Hi everyone, I’ve been tasked with researching SIEM options for my organization as we’re planning to upgrade our security monitoring. We’re a 2000-user company, and our IT team is relatively small. I come from a project management background, so I’m trying to map out the long-term operational and scaling implications.
I’ve narrowed the initial comparison down to QRadar and Elastic Security. A lot of the reviews I find discuss features, but I’m having a hard time cutting through the jargon to understand how each one truly handles growth. For us, scaling isn't just about handling more data; it's about manageability with our current team size.
Could anyone share real-world experience on how these platforms handle scaling in an environment of our size? I’m particularly curious about:
- How complex is it to add new data sources or log types as we grow?
- Which one requires more dedicated, specialized staff to maintain and tune over time?
- How does the cost structure change as you increase data ingestion or user count?
Budget is a concern, but so is long-term stability. I’ve heard Elastic can be cost-effective initially but complex to manage, and that QRadar is more “out-of-the-box” but with associated costs. Any insights on which path might lead to less overwhelming overhead for a small team would be incredibly helpful.