"User-Friendly and Excellent for Data Analysis"
One improvement I've noticed is that scaling now feels smoother when dealing with larger datasets. The newer dashboards also appear more responsive, and cloud setup seems easier than before. I appreciate how it handles logs from different sources without much extra configuration. Overall, it remains powerful and flexible for search and analytics. The only lingering issue is that indexing isn't always real-time; there's a slight delay before new events appear. Some cluster management aspects still feel complicated if you're not doing it regularly. A few UI parts could be cleaner, as I sometimes click around too much to find the right view. It's a really good tool compared to others like QRadar, and it's easy to implement, use, and set up—making it an excellent choice for analyzing events.
"Simple Yet Mighty Search Tool"
This tool is easily configurable and highly customizable. We often discovered that user searches revealed content gaps that needed attention. Our analytics team directly benefited from the wealth of data we could extract. I have no complaints; I genuinely can't recall being disappointed with it. Swiftype is user-friendly, powerful, and reasonably priced while offering a top-tier solution. As we rapidly prototyped websites and conducted A/B tests, Swiftype kept us agile and provided the data we needed. Our clients were impressed with the speed and utility of Swiftype's site search.
S
Senior Solution Architect
"Robust and Scalable Search Solution"
What I appreciate most about Elasticsearch is its speed and flexibility. It efficiently handles large data volumes and makes searching extremely fast. It's also versatile enough for both search and analytics use cases. One downside is that it can become complex to manage as it grows, requiring careful planning and monitoring to avoid performance and stability issues. Licensing and pricing changes over time have also caused some uncertainty for users. Elasticsearch enables us to quickly search and analyze large amounts of data in one place, making it easier to find relevant information, monitor systems, and derive insights from logs or application data. This improves visibility and allows us to respond to issues faster and make better decisions.
"Top-Notch NoSQL Database with Vector Search and AI Capabilities"
This is one of the best NoSQL databases available. It simplifies collecting logs from diverse sources and defining integrations for them. It offers a comprehensive suite of features including vector search, machine learning, alerting, and much more. What I dislike are the breaking changes that come with version upgrades, which have significant impacts when multiple teams rely on the deployment. We gather telecom metrics from around 1,000 servers, which facilitates error searching and debugging, KPI creation, and setting up rules and alerts based on that data. As a result, it reduces manual effort and integrates easily with other systems. The best aspect is Elasticsearch's versatility—it serves as a single monitoring point for our entire telecom stack.
"Data Management Made Simple, but Upgrading Is Tricky"
Managing data in Elasticsearch is straightforward compared to other databases, as it avoids the tedious re-indexing and maintenance they require. Setting up an ILM policy allows it to handle growth automatically, and I particularly like managing hot, warm, and cold phases based on data needs. The ability to define data movement between tiers and store historical data in searchable snapshots is my favorite feature. Also, initial setup was easy, which is a big advantage. However, upgrading Elasticsearch between versions is always problematic; rolling upgrades don't allow jumping two versions, and certain versions have restrictions on indices created in earlier versions. I use Elasticsearch for rapid search and data archival, storing trading data for seven years. Managing it is easy with ILM, enabling efficient data tier management without constant re-indexing.
"Swift, Tailorable Search with Excellent Community Support"
I use Elasticsearch to develop search products for websites, and I value the fast, highly customizable search experience it offers. It effectively addresses indexing and search speed challenges, and the ability to deeply customize search while incorporating AI is very advantageous. The supportive community around Elasticsearch is invaluable; there's ample help when building with it, and the thorough documentation simplifies things. Technical support is accessible when needed. I also appreciate events like ElasticON, which are free and educational. Additionally, initial setup was a breeze thanks to excellent documentation. Sometimes, the Elastic Cloud 'PaaS' experience demands more hands-on effort than expected; we have to delve into areas we didn't anticipate to investigate and fix issues. We assumed it would be fully managed by Elastic, but it's not entirely hands-off. I use Elasticsearch to build search products, delivering fast, customizable search and leveraging AI to enhance the search experience.
"Consolidates Multi-Platform Data with Powerful Log Search"
Elasticsearch aggregates information from various platforms, offering a unified search view and efficient searching across massive log data. So far, we haven't utilized many advanced features. When we need a specific function, we have to research the approach and look for case studies in the community. Additionally, there aren't many examples or references easily available for integrating Elasticsearch with third-party applications like Oracle DB or Fortigate Firewall. For internal telecom use, operators typically have numerous IoT devices and applications such as switches, routers, servers, VMs, generating many log files. The inventory is vast and complex. We've leveraged Elasticsearch to create a consolidated view for recording and searching device logs. Moreover, we've set up alarm mechanisms based on known behaviors or thresholds for potential faults, triggering support teams for quick troubleshooting. In summary, it helps with inventory, reporting, monitoring, and troubleshooting.
"Exceptional Speed and Near-Real-Time Search with Elasticsearch"
Elasticsearch provides outstanding search speed and robust performance, even with enormous datasets. Its near real-time search combined with powerful full-text search makes it a cornerstone of our data infrastructure. However, Elasticsearch can be heavy on resources, especially RAM. For smaller setups, managing JVM heap sizes and ensuring adequate cluster memory can quickly turn into a challenge. Elasticsearch tackles the issue of searching through vast amounts of unstructured data that traditional SQL databases handle poorly. It offers a highly scalable, distributed environment that guarantees fast retrieval. This has helped me by significantly lowering latency in our application's search functionality and providing potent analytical tools through its aggregation framework. It enables real-time log monitoring and delivers a smooth, Google-like search experience to our users.
M
Mid-Market (51-1000 emp.)
"Rapid, Scalable Elasticsearch for Real-Time Security Operations"
Elasticsearch excels in speed, scalability, and powerful search capabilities. I particularly value how effortlessly it ingests and correlates large volumes of security and operational data. KQL, the Query DSL, and Kibana offer great flexibility for investigations and visualizations. Overall, it's highly effective for real-time security monitoring, threat hunting, alerting, and crafting custom dashboards. The main downside is the complexity involved in managing and tuning Elasticsearch at scale. Tasks such as index management, shard sizing, mappings, retention policies, and controlling resource usage often demand considerable expertise. Kibana setup and configuring detection rules can also become complicated, especially in large environments with high event volumes. Additionally, licensing costs for advanced security and observability features might be a significant factor for organizations with large deployments. Elasticsearch helps us centralize and analyze large volumes of security and operational data from endpoints, servers, network devices, and applications. With real-time search, dashboards, and automated detection rules, it accelerates alert investigation, threat hunting, log correlation, and detection of suspicious activity. In summary, it has greatly improved our SOC visibility and incident response, reduced investigation time, and made it simpler to identify patterns and potential threats across our environment.
"User-Friendly Interface, Great Integrations, and Top-Notch Speed"
The interface and user experience are clean and straightforward, making it easy for newcomers to use Elasticsearch. It comes with built-in integrations that work well with a wide range of products. I've relied on it for over four years, and its performance for data analysis outshines other solutions I've tried. I've never encountered any problems with it. With Elasticsearch, we've been able to consolidate all our logs into a single location, and the search speed is remarkably fast—even when querying billions of documents, responses are quick. We pair it with Kibana for visualizations, which lets our team spot anomalies or error spikes much faster than before. Scalability is also excellent; adding nodes causes minimal downtime, and the cluster automatically handles shard distribution. For our log monitoring use case, this is invaluable because our log volume expands every month.