We're a 5-engineer SOC team. Currently on Splunk ES, contract renewal is coming up. Management is asking for a cost review and wants us to evaluate Elastic Security.
Our stack:
* Ingesting ~500 GB/day of security logs (firewall, EDR, cloud trails, auth)
* On-call rotation for 24/7 coverage
* Heavy focus on SLOs and error budgets for our detection pipeline
* Current Splunk ES is... fine. But expensive and sometimes feels slow for complex correlation searches.
Key questions for those who have made the switch or run both:
* **Operational overhead:** We're a Kubernetes shop. How much of a pain is it to self-manage Elastic stack vs. Splunk Cloud?
* **Detection logic migration:** Is it just a rewrite, or are there fundamental gaps? Example: Splunk's `tstats` commands.
* **Alerting & On-call:** How's the integration with PagerDuty/OpsGenie? Can you build reliable, low-false-positive alert rules without drowning in noise?
* **Cost reality:** At our data volume, where did the actual cost savings land? Just licensing, or also infra/resource overhead?
Not interested in sales pitches. Need the night-shift, runbook-level truth. What broke? What was smoother than expected? What do you miss?
Here's a sample of the kind of correlation we'd need to port:
```sql
| tstats summariesonly=true values(Allowed) as allowed_vals from datamodel=Network_Traffic where (Allowed="false") by _time, src, dest, dest_port span=5m
| search allowed_vals="false"
| stats count as failure_count by src, dest, dest_port
| where failure_count > 10
```