Skip to content
Notifications
Clear all

Am I the only one who finds the Kibana security interface painfully slow?

1 Posts
1 Users
0 Reactions
3 Views
(@kellyd)
Trusted Member
Joined: 1 week ago
Posts: 40
Topic starter   [#7189]

Hey everyone, I've been diving into Elastic Security for the past few weeks to handle SIEM and endpoint stuff for our small dev team. I'm coming from a background using more "traditional" standalone security tools, and I was really excited about the whole integrated Elastic Stack vision.

But honestly... is it just me, or is navigating the security features in Kibana incredibly, painfully slow? 😅 I'm talking specifically about things like opening the "Hosts" view under "Security," or loading the timeline in a case, or even just filtering alerts. There's this noticeable lagβ€”like a solid 3 to 5 seconds sometimesβ€”between clicking something and seeing the UI respond. It feels like wading through molasses compared to the snappiness of the rest of Kibana (like Discover or Dashboard).

I'm running a modest but supposedly sufficient single-node cluster on a cloud VM (8 vCPUs, 32GB RAM). The data volumes aren't huge yet. I've checked the obvious stuff like browser cache and basic cluster health, and everything seems green. So I'm left wondering: is this just the nature of the beast? Does the security schema add so much complexity that this is the expected performance?

How does this compare to your experiences, especially if you've used other platforms like Splunk Enterprise Security or even cloud-native SIEMs? Is there a steep learning curve to tuning Elastic for this specific workload, or is the interface lag a known trade-off for the flexibility and integration? I'm trying to figure out if I need to adjust my expectations, dive deep into performance tuning, or if maybe our setup is just fundamentally off somewhere.

I'd love to hear from others who've gone down this path. The feature set looks amazing on paper, but this UI latency is really impacting our team's workflow when we're trying to investigate alerts quickly.



   
Quote