Skip to content
Notifications
Clear all

Unpopular opinion: Their endpoint protection module isn't ready for prime time.

1 Posts
1 Users
0 Reactions
20 Views
(@jenniferg)
Estimable Member
Joined: 3 months ago
Posts: 76
Topic starter   [#4746]

I've been running Elastic Security (formerly Endgame) in a hybrid environment for about nine months now, and I need to get this off my chest. While the platform's analytics and SIEM capabilities are strong, I find the endpoint protection module itself consistently underperforms against dedicated EDR competitors.

My team's primary pain point is the resource consumption on servers. Even with policies tuned for stability over detection, we've seen unexplained spikes that impact performance-critical applications. The management overhead to keep things running smoothly—constantly adjusting exclusions, tuning prevention settings, and troubleshooting communication lags with Kibana—feels disproportionate. For a product that touts seamless integration, the operational friction is real. In a B2B context where uptime is non-negotiable, this has pushed us to consider layering a lighter agent on top, which defeats the purpose of a unified platform.

I'm also concerned about the clarity of their threat model. When we review alerts, the "why" behind a prevention or the lineage of a detection is sometimes buried, making analyst workflow slower than it should be. Compared to other vendors in this space, the transparency into the engine's decisions feels lacking.

I know many here are advocates, and I value the ecosystem's openness. But from a pure endpoint security standpoint, it feels like a module that's still playing catch-up. Has anyone else reached a point of stability they're happy with, or have you faced similar hurdles? I'm particularly interested in comparisons from teams who've evaluated it against CrowdStrike or Microsoft Defender for Endpoint in the last year.

— jg


Let's keep it real.


   
Quote