Fixed Price Deliverable

SIEM Accelerator: Basic, Standard, and Advanced

Basic

Overview

A fixed-price, time-boxed implementation engagement to deploy a foundational Elastic SIEM solution on one (1) net-new Elastic Cloud Hosted (ECH) or Serverless cluster, including configuration of data ingestion, dashboard setup, and detection rule implementation. This engagement is limited to one (1) net-new cluster only and does not cover existing (brownfield) deployments. Any additional clusters, deployments, environments, or expanded scope are expressly out of scope unless otherwise agreed in a mutually executed Order Form (change order).

Scope

  • Conduct discovery, finalize up to two (2) out-of-the-box integration data sources (excluding Elastic Defend), select up to two (2) out-of-the-box detection rules (excluding machine learning (ML) rules), define high-level data fields and use cases, and design a basic RBAC structure for up to two (2) customer roles.
  • Provision the ECH/Serverless cluster, configure Fleet Server, set up SIEM and RBAC in Kibana, and finalize detection rule and dashboard design.
  • Install Elastic Agent(s), configure and validate integrations for the two (2) selected data sources, tune and validate the two (2) selected out-of-the-box detection rules, and build/refine one (1) custom dashboard using live data and customer feedback.
  • Conduct a knowledge transfer workshop, provide documentation and a final report, transfer engagement assets to the customer, and complete project wrap-up.

Out of scope

This engagement does not include:

  • Configuration or integration of data sources beyond the two (2) sources defined in Scope, including the Elastic Defend data source
  • Any data not coming directly from the integration such as PAN logs in cribl or snowflake for example
  • Detection rules beyond the two (2) out-of-the-box rules defined in Scope, including any rules based on machine learning (ML)
  • Custom detection rule development beyond tuning and validation of the provided out-of-the-box rule content
  • Threat hunting, incident response, or SOAR/case management configuration
  • Evaluation, configuration, or integration of additional clusters, deployments, or environments
  • Evaluation or migration of existing (brownfield) Elastic deployments; this engagement covers net-new implementations only
  • Custom dashboard or visualization development beyond the one (1) custom dashboard included in this service
  • Data source-specific parsing, enrichment, or normalization beyond out-of-the-box integration defaults
  • Project management beyond internal Elastic delivery coordination
  • Ongoing support, operational ownership, or post-engagement remediation assistance unless separately purchased

Any work outside the scope above requires a mutually executed Order Form (change order) and may result in additional fees, revised assumptions, and schedule changes.

Engagement timeline

  • Scheduled to commence approximately 6–8 weeks after purchase, subject to resource availability and Customer readiness
  • Delivered by an Elastic Consultant or a certified partner resource under Elastic oversight
  • Unless otherwise agreed in writing, the services will be delivered remotely
  • Delivery is expected to occur over contiguous business days or contiguous calendar weeks, as scheduled by Elastic
  • If delivery is delayed, interrupted, or rescheduled due to Customer availability, access issues, environment readiness, or other Customer dependencies, Elastic may reassign resources, adjust the schedule, or require an Order Form (change order)
  • Time scheduled for the engagement that cannot be used due to Customer delay, unavailability, failure to meet dependencies, or inability to provide required access will count against the total consulting days

Fixed-price conditions and assumptions

The fixed price is based on the following assumptions and conditions:

  • Customer provides all required access, credentials, documentation, and relevant architectural information before the kickoff call
  • Customer designates a single point of contact and ensures appropriate technical stakeholders are available and responsive throughout the engagement
  • The target ECH/Serverless cluster is accessible, operational, and ready for configuration at the start of the engagement
  • Customer objectives, priorities, and detection use cases are defined and agreed before kickoff
  • The engagement covers a net-new (greenfield) implementation only; migration or evaluation of an existing deployment is out of scope
  • The engagement is limited to configuration of up to two (2) out-of-the-box integration data sources (excluding Elastic Defend), up to two (2) out-of-the-box detection rules (excluding ML rules), and RBAC for up to two (2) customer roles
  • The engagement is limited to the configuration of one (1) cluster only
  • No material changes to scope, target environment, architecture, or objectives are introduced after kickoff
  • Elastic's configuration and recommendations depend on the completeness, accuracy, and timeliness of the information and data provided by Customer or made available from the target environment during the engagement

If any of the above assumptions are not met, Elastic may adjust the schedule, limit the services performed to fit the fixed-price scope, or require an Order Form (change order).

Deliverables

  • One (1) configured net-new ECH/Serverless cluster with SIEM and RBAC configured
  • Configured and validated integrations for two (2) out-of-the-box data sources (excluding Elastic Defend)
  • Two (2) tuned and validated out-of-the-box detection rules (excluding ML rules)
  • One (1) custom dashboard
  • One (1) final report
  • Engagement documentation
  • One (1) knowledge transfer workshop

Completion

The engagement will be considered to have reached Completion upon delivery of the configured cluster, validated data source integrations, tuned detection rules, the custom dashboard, the final report, and Elastic's delivery or making available of the knowledge transfer workshop. The engagement may also be deemed to have reached Completion if Customer delays, is unavailable, fails to meet required dependencies, or is otherwise unable to participate after Elastic has made commercially reasonable efforts to schedule and deliver the services within the agreed scope. Completion is not conditioned on Customer's participation in, use of, or response to any deliverable or session.

General terms

Capitalized terms used but not defined in this package description have the meanings given to them in the Order Form, the applicable Service Description, or the Elastic Services Agreement.

No formal Customer signoff and no milestone or deliverable acceptance process applies to this fixed-price Services Package. Each Service is deemed accepted upon Completion.

"Completion" means, with respect to a Service, the point at which Elastic has performed the activities within the scope of this Services Package, including (where applicable) delivery of any written report, materials, or knowledge transfer session described in this package's scope, or the expiry of the time-boxed engagement period for this package, whichever occurs first. Completion does not require Customer signoff or acceptance of any deliverable.

Customer is solely responsible for the backup, maintenance, and security of its environment, systems, and data. Elastic is not responsible for any configuration changes, data loss, downtime, or other impact to Customer's environment arising from or in connection with the Service.

This engagement delivers a configured net-new Elastic SIEM cluster, including data source integrations, detection rules, a custom dashboard, and a final report, within the defined fixed-price scope. Elastic does not guarantee any specific performance, cost, operational, or business outcome beyond the deliverables defined above. Customer remains solely responsible for ongoing operations, configuration changes made outside the engagement scope, and all post-engagement activities related to its environment.

References in this package to validation, testing, acceptance tests or acceptance test harnesses, golden queries, launch readiness, or go-live describe activities performed, demonstrated, or delivered by Elastic and do not create any Customer acceptance, signoff, testing, or payment condition. Completion occurs as defined in this package regardless of any such activity, and no portion of the fees is withheld or deferred pending any test result, validation, or go-live event.

Standard

Overview

A fixed-price, time-boxed implementation engagement to deploy a foundational Elastic SIEM solution on one (1) net-new Elastic Cloud Hosted (ECH) or Serverless cluster, including configuration of data ingestion, dashboard setup, and detection rule implementation. This engagement is limited to one (1) net-new cluster only and does not cover existing (brownfield) deployments. Any additional clusters, deployments, environments, or expanded scope are expressly out of scope unless otherwise agreed in a mutually executed Order Form (change order).

Scope

  • Conduct discovery, finalize up to five (5) out-of-the-box integration data sources (excluding Elastic Defend), select up to five (5) out-of-the-box detection rules (excluding machine learning (ML) rules), define high-level data fields and use cases, and design a basic RBAC structure for up to two (2) customer roles.
  • Provision the ECH/Serverless cluster, configure Fleet Server, set up SIEM and RBAC in Kibana, and finalize detection rule and dashboard design.
  • Install Elastic Agent(s), configure and validate integrations for the five (5) selected data sources, tune and validate the five (5) selected out-of-the-box detection rules, and build/refine two (2) custom dashboards using live data and customer feedback.
  • Conduct a knowledge transfer workshop, provide documentation and a final report, and transfer engagement assets to the customer.

Out of scope

This engagement does not include:

  • Configuration or integration of data sources beyond the five (5) sources defined in Scope, including the Elastic Defend data source
  • Any data not coming directly from the integration such as PAN logs in cribl or snowflake for example
  • Detection rules beyond the five (5) out-of-the-box rules defined in Scope, including any rules based on machine learning (ML)
  • Custom detection rule development beyond tuning and validation of the provided out-of-the-box rule content
  • Threat hunting, incident response, or SOAR/case management configuration
  • Evaluation, configuration, or integration of additional clusters, deployments, or environments
  • Evaluation or migration of existing (brownfield) Elastic deployments; this engagement covers net-new implementations only
  • Custom dashboard or visualization development beyond the two (2) custom dashboards included in this service
  • Data source-specific parsing, enrichment, or normalization beyond out-of-the-box integration defaults
  • Project management beyond internal Elastic delivery coordination
  • Ongoing support, operational ownership, or post-engagement remediation assistance unless separately purchased

Any work outside the scope above requires a mutually executed Order Form (change order) and may result in additional fees, revised assumptions, and schedule changes.

Engagement timeline

  • Scheduled to commence approximately 6–8 weeks after purchase, subject to resource availability and Customer readiness
  • Delivered by an Elastic Consultant or a certified partner resource under Elastic oversight
  • Unless otherwise agreed in writing, the services will be delivered remotely
  • Delivery is expected to occur over contiguous business days or contiguous calendar weeks, as scheduled by Elastic
  • If delivery is delayed, interrupted, or rescheduled due to Customer availability, access issues, environment readiness, or other Customer dependencies, Elastic may reassign resources, adjust the schedule, or require an Order Form (change order)
  • Time scheduled for the engagement that cannot be used due to Customer delay, unavailability, failure to meet dependencies, or inability to provide required access will count against the total consulting days

Fixed-price conditions and assumptions

The fixed price is based on the following assumptions and conditions:

  • Customer provides all required access, credentials, documentation, and relevant architectural information before the kickoff call
  • Customer designates a single point of contact and ensures appropriate technical stakeholders are available and responsive throughout the engagement
  • The target ECH/Serverless cluster is accessible, operational, and ready for configuration at the start of the engagement
  • Customer objectives, priorities, and detection use cases are defined and agreed before kickoff
  • The engagement covers a net-new (greenfield) implementation only; migration or evaluation of an existing deployment is out of scope
  • The engagement is limited to configuration of up to five (5) out-of-the-box integration data sources (excluding Elastic Defend), up to five (5) out-of-the-box detection rules (excluding ML rules), and RBAC for up to two (2) customer roles
  • The engagement is limited to the configuration of one (1) cluster only
  • No material changes to scope, target environment, architecture, or objectives are introduced after kickoff
  • Elastic's configuration and recommendations depend on the completeness, accuracy, and timeliness of the information and data provided by Customer or made available from the target environment during the engagement

If any of the above assumptions are not met, Elastic may adjust the schedule, limit the services performed to fit the fixed-price scope, or require an Order Form (change order).

Deliverables

  • One (1) configured net-new ECH/Serverless cluster with SIEM and RBAC configured
  • Configured and validated integrations for five (5) out-of-the-box data sources (excluding Elastic Defend)
  • Five (5) tuned and validated out-of-the-box detection rules (excluding ML rules)
  • Two (2) custom dashboards
  • One (1) final report
  • Engagement documentation
  • One (1) knowledge transfer workshop

Completion

The engagement will be considered to have reached Completion upon delivery of the configured cluster, validated data source integrations, tuned detection rules, the custom dashboards, the final report, and Elastic's delivery or making available of the knowledge transfer workshop. The engagement may also be deemed to have reached Completion if Customer delays, is unavailable, fails to meet required dependencies, or is otherwise unable to participate after Elastic has made commercially reasonable efforts to schedule and deliver the services within the agreed scope. Completion is not conditioned on Customer's participation in, use of, or response to any deliverable or session.

General terms

Capitalized terms used but not defined in this package description have the meanings given to them in the Order Form, the applicable Service Description, or the Elastic Services Agreement.

No formal Customer signoff and no milestone or deliverable acceptance process applies to this fixed-price Services Package. Each Service is deemed accepted upon Completion.

"Completion" means, with respect to a Service, the point at which Elastic has performed the activities within the scope of this Services Package, including (where applicable) delivery of any written report, materials, or knowledge transfer session described in this package's scope, or the expiry of the time-boxed engagement period for this package, whichever occurs first. Completion does not require Customer signoff or acceptance of any deliverable.

Customer is solely responsible for the backup, maintenance, and security of its environment, systems, and data. Elastic is not responsible for any configuration changes, data loss, downtime, or other impact to Customer's environment arising from or in connection with the Service.

This engagement delivers a configured net-new Elastic SIEM cluster, including data source integrations, detection rules, custom dashboards, and a final report, within the defined fixed-price scope. Elastic does not guarantee any specific performance, cost, operational, or business outcome beyond the deliverables defined above. Customer remains solely responsible for ongoing operations, configuration changes made outside the engagement scope, and all post-engagement activities related to its environment.

References in this package to validation, testing, acceptance tests or acceptance test harnesses, golden queries, launch readiness, or go-live describe activities performed, demonstrated, or delivered by Elastic and do not create any Customer acceptance, signoff, testing, or payment condition. Completion occurs as defined in this package regardless of any such activity, and no portion of the fees is withheld or deferred pending any test result, validation, or go-live event.

Advanced

Overview

A fixed-price, time-boxed implementation engagement to deploy a foundational Elastic SIEM solution on one (1) net-new, self-managed Elastic deployment (including ECE/ECK), including configuration of data ingestion, dashboard setup, and detection rule implementation. This engagement is limited to one (1) net-new cluster of up to ten (10) nodes and does not cover existing (brownfield) deployments. Any additional clusters, deployments, environments, or clusters exceeding ten (10) nodes are expressly out of scope unless otherwise agreed in a mutually executed Order Form (change order).

Scope

  • Conduct discovery, finalize up to five (5) in-scope integration data sources (excluding Elastic Defend), select up to five (5) out-of-the-box detection rules (excluding machine learning (ML) rules), define high-level data fields and use cases, design a basic RBAC structure for up to two (2) customer roles, architect the self-managed deployment (up to 10 nodes), and plan for cluster security and data ingestion.
  • Provision and validate infrastructure, configure operating systems, generate and distribute TLS certificates, install and bootstrap Elasticsearch and Kibana, deploy Fleet Server, and configure SIEM and RBAC.
  • Install Elastic Agent(s), configure and validate integrations for the five (5) selected data sources, tune and validate the five (5) selected out-of-the-box detection rules, and build/refine two (2) custom dashboards using live data and customer feedback.
  • Conduct a knowledge transfer workshop, provide documentation and a final report, transfer engagement assets to the customer, and complete project wrap-up.

Out of scope

This engagement does not include:

  • Configuration or integration of data sources beyond the five (5) sources defined in Scope, including the Elastic Defend data source
  • Any data not coming directly from the integration such as PAN logs in cribl or snowflake for example
  • Detection rules beyond the five (5) out-of-the-box rules defined in Scope, including any rules based on machine learning (ML)
  • Custom detection rule development beyond tuning and validation of the provided out-of-the-box rule content
  • Threat hunting, incident response, or SOAR/case management configuration
  • Evaluation, configuration, or integration of additional self-managed deployments, clusters, or environments
  • Evaluation or migration of existing (brownfield) Elastic deployments; this engagement covers net-new implementations only
  • Deployments or cluster sizing exceeding ten (10) nodes
  • Custom dashboard or visualization development beyond the two (2) custom dashboards included in this service
  • Data source-specific parsing, enrichment, or normalization beyond out-of-the-box integration defaults
  • Underlying infrastructure procurement, capacity planning beyond the provisioned environment, or ongoing infrastructure management
  • Project management beyond internal Elastic delivery coordination
  • Ongoing support, operational ownership, or post-engagement remediation assistance unless separately purchased

Any work outside the scope above requires a mutually executed Order Form (change order) and may result in additional fees, revised assumptions, and schedule changes.

Engagement timeline

  • Scheduled to commence approximately 6–8 weeks after purchase, subject to resource availability and Customer readiness
  • Delivered by an Elastic Consultant or a certified partner resource under Elastic oversight
  • Unless otherwise agreed in writing, the services will be delivered remotely
  • Delivery is expected to occur over contiguous business days or contiguous calendar weeks, as scheduled by Elastic
  • If delivery is delayed, interrupted, or rescheduled due to Customer availability, access issues, environment readiness, or other Customer dependencies, Elastic may reassign resources, adjust the schedule, or require an Order Form (change order)
  • Time scheduled for the engagement that cannot be used due to Customer delay, unavailability, failure to meet dependencies, or inability to provide required access will count against the total consulting days

Fixed-price conditions and assumptions

The fixed price is based on the following assumptions and conditions:

  • Customer provides all required access, credentials, documentation, and relevant architectural information before the kickoff call
  • Customer designates a single point of contact and ensures appropriate technical stakeholders are available and responsive throughout the engagement
  • The target infrastructure is provisioned, accessible, operational, and ready for configuration at the start of the engagement
  • Customer objectives, priorities, and detection use cases are defined and agreed before kickoff
  • The engagement covers a net-new (greenfield) implementation only; migration or evaluation of an existing deployment is out of scope
  • The engagement is limited to configuration of up to five (5) in-scope integration data sources (excluding Elastic Defend), up to five (5) out-of-the-box detection rules (excluding ML rules), and RBAC for up to two (2) customer roles
  • The engagement is limited to the configuration of one (1) self-managed deployment (including ECE/ECK) of up to ten (10) nodes only
  • No material changes to scope, target environment, architecture, or objectives are introduced after kickoff
  • Elastic's configuration and recommendations depend on the completeness, accuracy, and timeliness of the information and data provided by Customer or made available from the target environment during the engagement

If any of the above assumptions are not met, Elastic may adjust the schedule, limit the services performed to fit the fixed-price scope, or require an Order Form (change order).

Deliverables

  • One (1) configured net-new self-managed deployment (up to 10 nodes) with SIEM and RBAC configured
  • Configured and validated integrations for five (5) out-of-the-box data sources (excluding Elastic Defend)
  • Five (5) tuned and validated out-of-the-box detection rules (excluding ML rules)
  • Two (2) custom dashboards
  • One (1) final report
  • Engagement documentation
  • One (1) knowledge transfer workshop

Completion

The engagement will be considered to have reached Completion upon delivery of the configured deployment, validated data source integrations, tuned detection rules, the custom dashboards, the final report, and Elastic's delivery or making available of the knowledge transfer workshop. The engagement may also be deemed to have reached Completion if Customer delays, is unavailable, fails to meet required dependencies, or is otherwise unable to participate after Elastic has made commercially reasonable efforts to schedule and deliver the services within the agreed scope. Completion is not conditioned on Customer's participation in, use of, or response to any deliverable or session.

General terms

Capitalized terms used but not defined in this package description have the meanings given to them in the Order Form, the applicable Service Description, or the Elastic Services Agreement.

No formal Customer signoff and no milestone or deliverable acceptance process applies to this fixed-price Services Package. Each Service is deemed accepted upon Completion.

"Completion" means, with respect to a Service, the point at which Elastic has performed the activities within the scope of this Services Package, including (where applicable) delivery of any written report, materials, or knowledge transfer session described in this package's scope, or the expiry of the time-boxed engagement period for this package, whichever occurs first. Completion does not require Customer signoff or acceptance of any deliverable.

Customer is solely responsible for the backup, maintenance, and security of its environment, systems, and data. Elastic is not responsible for any configuration changes, data loss, downtime, or other impact to Customer's environment arising from or in connection with the Service.

This engagement delivers a configured net-new, self-managed Elastic SIEM deployment, including infrastructure provisioning, data source integrations, detection rules, custom dashboards, and a final report, within the defined fixed-price scope. Elastic does not guarantee any specific performance, cost, operational, or business outcome beyond the deliverables defined above. Customer remains solely responsible for ongoing operations, configuration changes made outside the engagement scope, and all post-engagement activities related to its environment.

References in this package to validation, testing, acceptance tests or acceptance test harnesses, golden queries, launch readiness, or go-live describe activities performed, demonstrated, or delivered by Elastic and do not create any Customer acceptance, signoff, testing, or payment condition. Completion occurs as defined in this package regardless of any such activity, and no portion of the fees is withheld or deferred pending any test result, validation, or go-live event.