r/AskNetsec
Keep Elastic + swap EDR (CrowdStrike vs SentinelOne), or move SIEM to the EDR vendor?
- upvotes
- 10
- comments
- 14
Post
Highlighted: the lines this signal was extracted from
Large EU manufacturing company, multi-site, small security team. Endpoint platform renews in the next budget cycle. Shortlist: CrowdStrike vs SentinelOne (vs renewing what we have). SIEM today is Elastic; endpoint alerts already land there. Two architecture options:A) Keep Elastic as system of record. Change only the EDR (CS or S1). Day-1 = alerts into Elastic, deep dive in the EDR console. Full raw telemetry (FDR / Cloud Funnel) only later if we really need it.B) Make the chosen vendor’s SIEM (Falcon NG-SIEM or SentinelOne AI SIEM) the SoR and retire Elastic over ~1–1.5 years (parsers, rules, skills, parallel run). Internal tension: Elastic already feels heavy to operate; vendor SIEM looks “simpler” out of the box. Counter: we’d still re-onboard firewall/IdP/cloud into CS/S1 and retrain whoever does L1/L2. Also weighing MSSP (L2 contain on EDR + firewall, including overseas sites) vs vendor MDR as a bridge. Practitioner takes appreciated: Is dual-console (Elastic triage + Falcon/S1 deep dive) fine at scale, or a daily tax? When did consolidating off Elastic onto CS or S1 SIEM actually win vs regret? Do lean teams usually skip FDR / Cloud Funnel into Elastic on day 1? Any strong reason to pick CS vs S1 *if* we stay on path A (Elastic stays)? MSSP on Elastic+EDR vs vendor MDR+hub - what worked? No vendor pitches please. Thank you
Also quoted as evidence
[comment u/Naive_Caregiver_5760] Elastic being a pain to run with a small team is basically the default experience, not some edge case.