Just passed the six-month mark after moving our ~500 endpoints from CrowdStrike to Elastic Endpoint. Wanted to share some real hands-on experience, especially for teams deep in the Elastic Stack already.
The good: The integration with the rest of the Elastic ecosystem is fantastic. Having security alerts and endpoint data in the same place as our application logs is a game-changer for our small SecOps team. The cost was a major factor, and for our needs, the value is definitely there. Deployment via our existing Elastic Agent framework was smooth.
The not-so-good: The initial tuning was heavier than expected. We had a lot more noise out of the box compared to CrowdStrike. It took a few weeks of adjusting detection rules and exclusions for our dev environments. The console feels a bit less polished, and some automated response actions aren't as one-click simple. Missed the community around Falcon a bit.