Elastic Stack subscriptions

The Elastic Stack — Elasticsearch, Kibana, Beats, and Logstash — powers a variety of use cases. And we have flexible plans to help you get the most out of your on-prem subscriptions.

Our resource-based pricing philosophy is simple: You only pay for the data you use, at any scale, for every use case.

free

Open Source

Apache 2.0: Now and always.

Feature highlights include:
  • Clustering & high availability
  • Powerful search and analysis
  • Data visualization and dashboarding
  • And more

Basic

The forever-free plan.

Everything in Open Source plus:
  • Core Elastic Stack security features
  • Capabilities such as Elastic APM, SIEM, App Search, and Maps
  • Canvas & Lens
  • Kibana alerting and in-stack actions***
  • And more

Gold

More features. Dedicated support.

Everything in Basic plus:
  • Reporting
  • Kibana third-party alerting actions***
  • Watcher
  • Ingest management
  • Business hours support
  • And more

Platinum

Advanced functionality. Around the clock support.

Everything in Gold plus:
  • Advanced Elastic Stack security features
  • Machine learning
  • Workplace Search
  • Cross-cluster replication
  • 24/7/365 support
  • And more

Enterprise

Stack orchestration and endpoint protection by default.

Everything in Platinum plus:
  • Endpoint prevention
  • Endpoint detection and response mapped to MITRE ATT&CK
  • Endpoint event collection
  • Access to ECE & ECK orchestration features
 

Open Source

Basic

Gold

Platinum

Enterprise

Elastic Stack Operations & Management

Storage types

Inverted index (for search)
Document store (for unstructured)
Columnar store (for analytics)
BKD trees (for numeric, dates, & geo)
Flattened field type
Shape field type
Vector field type
Histogram field type
Frozen indices (for long term storage)

Data management

Snapshot/restore
Minimal snapshots
Snapshot lifecycle management
Data rollups
Data transforms
Index management
Index lifecycle management

Stack management

Data import tutorials
Ingest Node Pipeline Builder UI
Grok Debugger
Upgrade Assistant
License management
Centralized Beats management
Ingest Manager
Centralized Logstash pipeline management

Scalability & resiliency

Clustering & high availability
Automatic data rebalancing
Cross-cluster search
Voting-only master nodes
Cross-cluster replication*

Elastic Stack security

Secure settings
Encrypted communications
Role-based access control
File and native authentication
Kibana Spaces
Kibana feature controls
API keys management
Audit logging
IP filtering
LDAP, PKI*, Active Directory authentication
Elasticsearch Token Service
Single sign-on (SAML, OpenID Connect, Kerberos)
Attribute-based access control
Field- and document-level security
Custom authentication & authorization realms
Encryption at rest support
FIPS 140-2 mode

Stack monitoring

Full stack monitoring
Multi-stack monitoring
Configurable retention policy
Automatic stack issue alerts

Alerting

Watcher
Kibana Alerts
Kibana Actions - Index & Logging
Kibana Actions - email, PagerDuty, Slack, webhooks
Atlassian Jira integration
ServiceNow® ITSM integration

Clients

REST APIs
Language clients
Query DSL
Console
ES-Hadoop
Elasticsearch SQL APIs & CLI
JDBC Client
ODBC Client

Localized UI

English
Chinese (Simplified)
Japanese

Search & Analysis

Full-text search

Relevance scoring
Highlighting
Type ahead
Corrections
Suggestions
Percolations
Async search
Results pinning
Dynamically updateable synonyms
Query profiler
Similarity functions for vector fields

Analytics

Aggregations
Cumulative cardinality aggregation
String stats aggregation
Top metrics aggregation
Boxplot aggregation
T-test aggregation
Geoshape aggregations
Graph exploration

Machine learning

Data Visualizer
Anomaly detection on time series
Outlier detection
Classification
Population/entity analysis
Log message categorization
Root cause indication
Alerting on anomalies
Forecasting on time series
Inference
Feature importance
Language identification

Data Ingest & Transformation

Ingest products & features

Filebeat, Metricbeat, Winlogbeat, Packetbeat, Heartbeat, Auditbeat
Functionbeat
Elastic Agent
Logstash
ES-Hadoop
File import wizard
Elastic Endpoint Security**

Data sources

Operating systems
Web servers and proxies
Datastores and queues
Cloud services
Containers and orchestration
MQTT
Prometheus
ActiveMQ
ArcSight CEF
Audit system data
AWS (S3, EC2, ELB, Billing, CloudTrail, etc.)
Azure
Check Point Firewall (CEF)
Cisco ASA & Firepower
CockroachDB
CoreDNS
Docker Logging Plugin
Envoy Proxy
Google Cloud (Pub/Sub, VPC, etc.)
IBM MQ
Iptables
Istio Service Mesh
Microsoft (Office) 365
Microsoft SQL Server
MISP
NetFlow & IPFIX
Okta
Oracle Database
Palo Alto PAN-OS
Pivotal Cloud Foundry (PCF)
Redis Enterprise
Suricata
Zeek (formerly Bro)

Data transformation

Index time enrichment
Processors
Analyzers
Tokenizers
Filters
Grok
Field transformation
External lookup enrichment
Circle ingest processor
Match & Geo-match enrich processor

Elastic Common Schema

Elastic Common Schema

Data Exploration & Visualization

Visualizations

Time series
Geo
Metrics
Tables
Tag cloud
Custom (Vega)
Lens

Data exploration

Dashboards
Drilldown between dashboards
Discover
Console
Kibana query autocomplete
Graph analytics

Canvas

Canvas
Canvas shareables

Share & collaborate

Embeddable dashboards
Object export UI & APIs
CSV exports
PDF and PNG reports
Saved queries

Elastic APM

APM Server
Jaeger intake
APM app
Distributed tracing
Service maps

APM agents

Java
.NET
Go
Ruby
RUM (Javascript)
Python
Node

Integrations

Elastic Logs, Metrics
Kibana alerting and actions***
Machine learning

Elastic Logs

Log shipper (Filebeat)
Dashboards for common data sources
Logs app

Integrations

Elastic Uptime, APM
Kibana alerting and actions***
Log categorization
Machine learning

Elastic Metrics

Metric shipper (Metricbeat)
Dashboards for common data sources
Metrics app

Integrations

Elastic Logs, APM, Uptime
Kibana alerting and actions***

Elastic Uptime

Uptime monitor (Heartbeat)
Uptime dashboards in Kibana
Uptime app

Integrations

Elastic Logs, Metrics, APM
Kibana alerting and actions***
Machine learning

Elastic SIEM

Elastic Common Schema
Host security analysis
Network security analysis
Timeline event explorer
SIEM detection engine
Prebuilt detection rules
Case management
Detection rule alerting
Prebuilt anomaly detection jobs

Integrations

Elastic APM
Elastic Maps
Kibana alerting and actions***
Atlassian Jira
ServiceNow ITSM
Machine learning
Elastic Endpoint Security

Elastic Endpoint Security**

Endgame Platform

Role-based access control
LDAP authentication
Single sign-on (SAML 2.0)
Mutual authentication between the platform and endpoint
RESTful API
Policy-based management

Elastic Endpoint

EPP and EDR on Windows, Linux, macOS
Security event collection and storage
Tamper resistant

Protect against

Malware, ransomware, phishing
Memory injection, software exploitation
Adversary, tactics, techniques, and behaviors
In-memory attacks
Unwanted behaviors with customizable protection rules and automated responses

Response actions

Isolate hosts
Kill process
Suspend thread execution
Automated file quarantine
Delete, upload, execute files

Threat hunting

Artemis™ - AI-powered natural-language chat-bot
Search for IoCs and hunt using EQL
Audit system information, applications, file systems, and host firewall
Audit loaded drivers and removable media
Audit running processes, network events, registry hives and discover persistence
Automated memory analysis
Outlier analysis

Event collection

File, Process, Network, DNS, Registry, Security, PowerShell, Windows Management Instrumentation, Common Language Runtime, Windows API
DLL and driver loads

Data exploration and visualizations

Visual attack analysis, enriched with context from MITRE ATT&CK
Alert dashboards
Operations dashboards
Customizable reporting

Integrations

Elastic SIEM
Logstash

Elastic Maps

Elastic Maps Service

Base layer maps
Raster tile zoom level
10
18
18
18
18
Vector tile zoom level for Maps
14
14
14
14

Maps app

GeoJSON upload
Multiple layers
Layer-based filtering
Client-side styling
Individual points and shapes
Geo aggregations
Embed Maps in dashboard
Embed Maps in Canvas
Display up to 24 zoom levels

Elastic App Search

App Search Server
App Search UI
Search result curation
Search analytics
Custom synonyms
Language-specific relevance
Typo-tolerant relevance model
Relevance model tuning
Meta engines

Security

Encrypted communications
Role-based access control
Single sign-on (SAML)
Encryption at rest support

Elastic Workplace Search****

Unified organizational search experience

Workplace Search server
Unified search interface
Search API
Natural language query filtering
Search history and query suggestions
Typo-tolerant relevance model
Content source prioritization

Content sources

First-party cloud source synchronization
First-party on-premise source synchronization
Custom source support
Document-level permission support
Full-text content indexing for files, documents, and records
Private sources

User management & security

Organizational groups
Native user management
SAML user management
Role-based access control
Encrypted communications
Encryption at rest support

Orchestration

Elastic Cloud Enterprise

Deploy anywhere: bare metal, VMs, private or public cloud
Centrally provision, manage, and monitor multiple clusters
Resource tagging, and tag-based deployment configuration
Online same-day version updates
Single-click upgrades & scaling
User and role management
Automated periodic snapshots
Optimized resource utilization
Container-based resource isolation

Elastic Cloud on Kubernetes**

Deploy Elasticsearch, Kibana, and APM Server on Kubernetes
Provision, manage, and monitor multiple clusters
Default Elastic Stack security and authentication for every deployment
Support for hot-warm-cold architectures
Configure backups using snapshots

Support

Support coverage
Business hrs
24/7/365
24/7/365
Response times
Critical: 4 hrs
L2: 1 day
L3: 2 days
Critical: 1 hr
L2: 4 hrs
L3: 1 day
Critical: 1 hr
L2: 4 hrs
L3: 1 day
Unlimited # of incidents
Unlimited # of projects
Support contacts
6
8
8
Web and phone support
Emergency patches

Elastic Stack Operations & Management

Storage types

Inverted index (for search)
Document store (for unstructured)
Columnar store (for analytics)
BKD trees (for numeric, dates, & geo)
Flattened field type
Shape field type
Vector field type
Histogram field type
Frozen indices (for long term storage)

Data management

Snapshot/restore
Minimal snapshots
Snapshot lifecycle management
Data rollups
Data transforms
Index management
Index lifecycle management

Stack management

Data import tutorials
Ingest Node Pipeline Builder UI
Grok Debugger
Upgrade Assistant
License management
Centralized Beats management
Ingest Manager
Centralized Logstash pipeline management

Scalability & resiliency

Clustering & high availability
Automatic data rebalancing
Cross-cluster search
Voting-only master nodes
Cross-cluster replication*

Elastic Stack security

Secure settings
Encrypted communications
Role-based access control
File and native authentication
Kibana Spaces
Kibana feature controls
API keys management
Audit logging
IP filtering
LDAP, PKI*, Active Directory authentication
Elasticsearch Token Service
Single sign-on (SAML, OpenID Connect, Kerberos)
Attribute-based access control
Field- and document-level security
Custom authentication & authorization realms
Encryption at rest support
FIPS 140-2 mode

Stack monitoring

Full stack monitoring
Multi-stack monitoring
Configurable retention policy
Automatic stack issue alerts

Alerting

Watcher
Kibana Alerts
Kibana Actions - Index & Logging
Kibana Actions - email, PagerDuty, Slack, webhooks
Atlassian Jira integration
ServiceNow® ITSM integration

Clients

REST APIs
Language clients
Query DSL
Console
ES-Hadoop
Elasticsearch SQL APIs & CLI
JDBC Client
ODBC Client

Localized UI

English
Chinese (Simplified)
Japanese

Search & Analysis

Full-text search

Relevance scoring
Highlighting
Type ahead
Corrections
Suggestions
Percolations
Async search
Results pinning
Dynamically updateable synonyms
Query profiler
Similarity functions for vector fields

Analytics

Aggregations
Cumulative cardinality aggregation
String stats aggregation
Top metrics aggregation
Boxplot aggregation
T-test aggregation
Geoshape aggregations
Graph exploration

Machine learning

Data Visualizer
Anomaly detection on time series
Outlier detection
Classification
Population/entity analysis
Log message categorization
Root cause indication
Alerting on anomalies
Forecasting on time series
Inference
Feature importance
Language identification

Data Ingest & Transformation

Ingest products & features

Filebeat, Metricbeat, Winlogbeat, Packetbeat, Heartbeat, Auditbeat
Functionbeat
Elastic Agent
Logstash
ES-Hadoop
File import wizard
Elastic Endpoint Security**

Data sources

Operating systems
Web servers and proxies
Datastores and queues
Cloud services
Containers and orchestration
MQTT
Prometheus
ActiveMQ
ArcSight CEF
Audit system data
AWS (S3, EC2, ELB, Billing, CloudTrail, etc.)
Azure
Check Point Firewall (CEF)
Cisco ASA & Firepower
CockroachDB
CoreDNS
Docker Logging Plugin
Envoy Proxy
Google Cloud (Pub/Sub, VPC, etc.)
IBM MQ
Iptables
Istio Service Mesh
Microsoft (Office) 365
Microsoft SQL Server
MISP
NetFlow & IPFIX
Okta
Oracle Database
Palo Alto PAN-OS
Pivotal Cloud Foundry (PCF)
Redis Enterprise
Suricata
Zeek (formerly Bro)

Data transformation

Index time enrichment
Processors
Analyzers
Tokenizers
Filters
Grok
Field transformation
External lookup enrichment
Circle ingest processor
Match & Geo-match enrich processor

Elastic Common Schema

Elastic Common Schema

Data Exploration & Visualization

Visualizations

Time series
Geo
Metrics
Tables
Tag cloud
Custom (Vega)
Lens

Data exploration

Dashboards
Drilldown between dashboards
Discover
Console
Kibana query autocomplete
Graph analytics

Canvas

Canvas
Canvas shareables

Share & collaborate

Embeddable dashboards
Object export UI & APIs
CSV exports
PDF and PNG reports
Saved queries

Elastic APM

APM Server
Jaeger intake
APM app
Distributed tracing
Service maps

APM agents

Java
.NET
Go
Ruby
RUM (Javascript)
Python
Node

Integrations

Elastic Logs, Metrics
Kibana alerting and actions***
Machine learning

Elastic Logs

Log shipper (Filebeat)
Dashboards for common data sources
Logs app

Integrations

Elastic Uptime, APM
Kibana alerting and actions***
Log categorization
Machine learning

Elastic Metrics

Metric shipper (Metricbeat)
Dashboards for common data sources
Metrics app

Integrations

Elastic Logs, APM, Uptime
Kibana alerting and actions***

Elastic Uptime

Uptime monitor (Heartbeat)
Uptime dashboards in Kibana
Uptime app

Integrations

Elastic Logs, Metrics, APM
Kibana alerting and actions***
Machine learning

Elastic SIEM

Elastic Common Schema
Host security analysis
Network security analysis
Timeline event explorer
SIEM detection engine
Prebuilt detection rules
Case management
Detection rule alerting
Prebuilt anomaly detection jobs

Integrations

Elastic APM
Elastic Maps
Kibana alerting and actions***
Atlassian Jira
ServiceNow ITSM
Machine learning
Elastic Endpoint Security

Elastic Endpoint Security**

Endgame Platform

Role-based access control
LDAP authentication
Single sign-on (SAML 2.0)
Mutual authentication between the platform and endpoint
RESTful API
Policy-based management

Elastic Endpoint

EPP and EDR on Windows, Linux, macOS
Security event collection and storage
Tamper resistant

Protect against

Malware, ransomware, phishing
Memory injection, software exploitation
Adversary, tactics, techniques, and behaviors
In-memory attacks
Unwanted behaviors with customizable protection rules and automated responses

Response actions

Isolate hosts
Kill process
Suspend thread execution
Automated file quarantine
Delete, upload, execute files

Threat hunting

Artemis™ - AI-powered natural-language chat-bot
Search for IoCs and hunt using EQL
Audit system information, applications, file systems, and host firewall
Audit loaded drivers and removable media
Audit running processes, network events, registry hives and discover persistence
Automated memory analysis
Outlier analysis

Event collection

File, Process, Network, DNS, Registry, Security, PowerShell, Windows Management Instrumentation, Common Language Runtime, Windows API
DLL and driver loads

Data exploration and visualizations

Visual attack analysis, enriched with context from MITRE ATT&CK
Alert dashboards
Operations dashboards
Customizable reporting

Integrations

Elastic SIEM
Logstash

Elastic Maps

Elastic Maps Service

Base layer maps
Raster tile zoom level
Vector tile zoom level for Maps

Maps app

GeoJSON upload
Multiple layers
Layer-based filtering
Client-side styling
Individual points and shapes
Geo aggregations
Embed Maps in dashboard
Embed Maps in Canvas
Display up to 24 zoom levels

Elastic App Search

App Search Server
App Search UI
Search result curation
Search analytics
Custom synonyms
Language-specific relevance
Typo-tolerant relevance model
Relevance model tuning
Meta engines

Security

Encrypted communications
Role-based access control
Single sign-on (SAML)
Encryption at rest support

Elastic Workplace Search****

Unified organizational search experience

Workplace Search server
Unified search interface
Search API
Natural language query filtering
Search history and query suggestions
Typo-tolerant relevance model
Content source prioritization

Content sources

First-party cloud source synchronization
First-party on-premise source synchronization
Custom source support
Document-level permission support
Full-text content indexing for files, documents, and records
Private sources

User management & security

Organizational groups
Native user management
SAML user management
Role-based access control
Encrypted communications
Encryption at rest support

Orchestration

Elastic Cloud Enterprise

Deploy anywhere: bare metal, VMs, private or public cloud
Centrally provision, manage, and monitor multiple clusters
Resource tagging, and tag-based deployment configuration
Online same-day version updates
Single-click upgrades & scaling
User and role management
Automated periodic snapshots
Optimized resource utilization
Container-based resource isolation

Elastic Cloud on Kubernetes**

Deploy Elasticsearch, Kibana, and APM Server on Kubernetes
Provision, manage, and monitor multiple clusters
Default Elastic Stack security and authentication for every deployment
Support for hot-warm-cold architectures
Configure backups using snapshots

Support

Support coverage
Response times
Unlimited # of incidents
Unlimited # of projects
Support contacts
Web and phone support
Emergency patches
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
10
18
18
18
18
14
14
14
14
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Business hrs
24/7/365
24/7/365
Critical: 4 hrs
L2: 1 day
L3: 2 days
Critical: 1 hr
L2: 4 hrs
L3: 1 day
Critical: 1 hr
L2: 4 hrs
L3: 1 day
6
8
8

* Feature is currently not available in deployments on Elastic Cloud Enterprise.

** Customers whose Enterprise subscriptions use ECE/ECE Instances as the billing metric must agree to additional terms before they can access the Enterprise-level features listed in this section. Please contact us.

*** Refer to the Alerting section (Kibana Alerting and Kibana Actions items) for further details.

**** Elastic Workplace Search will include a free version in an upcoming release.

The list above reflects the features available in the latest version of the Elastic Stack. Any features or functions of services or products referenced on this page or other pages, or in any presentations, press releases or public statements, which are not currently available or not currently available as a GA release, may not be delivered on time or at all. The development, release, and timing of any features or functionality described for our products remains at our sole discretion. Customers who purchase our products and services should make the purchase decisions based upon services and product features and functions that are currently available.

We're with you every step of the way: from starting up to development to production.

We know what it's like to start small and launch something big. Have access to our products, features, and support right from the beginning from project conception to production.

Want to learn more?
We love a good query.

Get details. Request a quote. Explore your options. Anything you like, really.

MarketoFEForm

Supported platforms