Elastic Stack subscriptions

The Elastic Stack — Elasticsearch, Kibana, Beats, and Logstash — powers a variety of use cases. And we have flexible plans to help you get the most out of your on-prem subscriptions.

Our resource-based pricing philosophy is simple: You only pay for the data you use, at any scale, for every use case.

 
Free and open - Basic 1, 2
Gold
Plati­num
Enter­prise

Elastic Stack Operations & Management

Storage types

Inverted index (for search)
Evaluating calculated fields at index time
Runtime fields
Document store (for unstructured)
Columnar store (for analytics)
BKD trees (for numeric, dates, & geo)
Flattened field type
Histogram field type
Match only text field type
Shape field type
Vector field type
Version field type
Wildcard field type
Frozen indices (for long term storage)

Data management

Searchable snapshots
Snapshot/restore
Minimal snapshots
Snapshot lifecycle management
Data rollups
Data streams
Data tiers
Data transforms
Index management
Index lifecycle management

Stack management

Data import tutorials
Ingest Node Pipeline Builder UI
Grok Debugger
Upgrade Assistant
License management
Centralized Logstash pipeline management

Scalability & resiliency

Clustering & high availability
Automatic data rebalancing
Cross-cluster search
Voting-only master nodes
Cross-cluster replication

Elastic Stack security

Secure settings
Encrypted communications
Role-based access control
Anonymous access control (public sharing)
File and native authentication
Kibana Spaces
Kibana feature controls
Kibana sub-feature privileges8
Prelogin access agreement
API keys management
Elasticsearch audit logging
Kibana audit logging
IP filtering
LDAP, PKI3, Active Directory authentication
Elasticsearch Token Service
Single sign-on (SAML, OpenID Connect, Kerberos)
Attribute-based access control
Field- and document-level security
Custom authentication & authorization realms
Encryption at rest support
FIPS 140-2 mode

Stack monitoring

Full stack monitoring
Multi-stack monitoring
Configurable retention policy
Kibana alerting and actions5

Alerting

Kibana Alerts
Kibana Alerts: tracking containment (geofencing)
Kibana Alerts: Anomaly detection alert (machine learning)
Kibana Actions: Index and Logging
Kibana Actions: email, webhooks, Jira, Microsoft Teams, PagerDuty, Slack, Swimlane
Kibana Actions: IBM Resilient, ServiceNow® ITSM
Watcher

Clients

REST APIs
Language clients
Query DSL
Console
ES-Hadoop
JDBC Client
ODBC Client
Tableau Connector

Localized UI

English
Chinese (Simplified)
Japanese

Search & Analysis

Full-text search

Relevance scoring
Highlighting
Type ahead
Corrections
Suggestions
Percolations
Async search
Results pinning
Dynamically updateable synonyms
Query profiler
Similarity functions for vector fields

Analytics

Aggregations
Boxplot aggregation
Cumulative cardinality aggregation
Geoline aggregation
Geoshape aggregations
Moving percentiles aggregation
Multi terms aggregation
Normalize aggregation
Range aggregation over histogram fields
Rate aggregation
Significant terms aggregation p-value score
String stats aggregation
Top metrics aggregation
T-test aggregation
Graph exploration

Query languages

Elasticsearch SQL APIs & CLI
Event Query Language (EQL)

Machine learning

Data Visualizer
Anomaly detection on time series
Outlier detection
Regression
Classification
Population/entity analysis
Log message categorization
Root cause indication
Alerting on anomalies
Forecasting on time series
Inference
Feature importance
Model snapshot management
Language identification

Data Ingest & Transformation

Ingest products & features

Filebeat, Metricbeat, Winlogbeat, Packetbeat, Heartbeat, Auditbeat
Functionbeat
Real browser-based synthetic monitoring agent
Logstash
ES-Hadoop
File import wizard

Fleet

Fleet Server
Fleet app
Fleet integrations
Elastic Agent
Selective agent binary updates
Selective agent policy reassignment
Selective agent unenrollment

Data sources

Cloud services
Containers and orchestration
Operating systems
Web servers and proxies
Datastores and queues
MQTT
Prometheus
Abuse.ch
ActiveMQ
AlienVault Open Threat Exchange (OTX)
Anomali Limo & ThreatStream
ArcSight (as CEF)
Audit system data
AWS (S3, EC2, ELB, Billing, CloudTrail, etc.)
Azure
Carbon Black EDR
Check Point Firewall
Cisco AMP, IOS/ASA, Firepower & Umbrella
Cloudflare
CockroachDB
Common Event Format (CEF)
CoreDNS
CrowdStrike Falcon
Cyberark Privileged Access Security
Docker Logging Plugin
Envoy Proxy
Fortinet Fortigate
Google Cloud (Pub/Sub, VPC, etc.)
Google Workspace
Hashicorp Vault
IBM MQ
Iptables
Istio Service Mesh
Juniper SRX
Microsoft 365 Defender & Defender for Endpoint
Microsoft (Office) 365
Microsoft SQL Server
Microsoft Windows Security Events
MISP
MySQL Enterprise Audit Logs
NetFlow & IPFIX
Okta
Oracle Database
Osquery Log Collection
Palo Alto Networks Cortex XDR
Palo Alto Networks Firewalls
Pensando
PowerShell
Pivotal Cloud Foundry (PCF)
Recorded Future
Redis Enterprise
Session initiation protocol (SIP)
SIEM connector (legacy)
Snyk
Sophos XG
Suricata
Sysmon
ThreatQuotient
Zeek (formerly Bro)
Zoom

Data transformation

Index time enrichment
Processors
Analyzers
Tokenizers
Filters
Grok
Field transformation
External lookup enrichment
Circle ingest processor
Match & Geo-match enrich processor

Elastic Common Schema

Elastic Common Schema

Data Exploration & Visualization

Visualizations

Time series
Geo
Metrics
Tables
Tag cloud
Custom (Vega)
Lens

Data exploration

Dashboards
Drilldown between dashboards
Drilldown to URL
Discover
Console
Kibana query autocomplete
Kibana runtime fields editor
Run search sessions in background
Graph analytics

Canvas

Canvas
Canvas shareables

Share & collaborate

Embeddable dashboards
Anonymous access control (public sharing)
CSV exports
PDF and PNG reports
Saved queries

Content management

Kibana Spaces
Custom banners
Object export UI & APIs
Tags
Navigational search

Elastic Observability

Observability overview
User Experience overview

Elastic APM

APM Server
Jaeger intake
OpenTelemetry intake for traces and metrics
APM app
Distributed tracing
Service maps
Correlations

APM agents

Java
.NET
Go
Ruby
RUM (JavaScript)
PHP
Python
Node

Integrations

Elastic Logs, Metrics
Kibana alerting and actions5
Machine learning

Elastic Logs

Log shipper (Filebeat)
Dashboards for common data sources
Logs app

Integrations

Elastic Uptime, APM
Kibana alerting and actions5
Log categorization
Machine learning

Elastic Metrics

Metric shipper (Metricbeat)
Dashboards for common data sources
Metrics app

Integrations

Elastic Logs, APM, Uptime
Kibana alerting and actions5
Machine learning

Elastic Uptime

Uptime monitor (Heartbeat)
Uptime dashboards in Kibana
Uptime app

Integrations

Elastic Logs, Metrics, APM
Kibana alerting and actions5
Machine learning

Elastic Security

Elastic Common Schema
Extended detection and response (XDR)
Security information and event management (SIEM)
Host security analysis
Network security analysis
Timeline event explorer
Case management
Detection engine (e.g., correlation, indicator match, threshold)
Prebuilt detection rules
Detection rule external actions
Machine learning anomaly detection
Prebuilt anomaly detection jobs
Malware prevention
Ransomware prevention
Malicious behavior protection
Host memory protection
Host isolation remote response
Customizable on-endpoint protection notifications

Integrations

Elastic Agent
Native host-based response
Elastic APM
Elastic Maps
Kibana Alerts and Actions5
Osquery Manager
Threat intelligence feeds and platforms
Atlassian Jira
Swimlane SOAR
IBM Resilient
ServiceNow ITSM and SIR
Machine learning

Elastic Maps

Elastic Maps Service6

Base layer maps
Elastic Maps Server

Maps app

GeoJSON upload
Multiple layers
Layer-based filtering
Client-side styling
Individual points and shapes
Geo aggregations
Embed Maps in dashboard
Embed Maps in Canvas
Tracking alerts
Containment alerts
Geo-threshold alerts
Display up to 24 zoom levels
Custom raster and vector tile service support
Kibana Alerts: tracking containment (geofencing)

Elastic App Search

App Search Server
App Search UI
Search result curation
Search analytics
Synonyms management
Language-specific relevance
Typo-tolerant relevance model
Relevance model tuning
Index lifecycle management
Meta engines
Web crawler
Precision tuning (beta)

Clients

Python
Ruby

Security

Encrypted communications
Role-based access control
Single sign-on (SAML)
Encryption at rest support

Elastic Workplace Search

Unified organizational search experience

Workplace Search server
Unified search interface
Out-of-the-box search applications
Customizable look and feel
Natural language query filtering
Search history
Typo-tolerant relevance model
Synonyms management
Customizable filtering and faceting
Content source prioritization
Search analytics
Search API

Clients

Python
Ruby

Content sources

First-party cloud source synchronization
First-party on-premise source synchronization
Custom source support
Full-text content indexing for files, documents, and records
Document-level permission support
Global sync scheduling configuration
Source-level scheduling configuration
Sync scheduling API
Object synchronization selection
Path-based content synchronization
File extension-based content synchronization
Private sources

User management & security

Organizational groups
Native user management
SAML user management
Role-based access control
Encrypted communications
Encryption at rest support

Orchestration

Elastic Cloud Enterprise

Deploy anywhere: bare metal, VMs, private or public cloud
Centrally provision, manage, and monitor multiple clusters
Resource tagging, and tag-based deployment configuration
Online same-day version updates
Single-click upgrades & scaling
User and role management
Automated periodic snapshots
Optimized resource utilization
Container-based resource isolation
Cross-cluster search and replication across ECE installations
Deployment autoscaling

Elastic Cloud on Kubernetes4

Deploy Elasticsearch, Kibana, and APM Server, Beats, Enterprise tier, and Elastic Agent on Kubernetes
Deploy Enterprise Search and Elastic Maps Server on Kubernetes
Provision, manage, and monitor multiple clusters
Default Elastic Stack security and authentication for every deployment
Single command upgrades and scaling
Cross-cluster replication and search within or outside of a Kubernetes cluster
Autoscaling Elasticsearch and Machine learning nodes

Support

Support coverage
Business hrs
24/7/365
24/7/365
Response times
Critical: 4 hrs
L2: 1 day
L3: 2 days
Critical: 1 hr
L2: 4 hrs
L3: 1 day
Critical: 1 hr
L2: 4 hrs
L3: 1 day
Unlimited # of incidents
Unlimited # of projects
Support contacts7
6
8
8
Web and phone support
Emergency patches

Elastic Stack Operations & Management

Storage types

Inverted index (for search)
Evaluating calculated fields at index time
Runtime fields
Document store (for unstructured)
Columnar store (for analytics)
BKD trees (for numeric, dates, & geo)
Flattened field type
Histogram field type
Match only text field type
Shape field type
Vector field type
Version field type
Wildcard field type
Frozen indices (for long term storage)

Data management

Searchable snapshots
Snapshot/restore
Minimal snapshots
Snapshot lifecycle management
Data rollups
Data streams
Data tiers
Data transforms
Index management
Index lifecycle management

Stack management

Data import tutorials
Ingest Node Pipeline Builder UI
Grok Debugger
Upgrade Assistant
License management
Centralized Logstash pipeline management

Scalability & resiliency

Clustering & high availability
Automatic data rebalancing
Cross-cluster search
Voting-only master nodes
Cross-cluster replication

Elastic Stack security

Secure settings
Encrypted communications
Role-based access control
Anonymous access control (public sharing)
File and native authentication
Kibana Spaces
Kibana feature controls
Kibana sub-feature privileges8
Prelogin access agreement
API keys management
Elasticsearch audit logging
Kibana audit logging
IP filtering
LDAP, PKI3, Active Directory authentication
Elasticsearch Token Service
Single sign-on (SAML, OpenID Connect, Kerberos)
Attribute-based access control
Field- and document-level security
Custom authentication & authorization realms
Encryption at rest support
FIPS 140-2 mode

Stack monitoring

Full stack monitoring
Multi-stack monitoring
Configurable retention policy
Kibana alerting and actions5

Alerting

Kibana Alerts
Kibana Alerts: tracking containment (geofencing)
Kibana Alerts: Anomaly detection alert (machine learning)
Kibana Actions: Index and Logging
Kibana Actions: email, webhooks, Jira, Microsoft Teams, PagerDuty, Slack, Swimlane
Kibana Actions: IBM Resilient, ServiceNow® ITSM
Watcher

Clients

REST APIs
Language clients
Query DSL
Console
ES-Hadoop
JDBC Client
ODBC Client
Tableau Connector

Localized UI

English
Chinese (Simplified)
Japanese

Search & Analysis

Full-text search

Relevance scoring
Highlighting
Type ahead
Corrections
Suggestions
Percolations
Async search
Results pinning
Dynamically updateable synonyms
Query profiler
Similarity functions for vector fields

Analytics

Aggregations
Boxplot aggregation
Cumulative cardinality aggregation
Geoline aggregation
Geoshape aggregations
Moving percentiles aggregation
Multi terms aggregation
Normalize aggregation
Range aggregation over histogram fields
Rate aggregation
Significant terms aggregation p-value score
String stats aggregation
Top metrics aggregation
T-test aggregation
Graph exploration

Query languages

Elasticsearch SQL APIs & CLI
Event Query Language (EQL)

Machine learning

Data Visualizer
Anomaly detection on time series
Outlier detection
Regression
Classification
Population/entity analysis
Log message categorization
Root cause indication
Alerting on anomalies
Forecasting on time series
Inference
Feature importance
Model snapshot management
Language identification

Data Ingest & Transformation

Ingest products & features

Filebeat, Metricbeat, Winlogbeat, Packetbeat, Heartbeat, Auditbeat
Functionbeat
Real browser-based synthetic monitoring agent
Logstash
ES-Hadoop
File import wizard

Fleet

Fleet Server
Fleet app
Fleet integrations
Elastic Agent
Selective agent binary updates
Selective agent policy reassignment
Selective agent unenrollment

Data sources

Cloud services
Containers and orchestration
Operating systems
Web servers and proxies
Datastores and queues
MQTT
Prometheus
Abuse.ch
ActiveMQ
AlienVault Open Threat Exchange (OTX)
Anomali Limo & ThreatStream
ArcSight (as CEF)
Audit system data
AWS (S3, EC2, ELB, Billing, CloudTrail, etc.)
Azure
Carbon Black EDR
Check Point Firewall
Cisco AMP, IOS/ASA, Firepower & Umbrella
Cloudflare
CockroachDB
Common Event Format (CEF)
CoreDNS
CrowdStrike Falcon
Cyberark Privileged Access Security
Docker Logging Plugin
Envoy Proxy
Fortinet Fortigate
Google Cloud (Pub/Sub, VPC, etc.)
Google Workspace
Hashicorp Vault
IBM MQ
Iptables
Istio Service Mesh
Juniper SRX
Microsoft 365 Defender & Defender for Endpoint
Microsoft (Office) 365
Microsoft SQL Server
Microsoft Windows Security Events
MISP
MySQL Enterprise Audit Logs
NetFlow & IPFIX
Okta
Oracle Database
Osquery Log Collection
Palo Alto Networks Cortex XDR
Palo Alto Networks Firewalls
Pensando
PowerShell
Pivotal Cloud Foundry (PCF)
Recorded Future
Redis Enterprise
Session initiation protocol (SIP)
SIEM connector (legacy)
Snyk
Sophos XG
Suricata
Sysmon
ThreatQuotient
Zeek (formerly Bro)
Zoom

Data transformation

Index time enrichment
Processors
Analyzers
Tokenizers
Filters
Grok
Field transformation
External lookup enrichment
Circle ingest processor
Match & Geo-match enrich processor

Elastic Common Schema

Elastic Common Schema

Data Exploration & Visualization

Visualizations

Time series
Geo
Metrics
Tables
Tag cloud
Custom (Vega)
Lens

Data exploration

Dashboards
Drilldown between dashboards
Drilldown to URL
Discover
Console
Kibana query autocomplete
Kibana runtime fields editor
Run search sessions in background
Graph analytics

Canvas

Canvas
Canvas shareables

Share & collaborate

Embeddable dashboards
Anonymous access control (public sharing)
CSV exports
PDF and PNG reports
Saved queries

Content management

Kibana Spaces
Custom banners
Object export UI & APIs
Tags
Navigational search

Elastic Observability

Observability overview
User Experience overview

Elastic APM

APM Server
Jaeger intake
OpenTelemetry intake for traces and metrics
APM app
Distributed tracing
Service maps
Correlations

APM agents

Java
.NET
Go
Ruby
RUM (JavaScript)
PHP
Python
Node

Integrations

Elastic Logs, Metrics
Kibana alerting and actions5
Machine learning

Elastic Logs

Log shipper (Filebeat)
Dashboards for common data sources
Logs app

Integrations

Elastic Uptime, APM
Kibana alerting and actions5
Log categorization
Machine learning

Elastic Metrics

Metric shipper (Metricbeat)
Dashboards for common data sources
Metrics app

Integrations

Elastic Logs, APM, Uptime
Kibana alerting and actions5
Machine learning

Elastic Uptime

Uptime monitor (Heartbeat)
Uptime dashboards in Kibana
Uptime app

Integrations

Elastic Logs, Metrics, APM
Kibana alerting and actions5
Machine learning

Elastic Security

Elastic Common Schema
Extended detection and response (XDR)
Security information and event management (SIEM)
Host security analysis
Network security analysis
Timeline event explorer
Case management
Detection engine (e.g., correlation, indicator match, threshold)
Prebuilt detection rules
Detection rule external actions
Machine learning anomaly detection
Prebuilt anomaly detection jobs
Malware prevention
Ransomware prevention
Malicious behavior protection
Host memory protection
Host isolation remote response
Customizable on-endpoint protection notifications

Integrations

Elastic Agent
Native host-based response
Elastic APM
Elastic Maps
Kibana Alerts and Actions5
Osquery Manager
Threat intelligence feeds and platforms
Atlassian Jira
Swimlane SOAR
IBM Resilient
ServiceNow ITSM and SIR
Machine learning

Elastic Maps

Elastic Maps Service6

Base layer maps
Elastic Maps Server

Maps app

GeoJSON upload
Multiple layers
Layer-based filtering
Client-side styling
Individual points and shapes
Geo aggregations
Embed Maps in dashboard
Embed Maps in Canvas
Tracking alerts
Containment alerts
Geo-threshold alerts
Display up to 24 zoom levels
Custom raster and vector tile service support
Kibana Alerts: tracking containment (geofencing)

Elastic App Search

App Search Server
App Search UI
Search result curation
Search analytics
Synonyms management
Language-specific relevance
Typo-tolerant relevance model
Relevance model tuning
Index lifecycle management
Meta engines
Web crawler
Precision tuning (beta)

Clients

Python
Ruby

Security

Encrypted communications
Role-based access control
Single sign-on (SAML)
Encryption at rest support

Elastic Workplace Search

Unified organizational search experience

Workplace Search server
Unified search interface
Out-of-the-box search applications
Customizable look and feel
Natural language query filtering
Search history
Typo-tolerant relevance model
Synonyms management
Customizable filtering and faceting
Content source prioritization
Search analytics
Search API

Clients

Python
Ruby

Content sources

First-party cloud source synchronization
First-party on-premise source synchronization
Custom source support
Full-text content indexing for files, documents, and records
Document-level permission support
Global sync scheduling configuration
Source-level scheduling configuration
Sync scheduling API
Object synchronization selection
Path-based content synchronization
File extension-based content synchronization
Private sources

User management & security

Organizational groups
Native user management
SAML user management
Role-based access control
Encrypted communications
Encryption at rest support

Orchestration

Elastic Cloud Enterprise

Deploy anywhere: bare metal, VMs, private or public cloud
Centrally provision, manage, and monitor multiple clusters
Resource tagging, and tag-based deployment configuration
Online same-day version updates
Single-click upgrades & scaling
User and role management
Automated periodic snapshots
Optimized resource utilization
Container-based resource isolation
Cross-cluster search and replication across ECE installations
Deployment autoscaling

Elastic Cloud on Kubernetes4

Deploy Elasticsearch, Kibana, and APM Server, Beats, Enterprise tier, and Elastic Agent on Kubernetes
Deploy Enterprise Search and Elastic Maps Server on Kubernetes
Provision, manage, and monitor multiple clusters
Default Elastic Stack security and authentication for every deployment
Single command upgrades and scaling
Cross-cluster replication and search within or outside of a Kubernetes cluster
Autoscaling Elasticsearch and Machine learning nodes

Support

Support coverage
Response times
Unlimited # of incidents
Unlimited # of projects
Support contacts7
Web and phone support
Emergency patches
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Business hrs
24/7/365
24/7/365
Critical: 4 hrs
L2: 1 day
L3: 2 days
Critical: 1 hr
L2: 4 hrs
L3: 1 day
Critical: 1 hr
L2: 4 hrs
L3: 1 day
6
8
8

1 For a more detailed discussion of our licensing options and 2021 licensing changes, please refer to the licensing FAQ on our website.

2 Available under the Elastic License. Select features are also available under SSPL or Apache License 2.0. For questions about which features may be licensed under SSPL and Apache License 2.0, please contact elastic_license@elastic.co.

3 Feature is currently not available in deployments on Elastic Cloud Enterprise.

4 Customers whose Enterprise subscriptions use ECE/ECE Instances as the billing metric must agree to additional terms before they can access the Enterprise-level features listed in this section. Please contact us.

5 Refer to the Alerting section (Kibana Alerts and Kibana Actions items) for further details.

6 Elastic Maps Service - Terms of Service

7 Elastic Certified Professionals can be added as additional Support contacts on paid subscriptions at no additional charge.

8 Access to administering Kibana subfeature privileges start at the Gold tier and are available on a per-feature basis matching the feature’s subscriptions tier.

The list above reflects the features available in the latest version of the Elastic Stack. Any features or functions of services or products referenced on this page or other pages, or in any presentations, press releases or public statements, which are not currently available or not currently available as a GA release, may not be delivered on time or at all. The development, release, and timing of any features or functionality described for our products remains at our sole discretion. Customers who purchase our products and services should make the purchase decisions based upon services and product features and functions that are currently available.