Just finished reading the Forrester Wave™ for Security Analytics Platform Providers, Q4 2024. They placed Elastic Security as a Strong Performer, which feels about right given the competitive landscape. Their cited strengths—like the open platform, search foundation, and cost-effectiveness for data ingestion—are spot-on from my deployment experience.
However, I'm chewing on a few of their noted "challenges." They mention the need for more out-of-the-box content and guided workflows compared to some competitors. In my integrations, I've found:
* The power is there, but it often requires more customization and tuning to get the full value, which can be a pro or a con depending on the client's resources.
* The convergence of observability and security data is a huge strength, but the operational workflow for a pure security team can feel less "packaged" than a dedicated SIEM.
My take: Elastic Security is incredibly powerful for organizations already on the Elastic Stack or those with strong in-house skills who want control and a unified data lake. For a team wanting a more pre-packaged, turn-key SOC experience, the critique holds weight.
Do you agree? Especially interested from those who have evaluated or switched from other platforms like Splunk or Microsoft Sentinel. Where does Forrester get it right, and where might they be missing the nuance?
-mike
Integrate or die
Yeah, that point about needing strong in-house skills really resonates. I've seen marketing ops teams run into the same "power vs. packaging" dilemma with some of our tools.
The trade-off you're describing - a unified, powerful platform that demands more hands-on work - feels very familiar. In my world, that's the difference between a point-and-click email platform and something like a flexible CDP. One gets you going faster, the other gives you ultimate control... if you can build it.
That convergence of data (observability/security for you, maybe customer/engagement data for me) is always a double-edged sword. The value is massive, but you're right, the pre-built workflows for a specific use case just aren't always there. Makes me wonder if Forrester underplayed how much that "customization" factor is a strategic choice, not just a weakness.
Your point about it being a pro or con depending on the client's resources is dead on. I've seen it go both ways.
For platform teams that are already managing the Elastic Stack for logging, the move to Elastic Security feels like a natural, powerful extension. You get that single pane for logs, metrics, and security events, which is fantastic for hunting. But for a dedicated security team that just wants to open a console and start triaging alerts, that initial setup and content creation is a real hurdle. They don't always have the cycles to build all those correlation rules and dashboards from a strong foundation.
I think Forrester's critique on packaged workflows is fair for the pure-play SOC use case. But maybe they underplayed how big a deal that converged data lake is becoming for orgs trying to break down silos between platform engineering and security. The power is in the unification, even if it comes with more assembly required.
Automate all the things.