# Elastic Stack for SIEM(Elastic Security)

**URL:** <https://discuss.elastic.co/t/elastic-stack-for-siem-elastic-security/356870>\
**Category:** SIEM\
**Created:** [April 5, 2024, 1:27pm UTC](https://discuss.elastic.co/t/elastic-stack-for-siem-elastic-security/356870 "2024-04-05T13:27:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aliya\_Khalel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aliya_khalel/32/132809_2.png) [@Aliya\_Khalel](https://discuss.elastic.co/u/Aliya_Khalel)\
**Post date:** [April 5, 2024, 1:27pm UTC](https://discuss.elastic.co/t/elastic-stack-for-siem-elastic-security/356870/1 "2024-04-05T13:27:55Z")

</div>

Hello, I am noob in Elastic.

We planning to use Elastic Security for MSSP.

3 nodes of Elastic will be in private datacenter and our customer's logs will send by VPN.

The question: I don't know how to forward data from customer side to my cluster.

1. Should I use Logstash with Beats?
2. My colleague says that we can use Elastic Agents and it will be much easier... but I didn't find any information about what is better or right to use...

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 5, 2024, 2:19pm UTC](https://discuss.elastic.co/t/elastic-stack-for-siem-elastic-security/356870/2 "2024-04-05T14:19:42Z")

</div>

Hi @Aliya_Khalel

It really depends on what you're trying to accomplish depending on The specifics of your use case.

Both are valid approaches.

But in short, if you're just getting started, I would recommend  
starting with the Elastic Agent.

Elastic agent has some nice features such as being able to upgrade from a central console, hundreds of out of the box integrations and it's the way elastic is moving forward in the future.

It also includes elastic defend which is the endpoint security capabilities If you choose to configure that.

Here is a bit of a comparison.

> **[Beats and Elastic Agent capabilities | Fleet and Elastic Agent Guide \[8.13\] |...](https://www.elastic.co/guide/en/fleet/current/beats-agent-comparison.html)**

Get started and come back with detailed questions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2024, 2:20pm UTC](https://discuss.elastic.co/t/elastic-stack-for-siem-elastic-security/356870/3 "2024-05-03T14:20:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
