I've been running Elastic Security for about a year now, and honestly, I'm hitting a wall. The product is powerful, but the complexity is no joke. My team is stretched thin just keeping the lights on, let alone trying to optimize our detection rules or properly tune the SIEM.
Now we're looking at a significant scale-up, and I'm facing a classic dilemma. Elastic offers their own certified expert servicesβimplementation, architecture reviews, the whole package. But the quote made my finance person wince. On the other hand, I've been pitched by a few independent consultants who claim deep Elastic experience at a lower hourly rate.
My gut says the official route might be "safer," but is it really? I'm specifically worried about knowledge transfer. If I pay for their certified experts, do they actually leave us with a maintainable setup, or is it a black box that locks us into needing them again next year?
I'd love to hear from anyone who's gone down either path:
- Did you use Elastic's professional services? Was the outcome worth the premium, or did it feel like you were just paying for the brand name?
- If you hired an independent consultant, how did you vet their actual expertise? Any horror stories or success tales?
- For those who tried to go it alone with just support subscriptions and documentation... how's that going for you? 😅
I'm trying to avoid a costly mistake here. The migration from our last vendor was painful enough, and I don't want to waste budget on consulting that doesn't give us real, long-term ownership.
The grass is greener? We'll see.