The Elastic Security homepage

Elastic Security

Score6.9
Rank#4 of 28
From$0.09/mo
Free planYes
Free trialYes
Runs onAPI, Linux, Self-hosted, Web

Summary

Elastic Security combines SIEM, XDR, endpoint security, and cloud security for detecting, preventing, and responding to cyber threats. Detection options include prebuilt and customizable rules, machine-learning anomaly detection, and threat hunting. Elastic Defend applies machine learning, behavioral analysis, and prebuilt rules to endpoint threats. Cloud features cover security posture management for cloud and Kubernetes, workload protection, and vulnerability management. Elastic Workflows can automate triage, enrichment, response, notifications, and case management. Elastic lists 400+ prebuilt integrations and up to 1,000 total security and data-source integrations, alongside native OpenTelemetry support. It can run on Elastic Cloud or self-managed infrastructure. The free Basic plan includes SIEM, XDR, and host security analysis; Elastic Cloud Hosted and Serverless offer a 14-day trial. Security Analytics Essentials is listed at 0.09 USD per month, with retention priced separately. Elastic Cloud secures internet-facing and inter-node communications with HTTPS and encrypts cluster data at rest. Query options include KQL, Lucene, and ES|QL.

Who it is for

It suits teams seeking SIEM, endpoint, and cloud security capabilities in one product. Teams can choose Elastic Cloud or self-managed deployment and use the listed query languages.

What is good

  • Free Basic plan includes SIEM, XDR, and host analysis
  • Offers prebuilt and customizable detection rules
  • Elastic Workflows automates triage and response tasks
  • Supports KQL, Lucene, and ES|QL

What to know first

  • 14-day trial applies to Elastic Cloud Hosted and Serverless
  • Essentials retention is priced separately
  • Optional Serverless endpoint and cloud protection costs extra

Verdict

Elastic Security combines threat detection and response tools with endpoint and cloud protections, plus automation and integrations. Review retention and optional protection charges when evaluating plans.

Elastic Security plans and pricing

All plans
Security Analytics Essentials $0.09/mo billed monthly Ad hoc analytics and machine learning · Prebuilt detection rules · Triage, investigation, and hunting · Threat intelligence integration · Endpoint protection · Retention priced separately at as low as $0.017 per retained GB per month elastic.co · 19 Sept 2026
Security Analytics Complete $0.11/mo billed monthly Everything in Security Analytics Essentials · Entity analytics and UEBA · Threat intelligence management · Elastic AI Assistant · Advanced endpoint protection · Private connectivity and IP filtering elastic.co · 19 Sept 2026
Free and open - Basic Free SIEM · XDR · host security analysis elastic.co · 29 Sept 2026
Elastic Cloud Serverless Security Not published SIEM and security analytics billed based on usage; optional endpoint and cloud protection costs extra per asset Usage-based pricing · optional endpoint and cloud protection at additional per-asset price elastic.co · 29 Sept 2026
Elastic self-managed subscriptions Not published Contact sales for pricing information License-based pricing based on number of nodes and used RAM elastic.co · 29 Sept 2026

Compared on file integrity monitoring software

Free plan
Yeselastic.co
Deployment
hybridelastic.co
Real-time alerts
Yeselastic.co

Facts

Purpose
Elastic Security unifies SIEM, XDR, endpoint security, and cloud security to detect, prevent, and respond to cyber threats.elastic.co · 29 Sept 2026
Threat detection
It provides prebuilt and customizable detection rules, machine-learning anomaly detection, and threat-hunting tools.elastic.co · 29 Sept 2026
Endpoint protection
Elastic Defend uses machine learning, behavioral analysis, and prebuilt rules to detect, prevent, and respond to endpoint threats.elastic.co · 29 Sept 2026
Cloud security
Cloud capabilities include cloud and Kubernetes security posture management, workload protection, and vulnerability management.elastic.co · 29 Sept 2026
Automation
Elastic Workflows automates triage, enrichment, response, notifications, and case management within Elastic Security.elastic.co · 29 Sept 2026
Integrations
Elastic says it supports 400+ prebuilt integrations and up to 1,000 total security and data-source integrations, with native OpenTelemetry data support.elastic.co · 29 Sept 2026
Trial
Elastic Cloud Hosted and Serverless offer a 14-day free trial.elastic.co · 29 Sept 2026
Security
Elastic Cloud automatically secures internet-facing and inter-node communications with HTTPS and encrypts cluster data at rest.elastic.co · 29 Sept 2026
Compliance
Elastic says its Elastic Cloud service and Information Security Management System have undergone compliance audits and certifications.elastic.co · 29 Sept 2026
Support
Elastic Cloud support levels include Limited, Base, Enhanced, and Premium, with target response times that vary by level.elastic.co · 29 Sept 2026
Pricing model
Serverless SIEM and security analytics are billed based on usage, while optional endpoint and cloud protection carry an additional per-asset price.elastic.co · 29 Sept 2026
Maker
Elastic says it was founded in 2012 and has headquarters in Amsterdam and Mountain View, California.elastic.co · 29 Sept 2026

Company

Founded
2012elastic.co · 23 Sept 2026
Headquarters
Amsterdam, Netherlands and Mountain View, Californiaelastic.co · 23 Sept 2026

Best Elastic Security alternatives

See all 12

Where it ranks on Everything Xiaomi

Is Elastic Security yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources