Elastic Cloud managed service pricing

Elastic Cloud gives you the flexibility to run where you want. Deploy our managed service on Google Cloud, Microsoft Azure, or Amazon Web Services, and we'll handle the maintenance and upkeep for you.

Standard

Great place to start for small projects.

As low as

$16/month

Features include:
  • Core Elastic Stack security features
  • Capabilities such as Elastic APM, App Search, Workplace Search, Security, and Maps
  • Canvas & Lens
  • And more

Gold

Dedicated support and more features.

As low as

$19/month

Everything in Standard plus:
  • Custom plugins
  • Business hour support
  • And more

Platinum

Advanced functionality with 24/7 support.

As low as

$22/month

Everything in Gold plus:
  • Advanced Elastic Stack security features
  • Machine learning
  • 24/7/365 support
  • And more

Enterprise

The fully loaded package with endpoint protection by default.

Contact us to find out more

Everything in Platinum plus:
  • Access to Elastic Endgame1

Elasticsearch Service Private

Want isolated hosts and a dedicated VPC? Our private tier gives you all the features in Enterprise, served from dedicated and isolated hosts and hosted in a separate VPC. Also includes support for direct VPC connectivity and multiple user accounts.

 

Standard

Gold

Platinum

Enterprise

Platform Services

Managed Elasticsearch and Kibana
Same day version availability
Instant access to security patches
Single-click deployment upgrades
In-place configuration change
Deployment templates
Hot-warm architecture, with automated index curation
Automated snapshots (configurable, default every 30 minutes)
REST API for deployment management
REST API support in ecctl CLI, Golang SDK, and generated SDKs
Providers: AWS, Azure, Google Cloud
FedRAMP authorized at Moderate Impact level on AWS GovCloud (US)2
High availability across zones
Console signup with Google Account
Multi-factor authentication
AWS Marketplace billing integration
Google Cloud Marketplace billing integration
AWS PrivateLink integration
IP filtering
SOC 2 and CSA Star 2 compliance
HIPAA BAA ready
ISO 27001/27017/27018

Elastic Stack Operation & Management

Storage types

Inverted index (for search)
Document store (for unstructured)
Columnar store (for analytics)
BKD trees (for numeric, dates, geo)
Flattened field type
Histogram field type
Shape field type
Vector field type
Wildcard field type
Frozen indices (for long-term storage)

Data management

Snapshot/restore APIs
Snapshot lifecycle management
Minimal snapshots
Data rollups
Data streams
Data transforms
Index management
Index lifecycle management

Stack management

Data import tutorials
Ingest Node Pipeline Builder UI
Grok Debugger
Upgrade Assistant
Centralized Beats management
Ingest Manager
Centralized Logstash pipeline management

Scalability & resiliency

Clustering and high availability
Automatic data rebalancing
Cross-cluster search
Voting only nodes
Dedicated master nodes
Dedicated coordinating nodes

Elastic Stack security

Secure settings
Data encryption at rest
Encrypted node-to-node communications
Role-based access control
Native authentication
Kibana Spaces
Kibana feature controls
API Keys management
Elasticsearch Token Service
Single sign-on (SAML, OpenID Connect, Kerberos)
Attribute-based access control
Field- and document-level security
Custom authentication and authorization realms

Stack monitoring

Full-stack monitoring (including Beats and Logstash)
Multi-stack monitoring
Configurable retention policy
Automatic stack issue alerts

Alerting

Watcher
Kibana alerts
Kibana actions: index and logging
Kibana actions: email, PagerDuty, ServiceNow®, Slack, webhooks
Atlassian Jira integration
ServiceNow ITSM integration

Clients

REST APIs
Language clients
Query DSL
Console
JDBC client
ODBC client
Tableau Connector

Localized UI

English
Chinese (Simplified)
Japanese

Custom plugins

Custom plugins

Search & Analysis

Full-text search

Relevance scoring
Highlighting
Type ahead
Corrections
Suggestions
Percolations
Async search
Results pinning
Query profiler
Dynamically updateable synonyms
Similarity functions for vector fields

Analytics

Aggregations
Boxplot aggregation
Cumulative cardinality aggregation
Moving percentiles aggregation
Normalize aggregation
String stats aggregation
Top metrics aggregation
T-test aggregation
Geoshape aggregations
Graph exploration

Query languages

Elasticsearch SQL APIs
Event Query Language (EQL)

Machine learning

File import wizard
Data Visualizer
Anomaly detection on time series
Outlier detection
Regression
Classification
Population/entity analysis
Log message categorization
Root cause indication
Alerting on anomalies
Forecasting on time series
Inference
Feature importance
Model snapshot management
Language identification

Data Ingest & Transformation

Ingest products & features

Filebeat, Metricbeat, Winlogbeat, Packetbeat, Heartbeat, Auditbeat
Functionbeat
Elastic Agent
Logstash
ES-Hadoop
File import wizard
Elastic Endgame1

Data sources

Operating systems
Web servers and proxies
Datastores and queues
Cloud services
Containers and orchestration
MQTT
Prometheus
ActiveMQ
ArcSight CEF
Audit system data
AWS (S3, EC2, ELB, Billing, CloudTrail, etc.)
Azure
CheckPoint Firewall
Cisco IOS/ASA and Firepower
CockroachDB
CoreDNS
Crowdstrike Falcon
Docker Logging Plugin
Envoy Proxy
Fortinet Fortigate
Google Cloud (Pub/Sub, VPC, etc.)
Google GSuite
IBM MQ
Iptables
Istio Service Mesh
Microsoft Defender ATP
Microsoft (Office) 365
Microsoft SQL Server
Microsoft Windows Security Events
MISP
NetFlow and IPFIX
Okta
Oracle Database
Palo Alto Firewalls
PowerShell
Pivotal Cloud Foundry (PCF)
Redis Enterprise
SophosXG
Suricata
Sysmon
Zeek (formerly Bro)

Data transformation

Index time enrichment
Processors
Analyzers
Tokenizers
Filters
Grok
Field transformation
External lookup enrichment
Circle ingest processor
Match and geo-match enrich processor

Elastic Common Schema

Elastic Common Schema

Data Exploration & Visualization

Visualizations

Time series
Geo
Metrics
Tables
Tag cloud
Custom (Vega)
Lens

Data exploration

Dashboards
Drilldown between dashboards
Discover
Console
Kibana query autocomplete
Graph analytics

Canvas

Canvas
Canvas shareables

Share & collaborate

Embeddable dashboards
Object export UI and APIs
CSV exports
PDF and PNG reports
Saved queries

Elastic Observability

Observability overview

Elastic APM3

Elastic APM

APM server
OpenTelemetry intake
APM app
Distributed tracing
Service maps

APM language support

Java
.NET
Go
Ruby
RUM (Javascript)
Python
Node

Stack integrations

Elastic Logs and Metrics
Kibana alerting and actions4
Machine learning

Elastic Logs

Log shipper (Filebeat)
Dashboards for common data sources
Logs app

Integrations

Elastic Uptime and APM
Kibana alerting and actions4
Log categorization
Machine learning

Elastic Metrics

Metric shipper (Metricbeat)
Dashboards for common data sources
Metrics app

Integrations

Elastic Logs, APM, Uptime
Kibana alerting and actions4

Elastic Uptime

Send data using Heartbeat
Uptime dashboards in Kibana
Uptime app

Integrations

Elastic Logs, Metrics, APM
Kibana alerting and actions4
Machine learning

Elastic Security

Elastic Common Schema
Security information and event management (SIEM)
Host security analysis
Network security analysis
Timeline event explorer
Case management
Detection engine
Prebuilt detection rules
Detection rule alerting
Machine learning anomaly detection
Prebuilt anomaly detection jobs
Malware prevention and data collection

Integrations

Elastic Endgame1
Elastic Agent
Elastic APM
Elastic Maps
Machine learning
Kibana alerting and actions4
Atlassian Jira
IBM Resilient
ServiceNow ITSM

Elastic Endgame1

Endgame Server

Role-based access control
LDAP authentication
Single sign-on (SAML 2.0)
Mutual authentication between the platform and endpoint
RESTful API
Policy-based management

Endgame Sensor

EPP and EDR on Windows, Linux, macOS
Security event collection and storage
Tamper resistant

Protect against

Malware, ransomware, phishing
Memory injection, software exploitation
Adversary, tactics, techniques, and behaviors
In-memory attacks
Customizable protection rules and automated responses

Response actions

Isolate hosts
Kill process
Suspend thread execution
Automated file quarantine
Delete, upload, execute files

Threat hunting

Artemis(TM) - AI-powered natural-language chat-bot
Search for IoCs and hunt using EQL
Audit system information, applications, file systems, and host firewall
Audit loaded drivers and removable media
Audit running processes, network events, registry hives, and discover persistence
Automated memory analysis
Outlier analysis

Event collection

File, Process, Network, DNS, Registry, Security, PowerShell, Windows Management Instrumentation, Common Language Runtime, Windows API
DLL and driver loads

Data exploration & visualizations

Visual attack analysis, enriched with context from MITRE ATT&CK
Alert dashboards
Operations dashboards
Customizable reporting

Integrations

Elastic Security
Logstash

Elastic Maps

Elastic Maps Service

Base layer maps
Raster tile zoom level
10
18
18
18
Vector tile zoom level
14
14
14

Maps app

GeoJSON upload
Multiple layers
Layer-based filtering
Client-side styling
Individual points and shapes
Geo aggregations
Embed maps in dashboard
Embed maps in Canvas
Display up to 24 zoom levels
Custom raster and vector tile service support

Elastic App Search

Elastic App Search

Index once, sort all you want
Customizable relevance model
Language-specific relevance
Analytics API
Clickthrough API
Index lifecycle management

Analytics

Searches
Clicks
Insights

Security & collaboration

Multi-user collaboration
Signed search keys
Engine scoping
Role-based access control
Engine-scoped API keys
SAML
Meta engines

Elastic Workplace Search

Unified organizational search experience

Workplace Search server
Unified search interface
Natural language query filtering
Search history
Typo-tolerant relevance model
Content source prioritization
Search API

Content sources

First-party cloud source synchronization
First-party on-premise source synchronization
Custom source support
Full-text content indexing for files, documents, and records
Document-level permission support
Private sources

User management & security

Organizational groups
Native user management
SAML user management
Role-based access control
Encrypted communications
Encryption at rest support

Support

Support coverage
Business hours
24/7/365
24/7/365
Response times
Critical: 4 hrs
L2: 1 day
L3: 2 days
Critical: 1 hr
L2: 4 hrs
L3: 1 day
Critical: 1 hr
L2: 4 hrs
L3: 1 day
Unlimited # of incidents
Support contacts
2
6
8
8
Ticket-based support
SLA-based support

Platform Services

Managed Elasticsearch and Kibana
Same day version availability
Instant access to security patches
Single-click deployment upgrades
In-place configuration change
Deployment templates
Hot-warm architecture, with automated index curation
Automated snapshots (configurable, default every 30 minutes)
REST API for deployment management
REST API support in ecctl CLI, Golang SDK, and generated SDKs
Providers: AWS, Azure, Google Cloud
FedRAMP authorized at Moderate Impact level on AWS GovCloud (US)2
High availability across zones
Console signup with Google Account
Multi-factor authentication
AWS Marketplace billing integration
Google Cloud Marketplace billing integration
AWS PrivateLink integration
IP filtering
SOC 2 and CSA Star 2 compliance
HIPAA BAA ready
ISO 27001/27017/27018

Elastic Stack Operation & Management

Storage types

Inverted index (for search)
Document store (for unstructured)
Columnar store (for analytics)
BKD trees (for numeric, dates, geo)
Flattened field type
Histogram field type
Shape field type
Vector field type
Wildcard field type
Frozen indices (for long-term storage)

Data management

Snapshot/restore APIs
Snapshot lifecycle management
Minimal snapshots
Data rollups
Data streams
Data transforms
Index management
Index lifecycle management

Stack management

Data import tutorials
Ingest Node Pipeline Builder UI
Grok Debugger
Upgrade Assistant
Centralized Beats management
Ingest Manager
Centralized Logstash pipeline management

Scalability & resiliency

Clustering and high availability
Automatic data rebalancing
Cross-cluster search
Voting only nodes
Dedicated master nodes
Dedicated coordinating nodes

Elastic Stack security

Secure settings
Data encryption at rest
Encrypted node-to-node communications
Role-based access control
Native authentication
Kibana Spaces
Kibana feature controls
API Keys management
Elasticsearch Token Service
Single sign-on (SAML, OpenID Connect, Kerberos)
Attribute-based access control
Field- and document-level security
Custom authentication and authorization realms

Stack monitoring

Full-stack monitoring (including Beats and Logstash)
Multi-stack monitoring
Configurable retention policy
Automatic stack issue alerts

Alerting

Watcher
Kibana alerts
Kibana actions: index and logging
Kibana actions: email, PagerDuty, ServiceNow®, Slack, webhooks
Atlassian Jira integration
ServiceNow ITSM integration

Clients

REST APIs
Language clients
Query DSL
Console
JDBC client
ODBC client
Tableau Connector

Localized UI

English
Chinese (Simplified)
Japanese

Custom plugins

Custom plugins

Search & Analysis

Full-text search

Relevance scoring
Highlighting
Type ahead
Corrections
Suggestions
Percolations
Async search
Results pinning
Query profiler
Dynamically updateable synonyms
Similarity functions for vector fields

Analytics

Aggregations
Boxplot aggregation
Cumulative cardinality aggregation
Moving percentiles aggregation
Normalize aggregation
String stats aggregation
Top metrics aggregation
T-test aggregation
Geoshape aggregations
Graph exploration

Query languages

Elasticsearch SQL APIs
Event Query Language (EQL)

Machine learning

File import wizard
Data Visualizer
Anomaly detection on time series
Outlier detection
Regression
Classification
Population/entity analysis
Log message categorization
Root cause indication
Alerting on anomalies
Forecasting on time series
Inference
Feature importance
Model snapshot management
Language identification

Data Ingest & Transformation

Ingest products & features

Filebeat, Metricbeat, Winlogbeat, Packetbeat, Heartbeat, Auditbeat
Functionbeat
Elastic Agent
Logstash
ES-Hadoop
File import wizard
Elastic Endgame1

Data sources

Operating systems
Web servers and proxies
Datastores and queues
Cloud services
Containers and orchestration
MQTT
Prometheus
ActiveMQ
ArcSight CEF
Audit system data
AWS (S3, EC2, ELB, Billing, CloudTrail, etc.)
Azure
CheckPoint Firewall
Cisco IOS/ASA and Firepower
CockroachDB
CoreDNS
Crowdstrike Falcon
Docker Logging Plugin
Envoy Proxy
Fortinet Fortigate
Google Cloud (Pub/Sub, VPC, etc.)
Google GSuite
IBM MQ
Iptables
Istio Service Mesh
Microsoft Defender ATP
Microsoft (Office) 365
Microsoft SQL Server
Microsoft Windows Security Events
MISP
NetFlow and IPFIX
Okta
Oracle Database
Palo Alto Firewalls
PowerShell
Pivotal Cloud Foundry (PCF)
Redis Enterprise
SophosXG
Suricata
Sysmon
Zeek (formerly Bro)

Data transformation

Index time enrichment
Processors
Analyzers
Tokenizers
Filters
Grok
Field transformation
External lookup enrichment
Circle ingest processor
Match and geo-match enrich processor

Elastic Common Schema

Elastic Common Schema

Data Exploration & Visualization

Visualizations

Time series
Geo
Metrics
Tables
Tag cloud
Custom (Vega)
Lens

Data exploration

Dashboards
Drilldown between dashboards
Discover
Console
Kibana query autocomplete
Graph analytics

Canvas

Canvas
Canvas shareables

Share & collaborate

Embeddable dashboards
Object export UI and APIs
CSV exports
PDF and PNG reports
Saved queries

Elastic Observability

Observability overview

Elastic APM3

Elastic APM

APM server
OpenTelemetry intake
APM app
Distributed tracing
Service maps

APM language support

Java
.NET
Go
Ruby
RUM (Javascript)
Python
Node

Stack integrations

Elastic Logs and Metrics
Kibana alerting and actions4
Machine learning

Elastic Logs

Log shipper (Filebeat)
Dashboards for common data sources
Logs app

Integrations

Elastic Uptime and APM
Kibana alerting and actions4
Log categorization
Machine learning

Elastic Metrics

Metric shipper (Metricbeat)
Dashboards for common data sources
Metrics app

Integrations

Elastic Logs, APM, Uptime
Kibana alerting and actions4

Elastic Uptime

Send data using Heartbeat
Uptime dashboards in Kibana
Uptime app

Integrations

Elastic Logs, Metrics, APM
Kibana alerting and actions4
Machine learning

Elastic Security

Elastic Common Schema
Security information and event management (SIEM)
Host security analysis
Network security analysis
Timeline event explorer
Case management
Detection engine
Prebuilt detection rules
Detection rule alerting
Machine learning anomaly detection
Prebuilt anomaly detection jobs
Malware prevention and data collection

Integrations

Elastic Endgame1
Elastic Agent
Elastic APM
Elastic Maps
Machine learning
Kibana alerting and actions4
Atlassian Jira
IBM Resilient
ServiceNow ITSM

Elastic Endgame1

Endgame Server

Role-based access control
LDAP authentication
Single sign-on (SAML 2.0)
Mutual authentication between the platform and endpoint
RESTful API
Policy-based management

Endgame Sensor

EPP and EDR on Windows, Linux, macOS
Security event collection and storage
Tamper resistant

Protect against

Malware, ransomware, phishing
Memory injection, software exploitation
Adversary, tactics, techniques, and behaviors
In-memory attacks
Customizable protection rules and automated responses

Response actions

Isolate hosts
Kill process
Suspend thread execution
Automated file quarantine
Delete, upload, execute files

Threat hunting

Artemis(TM) - AI-powered natural-language chat-bot
Search for IoCs and hunt using EQL
Audit system information, applications, file systems, and host firewall
Audit loaded drivers and removable media
Audit running processes, network events, registry hives, and discover persistence
Automated memory analysis
Outlier analysis

Event collection

File, Process, Network, DNS, Registry, Security, PowerShell, Windows Management Instrumentation, Common Language Runtime, Windows API
DLL and driver loads

Data exploration & visualizations

Visual attack analysis, enriched with context from MITRE ATT&CK
Alert dashboards
Operations dashboards
Customizable reporting

Integrations

Elastic Security
Logstash

Elastic Maps

Elastic Maps Service

Base layer maps
Raster tile zoom level
Vector tile zoom level

Maps app

GeoJSON upload
Multiple layers
Layer-based filtering
Client-side styling
Individual points and shapes
Geo aggregations
Embed maps in dashboard
Embed maps in Canvas
Display up to 24 zoom levels
Custom raster and vector tile service support

Elastic App Search

Elastic App Search

Index once, sort all you want
Customizable relevance model
Language-specific relevance
Analytics API
Clickthrough API
Index lifecycle management

Analytics

Searches
Clicks
Insights

Security & collaboration

Multi-user collaboration
Signed search keys
Engine scoping
Role-based access control
Engine-scoped API keys
SAML
Meta engines

Elastic Workplace Search

Unified organizational search experience

Workplace Search server
Unified search interface
Natural language query filtering
Search history
Typo-tolerant relevance model
Content source prioritization
Search API

Content sources

First-party cloud source synchronization
First-party on-premise source synchronization
Custom source support
Full-text content indexing for files, documents, and records
Document-level permission support
Private sources

User management & security

Organizational groups
Native user management
SAML user management
Role-based access control
Encrypted communications
Encryption at rest support

Support

Support coverage
Response times
Unlimited # of incidents
Support contacts
Ticket-based support
SLA-based support
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
10
18
18
18
14
14
14
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Business hours
24/7/365
24/7/365
Critical: 4 hrs
L2: 1 day
L3: 2 days
Critical: 1 hr
L2: 4 hrs
L3: 1 day
Critical: 1 hr
L2: 4 hrs
L3: 1 day
2
6
8
8

1 Elastic Endgame features in the Enterprise subscription require an annual commitment and are not available for the monthly plan.

2 Elastic Cloud subscriptions on AWS GovCloud (US) are only available annually at this time (not monthly).

3 Elastic APM is not supported on Elastic Cloud Standard when purchased through the AWS Marketplace.

4 Refer to the Alerting section (Kibana Alerting and Kibana Actions items) for further details.

Take managed Elasticsearch for a spin

Frequently asked questions