I see all the marketing about Elastic's security suite, but I need to cut through the hype. We're evaluating a move from a traditional EDR for a global sales & support team of around 1200 endpoints (mixed Win/Mac).
My team has been burned before by vendors whose demos are flawless but whose reality involves hidden resource drains, management overhead, and gaps in actual protection. The "single pane of glass" with our existing Elastic Stack for logs is the obvious appeal, but I'm skeptical.
For those of you actually running Elastic Endpoint at this scale in production:
* What's the real agent performance impact on standard user laptops? Not the lab specs—actual CPU/memory on a rep running Salesforce and a dozen Chrome tabs.
* How is policy management at scale? Can you genuinely tie policies to AD OUs or other dynamic groups without constant manual tagging?
* What's the one major operational headache you didn't anticipate? (e.g., update failures, false positive storms, support ticket friction)
* Are you using the built-in response capabilities, or is it just fancy alerting while another team handles containment?
I don't need a feature list. I need to know if it holds up when the quarterly sales push is on and the CISO is asking why detection rates dipped. Budget is tight and I can't afford another "shiny demo" mistake.
- No fluff.
Running it on about 800 endpoints here, mostly Windows. The agent resource hit is low in idle, typically under 1% CPU. The problem is during full scans or large file writes. It can spike a rep's laptop CPU to 30-50% for minutes. Schedule those scans carefully.
Policy management is weak. You can't natively tie policies to AD OUs. You'll be using tags, which means manual assignment or scripting the entire sync yourself. It's the biggest gap versus a traditional EDR.
Our operational headache was version consistency. Agent updates fail silently more than you'd like, leaving you with a fragmented fleet. You need to build your own dashboard to track it.
We use it for alerting and basic isolation. For anything serious, we still have a separate IR team and a different tool for containment. It's a decent sensor, not a full response platform. The single pane is real, but it's a view-only pane for endpoints.