SOC on Elastic Security: what ANOMAL delivers for existing customers

ANOMAL runs a 24/7 SOC for organisations already invested in Elastic Security. We manage detection engineering, response and threat hunting on your Elastic cluster. We correlate logs, endpoint, identity and cloud signals in one platform and handle documented response. Elastic is your platform, and ANOMAL is your operations team.

All

How this compares to neighbouring topics

This page describes how ANOMAL operates a SOC on Elastic Security. For fundamentals see What is a SOC. For the boundary between SIEM platform and managed service, see SOC vs. SIEM and MDR vs. Managed SIEM. For the Microsoft or CrowdStrike counterparts, see SOC for Microsoft 365 and Sentinel and SOC on CrowdStrike Falcon. See SOC cost Switzerland for pricing details.

Who this page is for

This page is for organisations that already licence Elastic Security, self-host it, or run it as Elastic Cloud. It does not describe the Elastic platform itself, but what ANOMAL delivers around it: operations, detection engineering, response, reporting. If you have not yet chosen a platform, start with SOC provider comparison.

What ANOMAL runs on your Elastic cluster

  • 24/7 monitoring of the Elastic Security stack by our analysts
  • Detection engineering: customer-specific rules in EQL, KQL and ES|QL, tuning of prebuilt rules
  • Playbook-driven response: host isolation via Elastic Defend, process kill, data-source quarantine
  • Threat hunting across raw logs, endpoint events and network signals in a single query layer
  • Correlation of cloud, identity and OT signals via Beats, Agent and custom integrations
  • Monthly reporting with MTTD, MTTR, MTTC, coverage map and open detections

How this differs from Elastic support or Elastic consulting alone

Elastic provides platform support and professional services. Its services exclude a 24/7 SOC with response rights in your environment. Dedicated Elastic consulting partners build the stack. They do not operate it around the clock. ANOMAL takes over daily operations, detection engineering and documented response. Elastic retains the platform, and you retain data sovereignty. Our relationship to the platform is technical, not contractual.

Rule of thumb

Elastic support keeps the platform alive. ANOMAL turns the platform into a SOC.

What documented response on Elastic looks like in practice

  • Host isolation via Elastic Defend within minutes of a confirmed detection
  • Response actions via Osquery and Elastic Agent, with audit log kept inside the cluster
  • Automated playbooks via Elastic Cases and connected SOAR or ticketing systems
  • Communication directly with your IT via a defined channel
  • Full case and timeline documentation for audit, revFADP and insurance

Typical pitfalls

Elastic without active detection engineering is a strong SIEM running generic prebuilt rules. A service that only forwards alerts without responding covers visibility, not response. Second, Elastic scales strongly with log volume but can turn expensive without a clean ingestion strategy. Without data tiering, suppression and sensible retention, cluster cost explodes. Third, without documented response rights the SOC cannot act when it matters. Alert-quality KPIs are covered in SOC KPIs MTTD and MTTR. For SIEM terminology see Glossary SIEM.

Cost drivers

Cost for a managed SOC with Elastic Security follows endpoints, identities, data sources, data volume, response scope and onboarding; vendor licences come on top. Full cost logic under SOC cost Switzerland.

Rule of thumb

Elastic without analysts is expensive log storage. Elastic with a SOC is a response platform.

Frequently asked questions

Does ANOMAL operate self-hosted Elastic clusters or only Elastic Cloud?

We operate both. We work on your existing cluster, whether on-premises, in a Swiss private cloud or in Elastic Cloud. We need defined access with documented rights. Your Elastic licence remains unchanged. Data sovereignty stays with you.

How many data sources can we reasonably connect?

Technically there is barely a ceiling. For cost control, we recommend a prioritised ingestion strategy. Start with identity, endpoint and perimeter, then add cloud and applications, followed by OT and less critical business systems. Anything without a detection purpose goes to cheaper frozen tiers or stays out of Elastic entirely.

Which response rights does ANOMAL need in Elastic Security?

ANOMAL needs at least host isolation and response actions via Elastic Defend according to the playbook catalogue, plus rule and case management. Optional extensions include Osquery actions for specific cases. Contracts define all rights, and the Elastic audit log records them.

How long does onboarding an Elastic environment take?

Onboarding takes several weeks. The time goes into access setup, ingestion review, rule baseline, data tiering and playbook tuning. See [SOC onboarding Switzerland](/en/soc/soc-onboarding-switzerland) for details.

Can we run Elastic in parallel with CrowdStrike or Sentinel?

Yes. In hybrid environments Elastic often serves as the central correlation and retention layer, while CrowdStrike Falcon or Microsoft Defender provides endpoint or identity signals. ANOMAL correlates these layers in a single timeline and playbook set, so you do not pay for two separate SOCs.

Continue reading in this cluster
What is a SOC? Definition, tasks and structure
A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.
SOC, SIEM, EDR, XDR, MDR: the terms explained
SOC is the function; SIEM, EDR and XDR are tools; MDR is a service. The label matters less than whether response happens and in whose mandate. At ANOMAL, SOC as a Service covers detection and response and is often called MDR; a managed SIEM is part of the SOC with analysts and response in the mandate. Customers keep their existing tools.
SOC for Microsoft 365 and Sentinel: what matters
A SOC for Microsoft 365 and Sentinel environments correlates signals from Entra ID, Defender XDR, Exchange Online and Azure in one detection layer. It responds 24/7. Analysts, playbooks and documented response provide the operational value beyond the licence.
SOC on CrowdStrike Falcon: what ANOMAL delivers for existing customers
ANOMAL runs a 24/7 SOC for organisations already invested in CrowdStrike Falcon. We orchestrate detection engineering, response and threat hunting on your Falcon console, correlate signals with identity and cloud, and take over documented response. Falcon is your platform, ANOMAL is your operations team.
What a SOC costs: cost drivers, pricing models, in-house or service
SOC costs arise from the response scope first, not the platform licence. What counts are endpoint and identity counts, log sources and data volume, the response scope you choose, onboarding and licences. Swiss providers rarely publish prices; offers differ widely by scope. Your own calculation starts by holding the cost drivers against your organisation.