Skip to main content

Technical Architecture & Overview

Elastic Security turns the Elasticsearch platform into a SIEM, with data ingestion through Elastic Agent and Fleet, prebuilt detection rules mapped to ATT&CK, case management, and endpoint response through the same agent. The base is free and open under Elastic licensing, with paid cloud and enterprise tiers on top. Query DSL and the rule DSL make detection-as-code practical.

Targeted Technical Use Cases

Teams that want a SIEM they can run themselves, with full control over storage, scaling, and detection rules.

Evaluation & Trade-offs

Core Strengths

  • +Free tier covers a working SIEM.
  • +Huge integration ecosystem from the Elastic stack.
  • +Detection rules are open and customizable.

Trade-Offs & Limitations

  • -Storage engineering is your responsibility on self-managed clusters.
  • -Licensing split between free and paid features needs review.

Defensive Security Application

Log aggregation, correlation, and endpoint response under one searchable data platform.

Frequently Asked Questions

What is Elastic Security?

Elastic Security turns the Elasticsearch platform into a SIEM, with data ingestion through Elastic Agent and Fleet, prebuilt detection rules mapped to ATT&CK, case management, and endpoint response through the same agent. The base is free and open under Elastic licensing, with paid cloud and enterprise tiers on top. Query DSL and the rule DSL make detection-as-code practical.

What is Elastic Security used for?

Teams that want a SIEM they can run themselves, with full control over storage, scaling, and detection rules.

What are the strengths of Elastic Security?
  • +Free tier covers a working SIEM.
  • +Huge integration ecosystem from the Elastic stack.
  • +Detection rules are open and customizable.
What are the limitations of Elastic Security?
  • +Storage engineering is your responsibility on self-managed clusters.
  • +Licensing split between free and paid features needs review.
How is Elastic Security used defensively?

Log aggregation, correlation, and endpoint response under one searchable data platform.