Skip to main content
ElasticCustomer feedback

A large EU manufacturing company with a small security team is considering replacing their Elastic SIEM because they find it is 'heavy to operate'.

What happened

Post: "Keep Elastic + swap EDR (CrowdStrike vs SentinelOne), or move SIEM to the EDR vendor?"

Source

RedditSep 22, 2026By u/Rough-Computer-803

r/AskNetsec

Keep Elastic + swap EDR (CrowdStrike vs SentinelOne), or move SIEM to the EDR vendor?

upvotes
10
comments
14

Post

Highlighted: the lines this signal was extracted from

Large EU manufacturing company, multi-site, small security team. Endpoint platform renews in the next budget cycle. Shortlist: CrowdStrike vs SentinelOne (vs renewing what we have). SIEM today is Elastic; endpoint alerts already land there. Two architecture options:A) Keep Elastic as system of record. Change only the EDR (CS or S1). Day-1 = alerts into Elastic, deep dive in the EDR console. Full raw telemetry (FDR / Cloud Funnel) only later if we really need it.B) Make the chosen vendor’s SIEM (Falcon NG-SIEM or SentinelOne AI SIEM) the SoR and retire Elastic over ~1–1.5 years (parsers, rules, skills, parallel run). Internal tension: Elastic already feels heavy to operate; vendor SIEM looks “simpler” out of the box. Counter: we’d still re-onboard firewall/IdP/cloud into CS/S1 and retrain whoever does L1/L2. Also weighing MSSP (L2 contain on EDR + firewall, including overseas sites) vs vendor MDR as a bridge. Practitioner takes appreciated: Is dual-console (Elastic triage + Falcon/S1 deep dive) fine at scale, or a daily tax? When did consolidating off Elastic onto CS or S1 SIEM actually win vs regret? Do lean teams usually skip FDR / Cloud Funnel into Elastic on day 1? Any strong reason to pick CS vs S1 *if* we stay on path A (Elastic stays)? MSSP on Elastic+EDR vs vendor MDR+hub - what worked? No vendor pitches please. Thank you

Also quoted as evidence

  • [comment u/Naive_Caregiver_5760] Elastic being a pain to run with a small team is basically the default experience, not some edge case.

reddit.com/r/AskNetsec/comments/1wniyv8/keep_elastic_swap_edr_crowdst...Read the full source

Comments on the post

5 of 14 comments
  • “We have committed fully to Crowdstrike alongside NextGen SIEM and MDR service. Overseeing the SOC remains a challenging task. My view let’s experts manage and the internal team focus on what they are good at.”

    u/simplecartoon10 points · Sep 22, 2026View

  • “I've implemented both Sentinel One and CrowdStrike SIEM. If you're used to something like Elastic or Splunk they're a big downgrade IMHO. The CrowdStrike SIEM is better out of those two though.”

    u/jdiscount4 points · Sep 23, 2026View

  • “Elastic being a pain to run with a small team is basically the default experience, not some edge case. If you're already feeling that weight now, doubling down on it for raw telemetry later sounds like a headache you'll keep putting off. Dual console isn't a dealbreaker if your L1/L2 are sharp enough to know when to pivot, but it gets old fast during a real incident when you're flipping tabs try”

    u/Naive_Caregiver_57603 points · Sep 22, 2026View

  • “Is there a reason you haven't included an option to move to Elastic EDR?”

    u/SecurityGandalf1 points · Sep 23, 2026View

  • “This is not a pitch, but we utilize/ sell a platform that is essentially managed elastic EDR/SIEM with a 24/7/365 SOC on top of it. I am curious if you have specific reasons for leaving elastic Endgame for S1/Crowdstrike. We have customers running S1 and Crowdstrike EDR and ingest those into our SIEM and work that way, it works just fine. I think ultimately the answer will come down to money a”

    u/justmirsk1 points · Sep 23, 2026View

Extracted by Autobound

From the Signal API record
Signal
Customer feedback

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/AskNetsec
Stage
Considering

Companies

  • CrowdStrikeAlso named
  • SentinelOneAlso named

The full record

From the Signal API record

Numbers

Mentions
3

Details

Timing
Ongoing state
Category
Usability
Virality
Somewhat high
Post kind
Text
Prominence
Core
Company's role
Vendor

Topics and mentions

Topics

  • operations
  • usability
  • total cost of ownership
  • siem

Flair

  • Architecture

Products named

  • Elastic SIEM

Extraction

Sentiment
Negative
Detected
Sep 22, 2026
signal_type
reddit-company
signal_subtype
customerFeedback

Use this data

Get every Reddit signal for Elastic and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Elastic this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/b59c78bd-01ff-5712-a18e-143fdd7f5d32 returns this record as JSON. POST /v1/companies/enrich returns every signal for elastic.co.

{
  "signal_id": "b59c78bd-01ff-5712-a18e-143fdd7f5d32",
  "signal_type": "reddit-company",
  "signal_subtype": "customerFeedback",
  "detected_at": "2026-09-22T19:15:39+00:00",
  "company": {
    "name": "Elastic",
    "domain": "elastic.co"
  },
  "data": {
    "nsfw": false,
    "stage": "considering",
    "awards": 0,
    "timing": "ongoing_state",
    "topics": [
      "siem",
      "operations",
      "usability",
      "total cost of ownership"
    ],
    "post_id": "1wniyv8",
    "summary": "A large EU manufacturing company with a small security team is considering replacing their Elastic SIEM because they find it is 'heavy to operate'.",
    "category": "usability",
    "comments": [
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1wniyv8/comment/pbg3u7o/",
        "depth": 0,
        "score": 10,
        "author": "simplecartoon",
        "excerpt": "We have committed fully to Crowdstrike alongside NextGen SIEM and MDR service. Overseeing the SOC remains a challenging task. My view let’s experts manage and the internal team focus on what they are good at.",
        "posted_at": "2026-09-22T21:25:07.000Z",
        "author_url": "https://www.reddit.com/user/simplecartoon/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1wniyv8/comment/pbh9yt8/",
        "depth": 0,
        "score": 4,
        "author": "jdiscount",
        "excerpt": "I've implemented both Sentinel One and CrowdStrike SIEM.\n\n If you're used to something like Elastic or Splunk they're a big downgrade IMHO.\n\n The CrowdStrike SIEM is better out of those two though.",
        "posted_at": "2026-09-23T01:07:42.000Z",
        "author_url": "https://www.reddit.com/user/jdiscount/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1wniyv8/comment/pbfj39f/",
        "depth": 0,
        "score": 3,
        "author": "Naive_Caregiver_5760",
        "excerpt": "Elastic being a pain to run with a small team is basically the default experience, not some edge case. If you're already feeling that weight now, doubling down on it for raw telemetry later sounds like a headache you'll keep putting off.\n\n Dual console isn't a dealbreaker if your L1/L2 are sharp enough to know when to pivot, but it gets old fast during a real incident when you're flipping tabs try",
        "posted_at": "2026-09-22T19:53:11.000Z",
        "author_url": "https://www.reddit.com/user/Naive_Caregiver_5760/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1wniyv8/comment/pbmcgk8/",
        "depth": 0,
        "score": 1,
        "author": "SecurityGandalf",
        "excerpt": "Is there a reason you haven't included an option to move to Elastic EDR?",
        "posted_at": "2026-09-23T18:48:18.000Z",
        "author_url": "https://www.reddit.com/user/SecurityGandalf/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1wniyv8/comment/pblx98y/",
        "depth": 0,
        "score": 1,
        "author": "justmirsk",
        "excerpt": "This is not a pitch, but we utilize/ sell a platform that is essentially managed elastic EDR/SIEM with a 24/7/365 SOC on top of it.\n\n I am curious if you have specific reasons for leaving elastic Endgame for S1/Crowdstrike. We have customers running S1 and Crowdstrike EDR and ingest those into our SIEM and work that way, it works just fine.\n\n I think ultimately the answer will come down to money a",
        "posted_at": "2026-09-23T17:44:43.000Z",
        "author_url": "https://www.reddit.com/user/justmirsk/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1wniyv8/comment/pbnmhes/",
        "depth": 0,
        "score": 1,
        "author": "Solid5-7",
        "excerpt": "Have you guys thought about move to Elastics “serverless” cloud deployment? We use it and it’s basically no maintenance. We use the security deployments and pay per device with full EDR coverage (Elastic Defend)\n\n It’s by far been my favorite security platform, and I’ve used QRadar, Splunk, Trellix, and Carbon Black.",
        "posted_at": "2026-09-23T22:13:59.000Z",
        "author_url": "https://www.reddit.com/user/Solid5-7/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1wniyv8/comment/pbog5wl/",
        "depth": 0,
        "score": 1,
        "author": "PrestigiousOnion1087",
        "excerpt": "On 2, the thing that predicts regret isn't console preference, it's how many of your Elastic rules actually fire.\n\n Pull the detection rules you rely on and count how many raised an alert at least once in the last 90 days, then migrate that set and park the rest. For scale, on a stock Wazuh 4.14.7 ruleset I counted 635 of 4420 rules sitting at level=0, present and enabled and silent by design. A p",
        "posted_at": "2026-09-24T00:55:34.000Z",
        "author_url": "https://www.reddit.com/user/PrestigiousOnion1087/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1wniyv8/comment/pbrznhk/",
        "depth": 0,
        "score": 1,
        "author": "briandoesdev",
        "excerpt": "Are you guys running Elastic in-house? Or are you using their cloud hosted and/or serverless platform?\n\n If you are self hosting I would highly recommend moving to the cloud platform (serverless for ease of maintenance) and using Elastic Defend. You can still keep Elastic as your SoR and migrating between on-prem and cloud is fairly using with their tooling. You can even start pointing your agents",
        "posted_at": "2026-09-24T14:46:17.000Z",
        "author_url": "https://www.reddit.com/user/briandoesdev/"
      }
    ],
    "evidence": [
      "[post] SIEM today is Elastic; endpoint alerts already land there.",
      "[post] Internal tension: Elastic already feels heavy to operate; vendor SIEM looks “simpler” out of the box.",
      "[comment u/Naive_Caregiver_5760] Elastic being a pain to run with a small team is basically the default experience, not some edge case."
    ],
    "virality": "somewhat_high",
    "post_date": "2026-09-22T19:15:39.000Z",
    "post_kind": "text",
    "post_text": "Large EU manufacturing company, multi-site, small security team.\n\nEndpoint platform renews in the next budget cycle. Shortlist: CrowdStrike vs SentinelOne (vs renewing what we have). SIEM today is Elastic; endpoint alerts already land there.\n\nTwo architecture options:A) Keep Elastic as system of record. Change only the EDR (CS or S1). Day-1 = alerts into Elastic, deep dive in the EDR console. Full raw telemetry (FDR / Cloud Funnel) only later if we really need it.B) Make the chosen vendor’s SIEM (Falcon NG-SIEM or SentinelOne AI SIEM) the SoR and retire Elastic over ~1–1.5 years (parsers, rules, skills, parallel run).\n\nInternal tension: Elastic already feels heavy to operate; vendor SIEM looks “simpler” out of the box. Counter: we’d still re-onboard firewall/IdP/cloud into CS/S1 and retrain whoever does L1/L2.\n\nAlso weighing MSSP (L2 contain on EDR + firewall, including overseas sites) vs vendor MDR as a bridge.\n\nPractitioner takes appreciated:\n\nIs dual-console (Elastic triage + Falcon/S1 deep dive) fine at scale, or a daily tax?\n\nWhen did consolidating off Elastic onto CS or S1 SIEM actually win vs regret?\n\nDo lean teams usually skip FDR / Cloud Funnel into Elastic on day 1?\n\nAny strong reason to pick CS vs S1 *if* we stay on path A (Elastic stays)?\n\nMSSP on Elastic+EDR vs vendor MDR+hub - what worked?\n\nNo vendor pitches please.\n\nThank you",
    "sentiment": "negative",
    "subreddit": "AskNetsec",
    "post_flair": [
      "Architecture"
    ],
    "post_title": "Keep Elastic + swap EDR (CrowdStrike vs SentinelOne), or move SIEM to the EDR vendor?",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/AskNetsec/comments/1wniyv8/keep_elastic_swap_edr_crowdstrike_vs_sentinelone/",
    "entity_role": "vendor",
    "post_author": "Rough-Computer-803",
    "upvote_ratio": 0.9166666666666666,
    "mention_count": 3,
    "mention_surge": true,
    "subreddit_url": "https://www.reddit.com/r/AskNetsec/",
    "total_upvotes": 10,
    "comments_total": 14,
    "total_comments": 14,
    "other_companies": [
      {
        "name": "CrowdStrike",
        "role": "alternative",
        "domain": "crowdstrike.com"
      },
      {
        "name": "SentinelOne",
        "role": "alternative",
        "domain": "sentinelone.com"
      }
    ],
    "post_author_url": "https://www.reddit.com/user/Rough-Computer-803/",
    "signal_category": "feedback",
    "comments_included": 10,
    "products_mentioned": [
      "Elastic SIEM"
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.