Highest Rating
  • Lowest Rating
  • Review Length
Search:
Showingreviews based on the current filters. Reset all filters
Real User
Associate Delivery Lead at a tech services company with 1,001-5,000 employees
Mar 05 2020

What is most valuable?

The feature that I have found most valuable is the infrastructure monitoring part because it is quite easy. If you want to get up and running, we could create use cases in four to five days. So the initial infrastructure for simple analytics is quite easy. ELK Logstash is easy and fast, at least for… more »

What needs improvement?

In terms of what could be improved with Elastic, in some use cases, especially on the advanced level, they are not ready-made, so you'll have to write some scripts. This is the case, especially with a trade. If you are comparing it with a SIEM tool, you don't have ready-made use cases. I would say… more »

What other advice do I have?

Based on my experience, it's quite easy and manageable with small scale implementations, and the time to market is quite fast. I can have good monitoring with a couple of use cases set up in less than four weeks. In terms of other advice, it depends what I am looking for. Am I looking at this as a… more »

Which other solutions did I evaluate?

Until now, we have not evaluated the Elastic cloud version, which is the fast kind of solution. But we have deployed the on-premise as well as the AWS options.
Real User
IT at a tech vendor with 10,001+ employees
Aug 03 2020

What is most valuable?

All of the features on the solution are useful due to the fact that I have the full Stack, therefore I can collect and then visualize. We have the dashboard tutor as well. The solution has a good community surrounding it for lots of helpful… more »

What needs improvement?

The solution is lacking some features of AI and machine learning. There may be a feature out there we are not using or maybe it's on a different solution, however, having more AI would be so helpful for us. The solution needs to be more… more »

What's my experience with pricing, setup cost, and licensing?

I'm not sure how much the company pays to use ELK. It's not part of the job that I handle.

Which solution did I use previously and why did I switch?

We previously used a product from Quest Software called Change Auditor. We actually didn't switch off this solution. We use both Quest and ELK in our organization. The main difference is that one you have to pay for, while the other one is… more »

What other advice do I have?

We're ELK customers. Mostly I'm a specialist on the infrastructure of the solution. The solution is perfect as long as you are using it for forensics. In terms of threat detection, it could be better. There could be another product that is… more »
Learn what your peers think about ELK Logstash. Get advice and tips from experienced pros sharing their opinions. Updated: April 2020.
438,441 professionals have used our research since 2012.
Real User
Information Technology Engineer at a university with 501-1,000 employees
Feb 17 2020

What is most valuable?

The feature that helps us to create a report for the login testing of Logstash is the most valuable aspect of the solution. The query is very fast and the reports are very clean. We got a log for about 1,500 services and the report was… more »

What needs improvement?

We don't like the SIEM in version 7. It was introduced about three months ago, and it's not what we need. The machine learning is not included in the free version. It is only included in the Platinum or Gold versions. It would be helpful if… more »

What's my experience with pricing, setup cost, and licensing?

You do have to pay for support. It's an additional fee. However, it's not very expensive.

Which solution did I use previously and why did I switch?

I didn't previously use a different solution. So far, I've only tried a free trial for this solution that will last three months.

What other advice do I have?

In the future, I only plan to use the on-premises and free community edition of the solution. I'd recommend it this is a solution to other users. I recommend the free version. The one problem is that this solution has limited features. The… more »
Fazil BasheerSyed
Real User
Co Founder at Basheer Sharma Enterprises LLP
Jul 09 2020

What is most valuable?

The most valuable feature for me is Discover. I have not used all of the features, so I can't say that this will be best for everyone.

What needs improvement?

I would like the process of retrieving archived data and viewing it in Kibana to be simplified. We ran into trouble once or twice regarding problems with timestamps that came about because of issues with memory. Consequently, the correct… more »

What's my experience with pricing, setup cost, and licensing?

This is an open-source product, so there are no costs.

Which solution did I use previously and why did I switch?

We have used Graylog in the past, but it was self-hosted and the experience wasn't great.

What other advice do I have?

When my colleague set up this application, it was configured such that every seven days, the data is archived into long-term storage. When I needed something from the archived logs, it was easy to retrieve and I could look through them… more »
AmirJalilzadeh
Real User
Security Operation Center Analyst at Sadad
Aug 19 2019

What is most valuable?

This is one of the best open-source log management and log analyzer tools in the world.

How has it helped my organization?

This solution assists in tuning our applications.

What needs improvement?

The documentation for this solution is very important, and more needs to be developed. It was not as good as we expected, and because of that, we prefer to work on… more »

What's my experience with pricing, setup cost, and licensing?

We use the open-source version, so there is no charge for this solution.

Which solution did I use previously and why did I switch?

We used Splunk in parallel with this solution. In my role as a Security Operations Center Analyst, I think that Splunk is more useful for me. This is because I do not work… more »

What other advice do I have?

Our company uses Logstash for gathering the data, and Kibana for searching. The two are used together. This is a solution that I recommend. It is the best open-source… more »

Which other solutions did I evaluate?

The solution does not work as well as Splunk.
Maxime AGARIM
Real User
Junior System Engineer at Efficom-lille
Mar 25 2020

What is most valuable?

I use the stack every morning to check the errors and it's just so clear. I don't see any disadvantage to using Logstash.

What needs improvement?

Our system architect has noticed a slowdown of the solution, but I don't see a slowdown. One thing they could add is a quick step to enable users who don't have a solid background to build a dashboard and quickly search, without difficulty.

What's my experience with pricing, setup cost, and licensing?

Elastic Stack is an open-source tool. You don't have to pay anything for the components.

What other advice do I have?

Think carefully about how you will build the solution so that it is a high-availability solution. That is the trick when using Elastic Stack. Examine what your needs are. I would rate Logstash at eight out of 10. I think the solution is really complete, with the components it has. It is a good… more »
Shadow Fx
Real User
User at a comms service provider with 51-200 employees
Sep 26 2019

What is most valuable?

The visualization is very good.

How has it helped my organization?

This solution helps us because we can find all of the logs in one place. We can easily find a specific log in a specific time period.

What needs improvement?

There are connectors to gather logs for Windows PCs and Linux PCs, but if we have to get the logs from Syslog then we have to do it manually, and this should be automated… more »

What's my experience with pricing, setup cost, and licensing?

We are using the free, open-source version of this solution.

Which solution did I use previously and why did I switch?

We have used other SIEM solutions in our company.

What other advice do I have?

We are interested in learning more about plugins for specific firewalls or other products. The only problem with this solution is the development part, where we have to do… more »

Which other solutions did I evaluate?

We did not evaluate other options before choosing this solution.
MarioReale
Real User
Cloud Engineer at GARR
Mar 04 2020

What is most valuable?

The most valuable feature is the ability to collect authentication information from service providers.

What needs improvement?

Configuring the server is difficult and can be improved. I would like to have a high availability set up that is easy to configure. Anything that supports high availability or ease of deployment in a highly available environment would help to improve this solution.

What other advice do I have?

My advice for anybody who is implementing this system is to set it up so that you can manage it remotely. Overall, this product does what it is supposed to do, although there is always room for improvement. I would rate this solution a nine out of ten.
See 2 More ELK Logstash Reviews

What is ELK Logstash?

Logstash is an open source, server-side data processing pipeline that ingests data from a multitude of sources simultaneously, transforms it, and then sends it to your favorite “stash.”

Also known as
Elastic Stack, ELK Stack
ELK Logstash customers

Sprint, Grab, Autopilot, Just Eat, Verizon Wireless, Green Man Gaming, Compare Group, Tango, Perceivant, Quizlet

Read Archived Reviews
BUYER'S GUIDE
Download our free ELK Logstash Report and get advice and tips from experienced pros sharing their opinions.