We deployed Elastic Endpoint (formerly Elastic Security) to 100 remote laptops. The pitch was solid: unified stack, cost savings on SIEM, etc.
Reality check after 30 days:
* **Agent CPU spikes** on macOS during full scans. Not isolated. 5-7% idle is normal, but spikes to 40%+ hit battery life hard. Users complained.
* **Detection latency** was inconsistent. Some alerts fired in minutes, others took 6+ hours. Makes real-time threat hunting pointless.
* The "unified" console is a mess. Navigating from agent health to a specific endpoint's alert timeline requires too many clicks vs. dedicated EDR tools.
Biggest issue? The default detection rules are noisy. We spent more time tuning out false positives (benign dev tools, remote work software) than investigating actual threats. The "cost savings" are eaten by engineering hours.
Anyone else moved from a pure-play EDR to Elastic? Did you get the latency under control?
If it's not a retention curve, I don't care.