I think with OpenEDR, ELK has to be integrated by the users itself. Apart from telemetry what are the advantages of OpenEDR over cWatchEDR?
yes it will be required to integrate ELK. The agent is the same so the telemetry data collected as well as endpoint rules will be the same.
On Our cloud version, we have aggregated, indexed and summaries the data for dashboards, quarries, etc. the most work has been done for constructing event hierarchy like process creation information etc. All can be done with ELK but with some extra work will be required of course