Ask AI
VirtualMetric is heading to Gartner Security & Risk Management Summit

News overview

Elastic SIEM Pricing in 2026: Full Cost Breakdown (and How to Cut It)

elastic siem pricing

Elastic prices Security based on the resources and usage your deployment needs, not a flat rate per gigabyte ingested. That sounds different from other SIEMs, but the same data growth that inflates other platforms’ bills still drives what you pay here. More data means more infrastructure or a bigger invoice, just measured differently. 

This guide breaks down what actually ends up on an Elastic Security bill, how the different ways of running it affect that bill, and how to keep it lean. 

Prefer to jump straight to the numbers? See the full 2026 cost breakdown

Comparing SIEM platforms rather than Elastic specifically? See how different pricing models play out in our Microsoft Sentinel, Splunk, and Google SecOps pricing breakdowns.  

How Elastic Security pricing works 

Elastic offers three ways to run Security, each with its own billing mechanic. Cloud Serverless bills a straightforward per-GB rate for what you ingest and what you retain each month, no infrastructure sizing required. Cloud Hosted bills for the compute and storage resources you provision: RAM, disk, and zones, within a subscription tier. So the invoice reflects the size of your cluster (the group of servers running your Elastic deployment) rather than a direct per-GB rate. Self-managed Elasticsearch is license-based, tied to node count and RAM, and you run the infrastructure yourself. 

All three sit underneath four subscription tiers that gate features rather than set the base price directly: Standard, Gold, Platinum, and Enterprise. Gold is worth a specific note. It was discontinued for new self-managed customers in 2021. Existing self-managed Gold subscriptions were grandfathered, and Gold remains a fully current option on Elastic Cloud Hosted. 

Here is what each tier actually adds: 

elastic tier comparison

One billing detail changes the entire “resource-based is cheaper” pitch. It comes directly from Elastic’s own documentation: ingest and retention metering is based on the uncompressed, normalized, fully enriched data volume you send in, not the raw or compressed size on the wire. Whatever your log shipper measures as the payload size, Elastic bills a larger number once its own enrichment and normalization inflate it. This applies across Serverless, Hosted, and self-managed alike. It is the mechanic that quietly narrows the gap between “resource-based” and “ingest-based” pricing. 

The full cost breakdown: what an Elastic SIEM really costs 

Compute and storage sizing is the core driver on Hosted and self-managed. More data, kept longer, at higher query load, means more nodes. More nodes means a bigger bill within whichever tier you have chosen. On Serverless, the same pressure shows up as a larger per-GB ingest and retention charge instead of a resizing decision. 

Storage tiering is the biggest lever available once data is in. Warm storage runs roughly half the cost of hot, cold roughly a third. Frozen, searchable snapshot storage runs one-fifth to one-tenth, depending on query patterns. Data that does not need instant query speed belongs in a cheaper tier. But many environments leave far too much of it sitting in hot storage by default. 

Self-managed hidden total cost of ownership (TCO) is real and easy to underestimate against a Hosted quote. The Elastic license itself is one line item. Infrastructure, patching, version upgrades, and the engineering time to run capacity planning are separate, ongoing costs that a Hosted or Serverless subscription folds into a single higher rate. 

Premium features per tier gate a real cost decision. Machine learning anomaly detection and prebuilt detection rules sit behind Platinum. Buying a tier for one feature you need can mean paying for several you never touch. 

Support is billed as a percentage of your total consumption on Hosted and Serverless. Standard is included, Gold adds 5 percent, Platinum 10 percent, Enterprise 15 percent. A larger bill makes support cost more in absolute terms even at the same percentage tier. 

Add-ons such as Cloud Security Posture Management, cloud workload protection, and Elastic’s managed LLM are metered separately from core ingest and retention. Pricing runs per billable asset or per million tokens.

The hidden-cost pattern underneath all of it is the same one that shows up on every ingest-based SIEM in this space. It just wears a resource-sizing label instead of a per-GB one. Noisy, duplicate, and default “collect everything” data inflates cluster size, storage tier usage, and query load together. Resource-based pricing moves where that cost lands on the invoice. 

elastic siem pricing cost components

Serverless rates and the support and add-on percentages are drawn directly from Elastic’s pricing documentation. Hosted and self-managed dollar figures are independent estimates and will vary by region, cluster sizing, and negotiated terms. Confirm current pricing with Elastic or your reseller. 

A realistic pricing example: what an Elastic SIEM bill actually looks like 

Serverless gives the cleanest math, since it bills a flat rate with no cluster sizing involved. A security team ingesting 100 GB a day on the Security Analytics Essentials tier pays $9 a day in ingest, or about $270 a month. Retaining a rolling 30 days of that volume, roughly 3,000 GB, adds about $51 a month at $0.017 per GB retained. Total: roughly $321 a month, or under $4,000 a year, before egress beyond the free allowance or any add-ons. 

The same 100 GB a day on the Complete tier, at $0.11 ingest and $0.019 retention, runs closer to $387 a month. Both figures are before the uncompressed-billing effect described above. The actual billed volume, and therefore the actual bill, is usually higher than a raw log-volume estimate would suggest. 

Hosted does not offer an equally clean calculation, and that is itself the point. The same 100 GB a day has to be translated into provisioned RAM, storage, and node count. Independent trackers put modest production clusters at $1,500 to $8,000 a month on Standard or Gold, climbing to $10,000 to $50,000 a month on Platinum or Enterprise for larger deployments. There is no simple formula from GB to dollars on Hosted the way there is on Serverless. That’s why TCO surprises happen more often on that model. 

Why Elastic bills spiral 

Bills grow for the familiar reason: environments default to collecting everything, every log source that might someday be useful, whether or not it ever earns its place in a detection. On Elastic specifically, that default inflates cluster size, storage tier usage, and query load all at once. All three key off the same ingested volume

Resource-based pricing relocates this problem. Instead of a rising per-GB invoice, you get a cluster that needs more nodes. Or a Serverless bill where ingest and retention climb together, inflated further by the uncompressed metering rule covered above. Either way, the root cause is the same. Cost control here is a data problem before it is a tier-selection or cluster-sizing problem. 

How to cut Elastic Security costs in 2026 

Use the storage tiers aggressively. Data that does not need hot-tier query speed belongs in warm, cold, or frozen storage, where the same gigabyte costs a fraction as much. Tune retention to what compliance actually requires rather than a default that keeps everything at the most expensive tier. Right-size the cluster to real usage. Review which tier features you are actually using, since Platinum and Enterprise both carry cost for capabilities a given team may never touch. 

Elastic does offer a native tool for the next step. Ingest pipelines, included even in the free Basic tier, can filter, transform, and drop fields before data is indexed. It is a real, useful, and free capability. It is also fully DIY: you write and maintain the processors yourself, in Elastic’s own pipeline syntax. And none of that configuration transfers if you ever run a different platform alongside or instead of Elastic. For teams that want to reduce SIEM costs without building and maintaining that logic in-house, a platform-independent pipeline is the alternative. 

That is the lever that attacks the root cause directly. Filter and reduce data before ingestion, dropping known-noisy events, deduplicating repeated telemetry, and forwarding only what is detection-relevant, before it inflates cluster size, storage tier usage, or a Serverless ingest bill. VirtualMetric DataStream handles that step. It is a security data pipeline built to sit in front of Elastic. It takes on exactly that filtering, normalization, and routing, including ECS-ready normalization before the data ever reaches your cluster. 

What is VirtualMetric DataStream? 

VirtualMetric DataStream is a security data pipeline that sits between your log sources and Elastic. It collects telemetry from any source, normalizes it, cuts the noise, enriches it with context, and routes it to the right destination, so your cluster only holds what is actually worth the resources it consumes. 

Its five capabilities map onto the cost problem above: 

  • Collection: agentless-first ingestion from a wide range of sources, live in under 30 minutes, without disrupting existing systems. 
  • Normalization: logs are mapped to the Elastic Common Schema before ingestion, so Elastic Security’s detection rules and dashboards work against consistent, query-ready fields. Normalize security data before ingestion rather than writing and maintaining that mapping inside Elastic’s own ingest pipelines. 
  • Reduction: unnecessary fields and noisy, low-value events are filtered out before they add to cluster size or a Serverless ingest bill, keeping anything detection-relevant intact. 
  • Enrichment: events are annotated with identity, geo-location, device, and policy context, so analysts get complete signals without the cluster having to index raw fields just to stitch context together later. 
  • Routing: clean, high-priority data goes to Elastic for real-time detection. Lower-value telemetry routes to cheaper destinations instead of consuming the same hot-tier resources as everything else. 

For Elastic Security specifically, see how VirtualMetric for Elastic fits into an existing deployment. 

Why choose VirtualMetric? 

The core case is simple: run Elastic as your SIEM, and pay substantially less to feed it. A few things make that possible in practice. 

  • Lower cost without losing detection coverage. Reduction happens before ingestion, so what your cluster or Serverless bill has to carry is cleaner, smaller data with coverage intact. 
  • No build effort, and no lock-in. Elastic’s native ingest pipelines are a real, free option, but they are DIY, built and maintained by your team in Elastic’s own syntax, and none of that work transfers if you ever run another platform. DataStream is prebuilt, maintained for you, and works the same way regardless of which platform sits behind it. 
  • Works with what you run now, and whatever you run next. DataStream is SIEM-agnostic. It sits in front of Elastic today and can route to another SIEM later, without rebuilding collection from scratch. That matters for enterprises that may add or switch SIEMs, and for MSSPs routing each client tenant’s data to whichever platform that client runs. 
  • Nothing lost, even after reduction. Full raw logs stay available in low-cost storage for forensic retrieval, so a leaner Elastic bill does not mean a thinner investigation trail. 

Provable before you commit. Calculate your savings using real ingestion figures from your own environment, rather than taking a vendor estimate. The numbers should make the case. 

Frequently asked questions 

How much does Elastic Security cost? 

It depends on the deployment model. On Elastic Cloud Serverless, the Security Analytics Essentials tier bills $0.09 per GB ingested and $0.017 per GB retained per month, rising to $0.11 and $0.019 on the Complete tier. On Hosted, you pay for provisioned RAM and storage within a subscription tier, with small reference clusters starting near $99 to $184 a month and real production clusters running far higher. Self-managed adds infrastructure and license cost on top, with Platinum licenses estimated at roughly $25,000 to $75,000 a year. 

Is Elastic SIEM free? 

Self-managed Elastic’s Basic tier is free and open, and includes core Elasticsearch and Kibana, ingest pipelines, and basic alerting. Full SIEM capabilities, including machine learning anomaly detection and prebuilt detection rules, require a paid subscription, Platinum or Enterprise for self-managed, or a paid tier on Elastic Cloud. 

Is self-managed Elastic cheaper than Elastic Cloud? 

It can be, if you already have the infrastructure and the team to run it. Self-managed avoids Elastic’s hosting margin but shifts cost into your own compute, storage, and the engineering time to patch, upgrade, and scale the cluster. Elastic Cloud Hosted and Serverless absorb that operational cost into a higher per-unit rate. Which is cheaper depends on your existing infrastructure and staffing, not on data volume alone. 

Does Splunk Enterprise Security cost extra? 

Yes. Enterprise Security is a premium app licensed on top of the base Splunk platform, whether you pay by ingest or by workload. It is not included in standard platform pricing. On ingest pricing, independent estimates put its added cost at roughly 50 to 100 percent above the base platform price. On workload pricing, there is no equivalent estimate, since the base SVC cost itself is not published. 

What is the best way to reduce Elastic Security costs? 

Using storage tiers aggressively and tuning retention to actual compliance needs both help, since warm, cold, and frozen storage cost a fraction of hot. The highest-leverage fix is reducing data volume before it is ingested, since every gigabyte you avoid sending lowers ingest cost directly on Serverless, and lowers the resource footprint that drives cost on Hosted and self-managed. A security data pipeline such as VirtualMetric DataStream handles that reduction, along with collection, normalization, enrichment, and routing, before the data ever reaches Elastic. 

See VirtualMetric DataStream in action

customizable alert rules

Start your free trial to experience safer, smarter data routing with full visibility and control.

Start free