2019-08-08T07:02:00Z

What needs improvement with ELK Logstash?


Please share with the community what you think needs improvement with ELK Logstash.

What are its weaknesses? What would you like to see changed in a future version?

Guest
77 Answers

author avatar
Top 10Real User

Our system architect has noticed a slowdown of the solution, but I don't see a slowdown. One thing they could add is a quick step to enable users who don't have a solid background to build a dashboard and quickly search, without difficulty.

2020-03-22T06:49:00Z
author avatar
Top 5Real User

In terms of what could be improved with Elastic, in some use cases, especially on the advanced level, they are not ready-made, so you'll have to write some scripts. This is the case, especially with a trade. If you are comparing it with a SIEM tool, you don't have ready-made use cases. I would say that to have a better place in the market they should have more built-in use cases so that rather than people creating them, the prime uses had inbuilt use cases. It could even include more templates or automation.

2020-03-04T08:49:00Z
author avatar
Top 5Real User

Configuring the server is difficult and can be improved. I would like to have a high availability set up that is easy to configure. Anything that supports high availability or ease of deployment in a highly available environment would help to improve this solution.

2020-03-03T08:47:43Z
author avatar
Top 10Real User

This solution cannot do predictive maintenance, so we have to build our own modules for doing it. It doesn't do advanced analytics. They should have some advance analytics in this solution. With Kibana, we wanted it to be easier to use. The data visualization is there but it should be easier to use. Also, they should start proving APIs for doing ML and AI.

2020-03-03T08:47:40Z
author avatar
Top 10Real User

We don't like the SIEM in version 7. It was introduced about three months ago, and it's not what we need. The machine learning is not included in the free version. It is only included in the Platinum or Gold versions. It would be helpful if the machine learning features were available even on the free version of the solution. RSA and IBM are other solutions that also offer machine learning, which is interesting for us, but they cost money.

2020-02-16T08:27:45Z
author avatar
Real User

There are connectors to gather logs for Windows PCs and Linux PCs, but if we have to get the logs from Syslog then we have to do it manually, and this should be automated. It would be good if I could get technical support for specific devices. I think that Windows should have some specific connectors. When we implemented a new product, we had to create it manually.

2019-09-10T10:06:00Z
author avatar
Top 5LeaderboardReal User

The documentation for this solution is very important, and more needs to be developed. It was not as good as we expected, and because of that, we prefer to work on commercial solutions such as Splunk or ArcSight. If the documentation were improved and made more clear for beginners, or even professionals, then we would be more attracted to this solution. As you gather more and more data, and the data continues to grow, I think it is difficult to handle, administer, and perform declustering. I would like to see support for machine learning, where it can make predictions based on the data that it has learned from our environment.

2019-08-08T07:02:00Z
Learn what your peers think about ELK Logstash. Get advice and tips from experienced pros sharing their opinions. Updated: April 2020.
441,850 professionals have used our research since 2012.