Elastic Security SIEM pricing in 2026: self-managed vs cloud, and the true cost
Independent Elastic Security pricing reference. Open-source Basic tier vs paid subscriptions, Elastic Cloud resource-based pricing, self-managed infrastructure and engineering costs, and where Elastic genuinely wins or loses against Splunk and Sentinel.
Subscription tier comparison
Basic
Free (open-source)Core SIEM rules, basic detections, ELK stack
Machine learning, advanced analytics, premium support
Gold
$95/user/moBasic + Kibana spaces, alerting, JDBC
ML, advanced security, cross-cluster
Platinum
$125/user/moGold + ML jobs, advanced security, cross-cluster
Endpoint integrations, advanced UEBA
Enterprise
$175/user/moPlatinum + Endpoint Security, SOAR, advanced UEBA
Bespoke MSSP features only
The "free software, expensive people" reality
The Elastic Basic tier is genuinely free, but operating an Elasticsearch cluster at security-grade reliability is a specialised skill. Engineers who can tune shards, manage rollover policies, and debug cross-cluster replication command a 30-50 percent premium over generic SREs. Budget honestly.
$15K-$50K per year for 50-200 GB/day clusters. Hot, warm, and cold tiers required for cost-effective retention.
$120K-$180K per year for an engineer who can run Elasticsearch competently. 20-30 percent of their time goes to cluster ops alone.
Open-source rule sets exist but lag commercial vendors. Plan for a detection engineering function, not just a SIEM operator.
Real-world Elastic cost scenarios
| Scenario | Profile | Licence | Total TCO | Notes |
|---|---|---|---|---|
| Startup | 5 GB/day, Basic + self-hosted | $0 licence | $45K-$70K | Single engineer maintains, infra ~$8K-$15K |
| Mid-market cloud | 50 GB/day, Elastic Cloud Platinum, 25 users | $85K-$110K/yr | $240K-$320K | Resource-based + per-user mix |
| Mid-market self-managed | 50 GB/day, Platinum subscription, on-prem cluster | $70K-$95K/yr | $310K-$420K | Engineer salary premium dominates |
| Enterprise | 200 GB/day, Elastic Cloud Enterprise, 75 users | $280K-$400K/yr | $760K-$1.1M | Full Endpoint Security included |
| Open-source heavy | 200 GB/day, Basic only, 2 dedicated engineers | $0 licence | $520K-$680K | Engineering, infra, opportunity cost |