SOC on Elastic Security: what ANOMAL delivers for existing customers
ANOMAL runs a 24/7 SOC for organisations already invested in Elastic Security. We manage detection engineering, response and threat hunting on your Elastic cluster. We correlate logs, endpoint, identity and cloud signals in one platform and handle documented response. Elastic is your platform, and ANOMAL is your operations team.
How this compares to neighbouring topics
This page describes how ANOMAL operates a SOC on Elastic Security. For fundamentals see What is a SOC. For the boundary between SIEM platform and managed service, see SOC vs. SIEM and MDR vs. Managed SIEM. For the Microsoft or CrowdStrike counterparts, see SOC for Microsoft 365 and Sentinel and SOC on CrowdStrike Falcon. See SOC cost Switzerland for pricing details.
Who this page is for
This page is for organisations that already licence Elastic Security, self-host it, or run it as Elastic Cloud. It does not describe the Elastic platform itself, but what ANOMAL delivers around it: operations, detection engineering, response, reporting. If you have not yet chosen a platform, start with SOC provider comparison.
What ANOMAL runs on your Elastic cluster
- 24/7 monitoring of the Elastic Security stack by our analysts
- Detection engineering: customer-specific rules in EQL, KQL and ES|QL, tuning of prebuilt rules
- Playbook-driven response: host isolation via Elastic Defend, process kill, data-source quarantine
- Threat hunting across raw logs, endpoint events and network signals in a single query layer
- Correlation of cloud, identity and OT signals via Beats, Agent and custom integrations
- Monthly reporting with MTTD, MTTR, MTTC, coverage map and open detections
How this differs from Elastic support or Elastic consulting alone
Elastic provides platform support and professional services. Its services exclude a 24/7 SOC with response rights in your environment. Dedicated Elastic consulting partners build the stack. They do not operate it around the clock. ANOMAL takes over daily operations, detection engineering and documented response. Elastic retains the platform, and you retain data sovereignty. Our relationship to the platform is technical, not contractual.
Elastic support keeps the platform alive. ANOMAL turns the platform into a SOC.
What documented response on Elastic looks like in practice
- Host isolation via Elastic Defend within minutes of a confirmed detection
- Response actions via Osquery and Elastic Agent, with audit log kept inside the cluster
- Automated playbooks via Elastic Cases and connected SOAR or ticketing systems
- Communication directly with your IT via a defined channel
- Full case and timeline documentation for audit, revFADP and insurance
Typical pitfalls
Elastic without active detection engineering is a strong SIEM running generic prebuilt rules. A service that only forwards alerts without responding covers visibility, not response. Second, Elastic scales strongly with log volume but can turn expensive without a clean ingestion strategy. Without data tiering, suppression and sensible retention, cluster cost explodes. Third, without documented response rights the SOC cannot act when it matters. Alert-quality KPIs are covered in SOC KPIs MTTD and MTTR. For SIEM terminology see Glossary SIEM.
Cost drivers
Cost for a managed SOC with Elastic Security follows endpoints, identities, data sources, data volume, response scope and onboarding; vendor licences come on top. Full cost logic under SOC cost Switzerland.
Elastic without analysts is expensive log storage. Elastic with a SOC is a response platform.
Placement in SOC operations
See SOC as a Service Switzerland for how ANOMAL integrates Elastic Security into its operations.
Frequently asked questions
Does ANOMAL operate self-hosted Elastic clusters or only Elastic Cloud?
We operate both. We work on your existing cluster, whether on-premises, in a Swiss private cloud or in Elastic Cloud. We need defined access with documented rights. Your Elastic licence remains unchanged. Data sovereignty stays with you.
How many data sources can we reasonably connect?
Technically there is barely a ceiling. For cost control, we recommend a prioritised ingestion strategy. Start with identity, endpoint and perimeter, then add cloud and applications, followed by OT and less critical business systems. Anything without a detection purpose goes to cheaper frozen tiers or stays out of Elastic entirely.
Which response rights does ANOMAL need in Elastic Security?
ANOMAL needs at least host isolation and response actions via Elastic Defend according to the playbook catalogue, plus rule and case management. Optional extensions include Osquery actions for specific cases. Contracts define all rights, and the Elastic audit log records them.
How long does onboarding an Elastic environment take?
Onboarding takes several weeks. The time goes into access setup, ingestion review, rule baseline, data tiering and playbook tuning. See [SOC onboarding Switzerland](/en/soc/soc-onboarding-switzerland) for details.
Can we run Elastic in parallel with CrowdStrike or Sentinel?
Yes. In hybrid environments Elastic often serves as the central correlation and retention layer, while CrowdStrike Falcon or Microsoft Defender provides endpoint or identity signals. ANOMAL correlates these layers in a single timeline and playbook set, so you do not pay for two separate SOCs.
Related terms
- SIEM A Security Information and Event Management (SIEM) system collects logs from many sources, makes them searchable and analyses them with detection rules.
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- Detection as Code Detection as Code manages detection rules like software: versioned, tested, reviewed and deployed automatically.
- Sigma Rules Sigma rules describe detection logic for logs in an open format that can be translated for many SIEM platforms.
- Log Source A log source is any system that provides security-relevant events to a SIEM or the SOC.