Vendor hubInfra · APM · Logs · Security · ExperienceTechBag Intel Hub

Elastic

The leading unified cloud observability platform — metrics, traces, logs, real-user experience and security on ONE platform, with best-in-class correlation (one click: symptom → root cause). Powerful & easy — with an honest guide to the cost. This hub is your complete intel file.

5 intel pages insideUnified observability + cost helpIndia-ready via TechBag

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

The company, at a glance

Founded2010 · New York
ListingNASDAQ: DDOG
Scale~32,700 customers
Revenue~$3.5B (~30% growth)
The edgeBest correlation UX

Quick answer

Elastic is the company behind Elasticsearch — the search and analytics engine that a very large share of the world's engineering teams already run, often without anyone having bought it. That is the fact that makes Elastic unusual as a vendor: its products frequently arrive in an organisation bottom-up, installed by developers solving a logging or search problem, and only later become a commercial conversation. Founded in 2012 around Shay Banon's open-source project, Elastic (NYSE: ESTC) is domiciled in Amsterdam with executive operations in Mountain View, reported $1.739 billion revenue for the year ended 30 April 2026, and is led by CEO Ash Kulkarni, with Banon returning to the CTO role in 2022. The portfolio is one platform under three solutions: Elasticsearch (search and vector database), Elastic Observability (logs, metrics, traces and APM) and Elastic Security (SIEM plus endpoint). All three run on the same engine and the same data, which is the architectural argument — one store, queried three ways, rather than three products with three copies of your data. On licensing, Elastic did something almost no vendor does: after moving Elasticsearch away from open source in 2021 it moved BACK, adding AGPL as an option in 2024 alongside its existing licences. Elastic Security was named a Visionary — not a Leader — in the 2025 Gartner Magic Quadrant for SIEM, and being straight about that distinction matters more than the badge. Deployment is genuinely flexible: self-managed anywhere including air-gapped, Elastic Cloud Hosted across 60 regions with resource-based pricing, or Serverless with consumption pricing. The honest caveat is the same one that makes it attractive: the free tier is real and capable, so the value of paying is in the features above it and in not running the cluster yourself — and running Elasticsearch well at scale is genuine engineering work that teams routinely underestimate. TechBag scopes which tier you actually need, in INR with GST. Read more ↓ Show less ↑
The portfolio

Five intel pages. One unified observability platform.

The complete Elastic platform — every linked card is a full intel page, from infrastructure metrics to the real user experience.

Security — SIEM + endpointIntel page →

Elastic Security

The SIEM your engineers may already be running.

SIEM and endpoint security on the same engine that stores your logs — detection rules, MITRE ATT&CK coverage, entity analytics and an included endpoint agent, with no separate data copy to maintain. The distinctive commercial fact is deployment: it is the credible route when you need on-premises or air-gapped, which rules out most cloud-native SIEMs outright, and the free tier is genuinely usable so many teams start before they buy. Named a Visionary in the 2025 Gartner MQ for SIEM.

SIEM + endpoint · on-prem or air-gappedExplore
The engine — search & vectorIntel page →

Elasticsearch

The search engine underneath everything else.

The distributed search and analytics engine the whole platform is built on, and increasingly a vector database for retrieval-augmented generation. It powers site and application search, log analytics and the two solutions below it. Open source again under AGPL since 2024. The reason it matters commercially: your engineering team may already run it, so the question is usually not whether to adopt Elastic but which tier and deployment to formalise.

AGPL open source · search + vectorExplore
Observability — logs, metrics, APMIntel page →

Elastic Observability

Logs, metrics and traces on one store.

Full-stack observability — log analytics, infrastructure metrics, APM and distributed tracing, synthetics and real user monitoring — on the same Elasticsearch cluster as your search and security data. For teams already running the ELK stack for logs, this is the formalisation of what they have rather than a migration, and the cost model is resource-based rather than per-host, which changes the arithmetic against per-host competitors.

One store · resource-based pricingExplore
Security — endpoint (EPP / EDR)Intel page →

Elastic Defend

The endpoint agent that is also your log shipper.

Malware and ransomware prevention with EDR telemetry and response actions, delivered by the same Elastic Agent that ships your logs — so endpoint rollout is not a second project and there is no second agent to upgrade. It scored 100% malware protection in the AV-Comparatives 2026 Business Security Test. The honest scope: it is strongest as part of the Elastic platform rather than as a standalone EPP bought against CrowdStrike or SentinelOne on their own terms.

100% malware · AV-Comparatives 2026Explore
Search — apps & workplaceIntel page →

Elastic Enterprise Search

Search inside your own product, done properly.

Relevance tuning, semantic search and vector retrieval for your applications, websites, ecommerce and internal content — built on the same engine, so it is the same cluster and the same operational model as everything else Elastic sells you. This is the original commercial use of Elasticsearch and still the one that brings most teams to the platform in the first place.

Relevance you can tune · semantic + vectorExplore
Platform — Hosted & ServerlessIntel page →

Elastic Cloud

Elastic, without running the cluster.

The managed platform: Elastic Cloud Hosted across 60 regions with resource-based pricing and full control over the deployment, or Elastic Cloud Serverless with consumption pricing and nothing to size. Its real purpose is absorbing the operational work — shard strategy, capacity, upgrades — that makes self-managed cheaper on the licence and more expensive in engineer-days. That trade is the whole cost conversation.

60 regions · or Serverless on consumptionExplore

Elastic AI Assistant

Platform & engine

Across Search, Observability and Security

AutoOps

Platform & engine

Cluster health and optimisation guidance

Elastic sells across 6 of the products TechBag carries in security. The SIEM & log management guide shows how the category splits and which part is yours. →

The thesis

Why “unified observability, one click to root cause” is the whole story

Search, observability and security tools each keep their own copy of your data, so the same log is stored three times and queried three ways. Elastic bet on unifying observability on one platform with the best correlation UX— metrics, traces, logs, real-user experience and security unified on ONE platform, with best-in-class correlation (one click from symptom to root cause), from the observability leader doubled down on it.

01
One engine, three

One engine, three solutions

Search, Observability and Security are not three products with three data stores — they are three ways of querying one Elasticsearch cluster. A log your observability team ingested is the same document your security team writes a detection against. That is the architectural argument, and it is why the platform's economics differ from tools priced per host or per seat.

02
Deployment nobody else

Deployment nobody else matches

Self-managed anywhere including fully air-gapped, Elastic Cloud Hosted across 60 regions with resource-based pricing, or Elastic Cloud Serverless with consumption pricing and no cluster to size. For a regulated Indian buyer whose mandate rules out SaaS, this is frequently the only credible modern SIEM on the shortlist.

03
Open source, and

Open source, and back again

Elastic moved Elasticsearch away from open source in 2021 and then moved back, adding AGPL as an option in 2024 — a reversal almost no vendor makes. Whatever you think of the round trip, the practical effect is that the engine is open source today, the free tier is genuinely capable, and adoption does not require procurement.

04
Bottom-up adoption is

Bottom-up adoption is the norm

Elastic products usually arrive in an organisation because a developer installed one, not because a committee chose one. The commercial conversation is therefore rarely 'should we adopt Elastic' — it is 'we already run this, which tier do we actually need and who should operate it'. That is a different scoping exercise, and the one TechBag is most often asked for.

05
Running it well

Running it well is real work

The honest counterweight to a capable free tier: operating Elasticsearch at scale — shard strategy, index lifecycle, capacity, upgrades — is genuine engineering effort that teams underestimate. Elastic Cloud exists precisely to absorb that. The right comparison is rarely licence-versus-licence; it is licence plus your engineers' time versus a managed bill.

Start with Infrastructure Monitoring (the core) — then add APM, Logs, Cloud Security and Digital Experience, all correlated on one platform. (And manage the cost — TechBag’s key value.)

The trophy wall

Peer & market recognition

Every claim on this hub traces to one of these public signals.

Recognition

Gartner MQ for SIEM 2025

Named a Visionary — not a Leader. We say which.

Recognition

AV-Comparatives 2026

100% malware protection, Business Security Test

Recognition

NYSE: ESTC

$1.739B revenue, FY ended 30 April 2026

Recognition

Open source again

AGPL added back for Elasticsearch and Kibana, 2024

Recognition

60 regions

Elastic Cloud Hosted footprint

Recognition

Air-gapped capable

Self-managed deployment with no cloud dependency

Recognition

Founder still building

Shay Banon returned to CTO in 2022

Three solutions

one engine

Search · Observability · Security

By the numbers

The company in six figures

$1,739M
Revenue, FY ended 30 April 2026
Elastic FY26
3 solutions
Search, Observability and Security — one engine
The platform
60 regions
Elastic Cloud Hosted footprint
Elastic
2012
Founded around Shay Banon's project
Company
2024
AGPL added back — open source again
Licensing
100% malware
AV-Comparatives 2026 Business Security Test
AV-Comparatives

See the platform, hear the pitch

Elastic (official)·Overview

Elastic Security Solutions Overview

The security platform, explained by Elastic.

Elastic (official)·Platform

Elastic Security: an agentic security operations platform

Where the security product is heading.

Elastic (official)·Workflow

Elastic Security: End to End Incident Response

Detection through to response, end to end.

The market maps

Where Elastic sits — the grids

Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.

Grid 01 · The portfolio

Elastic Across Its Platform

Each dot is an Elastic solution: competitive position vs category momentum.

Emerging betsCrown jewelsSteady nicheAnchor strengths
Elastic SecurityElastic

SIEM + endpoint — on-prem or air-gapped capable.

Grid 02 · The industry

The Unification × Breadth Map

Deployment flexibility and cost control vs the field — and where the Leaders still go deeper.

Niche monitoringBroad + unifiedPoint playersBroad but disjointed
Elastic (platform)Elastic

One engine for search, observability and security — and the deployment flexibility nobody else matches.

Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Track 01 · Beginner guides

New to this? Learn it properly.

Zero-jargon starting points, in reading order. Each links into the deep education on the product page.

Interactive · 30 seconds

Where should you start with Elastic?

Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.

1. What is the most pressing thing you need to solve?

2. What does your deployment have to look like?

3. Who will be using it day to day?

The acronym decoder

Every term on these pages, in one place
Elasticsearch
The distributed search and analytics engine at the centre of everything Elastic sells — and increasingly a vector database for AI retrieval.
The ELK stack
Elasticsearch, Logstash (ingest) and Kibana (visualisation) — the combination a great many teams run for log analytics, often before any commercial relationship.
Kibana
The visualisation and management interface — dashboards, search, and the console for Security and Observability.
Beats / Elastic Agent
The lightweight shippers that send data in. Elastic Agent is the single unified one, and it doubles as the endpoint security agent.
AGPL
The open-source licence Elastic added back for Elasticsearch and Kibana in 2024, after moving away from open source in 2021.
OpenSearch
The fork AWS created in 2021 when Elasticsearch left open source — Apache 2.0 licensed and still developed separately.
Self-managed
You run the cluster on your own infrastructure, including fully air-gapped. Satisfies data residency by definition.
Elastic Cloud Hosted
Elastic runs the cluster for you across 60 regions, priced on the resources you provision rather than per host or per seat.
Serverless
Fully managed with no cluster to size, billed on consumption — ingest per GB plus storage per GB per month.
Subscription tiers
Standard, Gold, Platinum and Enterprise — the feature and support levels layered on top of whichever deployment you choose.
Shard strategy
How you split indices across nodes. Getting it wrong is the single most common cause of a badly performing Elasticsearch cluster.
Index lifecycle management
The policy that rolls data from hot to warm to cold to frozen storage as it ages — the main lever on self-managed cost.
Track 02 · Buying guides

Buy it like you’ve done this before

The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.

01

Find out what you already run

Elastic arrives bottom-up. Before anything else, find the clusters your engineering teams have already stood up — the commercial question is almost always about formalising something that exists, not adopting something new.

02

Decide the deployment model first

Self-managed, Cloud Hosted or Serverless have genuinely different economics and different residency answers. This decision constrains everything after it, so make it before comparing feature tiers.

03

Work out which tier you actually need

The free tier is capable. Map the specific features you need above it — and be honest about which are wants. This is where most of the negotiable money is.

04

Price your engineers' time honestly

Self-managed licences look cheap until you count shard strategy, capacity planning and upgrades. The real comparison is licence plus operations against a managed bill.

05

Plan index lifecycle before you ingest

Hot, warm, cold and frozen tiers are the main cost lever on any large deployment. Set the policy first; retrofitting it to a cluster already holding a year of data is painful.

06

Get it quoted in INR with GST

Elastic bills in USD. TechBag scopes the tier and deployment, and quotes locally with GST-compliant invoicing and support.

The licensing cheat-sheet

ProductLicensing modelHow you enterBest for
Elastic SecuritySubscription tier on top of your deployment; Platinum and Enterprise carry the SIEM and endpoint features most buyers needSubscription tier on top of your deployment; Platinum and Enterprise carry the SIEM and endpoint features most buyers needSubscription tier on top of your deployment; Platinum and Enterprise carry the SIEM and endpoint features most buyers need
ElasticsearchFree and open source under AGPL; paid tiers add features and support. Elastic Cloud is resource-basedFree and open source under AGPL; paid tiers add features and support. Elastic Cloud is resource-basedFree and open source under AGPL; paid tiers add features and support. Elastic Cloud is resource-based
Elastic ObservabilitySame tiering; Cloud Hosted priced on provisioned resources, Serverless on ingest and storage consumptionSame tiering; Cloud Hosted priced on provisioned resources, Serverless on ingest and storage consumptionSame tiering; Cloud Hosted priced on provisioned resources, Serverless on ingest and storage consumption

Free and open source under AGPL, with paid tiers above it — the cost that surprises is your engineers’ time, not the licence. The compounds across modules. TechBag scopes the tier you actually need AND prices your engineers’ time honestly (Elastic bills USD; GST added).

Five pitfalls that cost buyers quarters

1

Assuming free means free forever

The free tier is genuinely capable, which is exactly why teams get surprised: the feature you eventually need — a specific authentication integration, alerting depth, certain machine-learning jobs — sits in a paid tier, and by then the cluster is production-critical. Map the features you need up front.

2

Underestimating what running it costs

A self-managed cluster is engineering work: shard strategy, capacity planning, version upgrades, index lifecycle. Teams routinely compare a self-managed licence against a managed competitor's bill and forget to price their own people. That is not a fair comparison.

3

Not setting index lifecycle up front

Hot, warm, cold and frozen tiers are the main lever on storage cost, and they are far easier to configure before the cluster holds a year of data than after. Most cost problems on large deployments trace back to this.

4

Confusing Elasticsearch with OpenSearch

AWS forked Elasticsearch in 2021 as OpenSearch, and the two have diverged since. Documentation, clients and features are not interchangeable — check which one your team actually deployed before you buy support for the other.

5

Reading Visionary as Leader

Elastic Security was named a Visionary in the 2025 Gartner MQ for SIEM, not a Leader. That is a real distinction about execution at enterprise scale, and any vendor material that blurs it is worth reading twice.

The evaluation kit

The flagship intel page carries an 8-question vendor checklist and an automation-savings calculator:

Skip the homework entirely

Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.

Book a discovery call →
FAQ

Questions buyers ask about Elastic

Elastic is the company; Elasticsearch is its core product — the distributed search and analytics engine that everything else is built on. Founded in 2012 around Shay Banon's open-source project, Elastic (NYSE: ESTC) is domiciled in Amsterdam with executive operations in Mountain View, reported $1.739 billion in revenue for the year ended 30 April 2026, and is led by CEO Ash Kulkarni, with Banon having returned to the CTO role in 2022. The portfolio is one platform sold as three solutions: Elasticsearch for search, analytics and increasingly vector search for AI retrieval; Elastic Observability for logs, metrics, traces and APM; and Elastic Security for SIEM and endpoint protection. All three query the same cluster, which is the architectural argument — one copy of your data, three ways of using it, rather than three products each maintaining their own. The thing that makes Elastic commercially unusual is how it arrives: engineering teams install Elasticsearch to solve a search or logging problem, and the vendor conversation happens later, once something has become production-critical. So the question TechBag is usually asked is not whether to adopt Elastic, but which tier and deployment model to formalise around what already exists.

Ready to shortlist Elastic?

Open any of the five intel pages for the deep dive, or let a TechBag advisor build the case with you — module scoping, realistic cost estimation and active COST MANAGEMENT, honest comparisons, deployment, GST invoicing and support included.

Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.