# Start Elatsic Security and Observability

**URL:** <https://discuss.elastic.co/t/start-elatsic-security-and-observability/378565>\
**Category:** Elastic Security\
**Created:** [May 27, 2025, 6:32am UTC](https://discuss.elastic.co/t/start-elatsic-security-and-observability/378565 "2025-05-27T06:32:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![felixwong](https://avatars.discourse-cdn.com/v4/letter/f/ed8c4c/32.png) [@felixwong](https://discuss.elastic.co/u/felixwong)\
**Post date:** [May 27, 2025, 6:33am UTC](https://discuss.elastic.co/t/start-elatsic-security-and-observability/378565/1 "2025-05-27T06:33:00Z")

</div>

I am working on building Elastic Security for my company. I want to monitor user login activity and receive alerts when suspicious login behavior occurs. Which Elastic product should I use for this purpose?

From what I understand, Elastic Observability is used to collect logs and other telemetry data, while Elastic Security is focused on threat detection and alerting. Should I implement Elastic Observability to gather the login logs and then use Elastic Security to detect suspicious activity and generate alerts?

I am a bit confused about how these products work together. Could you please clarify their roles and recommend study materials to better understand how to set this up? Thank you!

---

<div class="post-metadata">

**Author:** ![Sergi\_Massaneda\_Dona](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergi_massaneda_dona/32/107149_2.png) [@Sergi\_Massaneda\_Dona](https://discuss.elastic.co/u/Sergi_Massaneda_Dona)\
**Post date:** [May 27, 2025, 8:47am UTC](https://discuss.elastic.co/t/start-elatsic-security-and-observability/378565/2 "2025-05-27T08:47:56Z")

</div>

Elastic Security has specific mechanisms for collecting the relevant logs (Fleet). If you are only interested in security, you don't need to install Elastic Observability.

---

<div class="post-metadata">

**Author:** ![felixwong](https://avatars.discourse-cdn.com/v4/letter/f/ed8c4c/32.png) [@felixwong](https://discuss.elastic.co/u/felixwong)\
**Post date:** [May 27, 2025, 10:14am UTC](https://discuss.elastic.co/t/start-elatsic-security-and-observability/378565/3 "2025-05-27T10:14:00Z")

</div>

Thanks . Do I need to deploy agents to monitor if my servers have Apache Carbon , Tomcat , or application logs .. etc,.

---

<div class="post-metadata">

**Author:** ![Sergi\_Massaneda\_Dona](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergi_massaneda_dona/32/107149_2.png) [@Sergi\_Massaneda\_Dona](https://discuss.elastic.co/u/Sergi_Massaneda_Dona)\
**Post date:** [May 28, 2025, 5:53pm UTC](https://discuss.elastic.co/t/start-elatsic-security-and-observability/378565/4 "2025-05-28T17:53:28Z")

</div>

You only need to install one agent on your host. You'll be able to manage them with Fleet.  
I hope this solves your doubts:

> **[Elastic Agent | Elastic](https://www.elastic.co/elastic-agent)**
>
> Elastic Agent delivers endpoint security and remediation, and simpler and faster telemetry collection, with secure centralized agent management for broad visibility and control in Elastic Observabilit...

The blog post:

> **[Elastic Agent and Fleet make it easier to integrate your systems with Elastic](https://www.elastic.co/blog/elastic-agent-and-fleet-make-it-easier-to-integrate-your-systems-with-elastic)**
>
> Elastic Agent, Fleet, and our first integrations are now generally available. Our unified agent will simplify data onboarding and security. Easily manage many thousands of agents at scale with Fleet, ...

Docs:

> **[Ingesting data for Elastic solutions | Elastic Docs](https://www.elastic.co/docs/manage-data/ingest/ingesting-data-for-elastic-solutions)**
>
> Elastic solutions—Security, Observability, and Search—are loaded with features and functionality to help you get value and insights from your data. Elastic...

Cheers
