description Elastic Security Overview
Elastic Security is an open-source threat detection and response platform that analyzes machine data from various sources – including endpoints, servers, and network logs – to identify and investigate suspicious activity using the Elasticsearch engine.
help Elastic Security FAQ
Is Elastic Security really free and open source?
Elastic Security is available at no cost as part of the free Elastic distribution, including its prebuilt detection rules and the Kibana security UI. The underlying Elasticsearch code became more openly licensed again after Elastic added an AGPL option in 2024, alongside its earlier Elastic License and SSPL choices.
How does Elastic Security compare to Splunk for SIEM?
Elastic Security is built directly on the Elasticsearch engine, so teams already running the Elastic Stack can add detection and response without a separate SIEM product or per-GB ingest licensing on top. Splunk is more entrenched in large enterprises, but Elastic's bundled free tier is a major draw for smaller security teams.
What did Elastic's Endgame acquisition add to Elastic Security?
Elastic acquired endpoint security firm Endgame in 2019, reportedly for around $234 million, which became the basis of the Elastic Defend endpoint agent. That deal is what allowed Elastic to combine SIEM-style detection with endpoint response in one platform.
Does Elastic Security map detections to MITRE ATT&CK?
Yes, its prebuilt detection rules library is tagged and mapped to MITRE ATT&CK techniques, so alerts arrive with the tactic and technique context analysts expect. Queries can also be written in KQL and EQL directly in Kibana for custom hunting.
explore Explore More
Similar to Elastic Security
ui.x_see_all arrow_forwardReviews & Comments
Write a Review
Be the first to review
Share your thoughts with the community and help others make better decisions.