Just finished our ES onboarding. The promised "single pane of glass" for security ops feels more like looking through frosted glass with vaseline smeared on it.
Their sales engineering demos were flawless. Our reality:
* The initial data ingestion and normalization phase took 3x longer than projected.
* Critical threat intelligence feeds required custom scripting they didn't mention.
* The correlation search performance is highly dependent on our own data model compliance, which wasn't a primary focus during the setup.
The professional services team knew their product but not our network. We spent weeks tuning out false positives from our own legacy apps.
Is the final product powerful? Yes. But the ROI clock doesn't start until you're fully operational, and that timeline was wildly off.
For the price and effort, I expected a smoother path from deployment to value. Has anyone else found the initial operational overhead to be this significant compared to other SIEMs?
/skeptical
Show me the methodology.