Skip to content
Notifications
Clear all

Anyone actually using Elastic Security in production for threat hunting?

1 Posts
1 Users
0 Reactions
21 Views
(@annak8)
Estimable Member
Joined: 2 months ago
Posts: 202
Topic starter   [#19762]

Alright, I have to ask this because I've been knee-deep in feature matrices and Gartner reports for weeks, and there's a gap between what's on paper and what's happening on the ground. I see all the capabilities listed for Elastic Security—the open source foundation, the integrations, the promise of blending SIEM, endpoint, and cloud data for proactive hunting. But when I talk to peers at other shops, the conversation always pivots to Splunk, Sentinel, or CrowdStrike for the "serious" threat hunting work.

So, I'm genuinely curious: is anyone here **operationally** using Elastic Security (not just ingesting logs, but actively hunting) in a production environment? I'm talking about a dedicated person or team building custom detection rules, using the Timeline feature in Kibana to pivot across indices, and regularly running EQL (Event Query Language) queries to find weirdness that the canned alerts missed.

My interest comes from our own A/B testing background—I love the idea of having all our telemetry (web app logs, CRM events, network data) in one place to correlate with security events. The potential for a unified data layer is huge from an analytics perspective. But I need some real-world validation before I advocate for a deeper investment.

Specifically, I'd love to hear about:

* **Your data scale & team size:** Are you hunting over terabytes per day? Is this a one-person show or a dedicated SOC?
* **The hunting workflow:** Do you live in Kibana's Security app? How do you structure your timelines? Are pre-built rules (like the Elastic pre-packaged ones) actually useful as a starting point, or do you end up writing everything custom?
* **The pain points:** I'm sure there are some. Is it the learning curve for EQL? Performance when querying across months of data? The operational overhead of managing the Elastic stack itself? The endpoint agent's footprint?
* **Comparison point:** If you've used other platforms, what does Elastic do better or worse for *proactive* hunting? Is it the data exploration freedom vs. a more guided SOAR-like workflow elsewhere?

I've got a trial running, and the data ingestion part is fine, but I want to understand the human element—the daily grind of a threat hunter using this toolset. The documentation shows *how* to do things, but not how well it works under pressure.

Any insights, war stories, or even "we tried it and moved on because of X" stories would be incredibly valuable for my evaluation. Happy evaluating



   
Quote