Elastic Cloud managed service features

Elastic Cloud gives you the flexibility to run where you want. Deploy our managed service on Google Cloud, Microsoft Azure, or Amazon Web services, and we'll handle the maintenance and upkeep for you.

 

standard

Gold

Platinum

Enterprise

Platform services

Managed Elasticsearch and Kibana
Deployment autoscaling
same day version availability
Instant access to security patches
single-click deployment upgrades
In-place configuration change
Deployment templates
Hot-warm-cold architecture, with automated index curation
Hot-warm-cold architecture, with automated index curation and searchable snapshots
Frozen data tier with automated index curation and searchable snapshots
Automated snapshots (configurable, default every 30 minutes)
REsT API for deployment management
REsT API support in ecctl CLI, Golang sDK, and generated sDKs
Providers: AWs, Azure, Google Cloud
FedRAMP authorized at Moderate Impact level on AWs GovCloud (Us)2
High availability across zones
Console signup with Google Account
Console signup with Microsoft Account
Multi-factor authentication
Multi-user management
Role-based access control
Elastic Cloud sAML single sign-on (ssO)
AWs Marketplace billing integration
Microsoft Azure Marketplace billing integration
Google Cloud Marketplace billing integration
AWs PrivateLink integration
Azure Private Link integration
Google Cloud Private service Connect integration
Encryption at rest with AWs KMs keys
Encryption at rest with Azure Key Vault keys
Encryption at rest with GCP KMs keys
IP filtering
sOC 2 and CsA star 2 compliance
HIPAA BAA ready
IsO 27001/27017/27018

Monitoring & Diagnostics

AutoOps

Real-time root cause analysis and resolution steps
Insights on how to improve performance and stability
Resource utilization visibility
Default data retention
Notifications to alerting and messaging frameworks (slack, Ms teams, PD, custom webhooks, and more)
Customization of events

stack monitoring

Full-stack monitoring (including Beats and Logstash)
Multi-stack monitoring
Configurable retention policy
Kibana alerting and actions4
Automatic stack issue alerts

Elastic stack operations & management

storage types

Inverted index (for search)
Evaluating calculated fields at index time
Runtime fields
Lookup runtime fields
Document store (for unstructured)
Columnar store (for analytics)
Doc-values only fields
BKD trees (for numeric, dates, geo)
Flattened field type
Histogram field type
Match only text field type
shape field type
Vector field type
Version field type
Wildcard field type
synthetic _source
13
13
13

Data management

searchable snapshots
snapshot/restore APIs
snapshot as simple archives
snapshot lifecycle management
snapshot-based peer recoveries
Data rollups
Data streams
Data tiers
Data transforms
Index lifecycle management
Data stream lifecycle
Downsampling lifecycle

stack management

Data import tutorials
Ingest Node Pipeline Builder UI
Grok Debugger
Upgrade Assistant
Centralized Logstash pipeline management

scalability & resiliency

Clustering and high availability
Cluster rebalancing
Advanced cluster rebalancing11
Cross-region cross-cluster replication
same-region cross-cluster replication
Cross-environment cross-cluster replication
Cross-region cross-cluster search
same-region cross-cluster search (legacy certificate based security model / _search only)
Cross-environment cross-cluster search
Dedicated master nodes
Dedicated coordinating nodes

Elastic stack security

secure settings
Data encryption at rest
Encrypted node-to-node communications
Role-based access control
Anonymous access control (public sharing)
Native authentication
Kibana spaces
Kibana feature controls
Kibana subfeature privileges8
Prelogin access agreement
API Keys management
Elasticsearch Token service
single sign-on (sAML, OpenID Connect, Kerberos, JWT)
Attribute-based access control
Field- and document-level security
Advanced security for remote clusters
Custom authentication and authorization realms

Alerting

Noise reduction capabilities (e.g., scheduled snooze, Muting, Deduping, etc.)
Maintenance Windows
Tracking containment rule type (geofencing)
Anomaly detection rule types by Machine Learning
Operational rule type for transforms
search threshold rule types for Discover
Case Management
Case user assignment
Elastic Connectors (e.g., server Log and Index)
Connectors (Actions) (e.g., email, webhook, Jira, Ms Teams, OpsGenie, PagerDuty, slack, IBM Resilient, serviceNow®, Tines, Torq)
Watcher

Clients

REsT APIs
Language clients
Query DsL
Console
JDBC client
ODBC client
Tableau Connector

Localized UI

English
Chinese (simplified)
French
Japanese

Custom plugins

Custom plugins

search & Analysis

Relevance scoring
Highlighting
Type ahead
Corrections
suggestions
Percolations
Async search
Results pinning
Query profiler
Dynamically updateable synonyms
similarity functions for vector fields
Vector search
Reciprocal Rank Fusion (RRF) for hybrid search
synonym management
Query Rules
Learning to Rank
Retrievers
Rank Vectors (for Maxsim)

Analytics

Aggregations
Boxplot aggregation
Cumulative cardinality aggregation
Geoline aggregation
Geoshape aggregations
Geohexgrid aggregations
Geogrid query
Moving percentiles aggregation
Multi terms aggregation
Normalize aggregation
Range aggregation over histogram fields
Random sampler aggregation
Rate aggregation
significant terms aggregation p-value score
string stats aggregation
Top metrics aggregation
T-test aggregation
Graph exploration
Vector tiles API

Query languages

Elasticsearch sQL APIs
Event Query Language (EQL)
Es|QL (Elasticsearch Query Language)
Cross-cluster Es|QL - Tech Preview

Machine learning

Data exploration for machine learning

Data Visualizer
File upload wizard
Data drift
Dashboard embeddables

Anomaly detection

single metric and multi-metric
Population/entity analysis
Log message categorization
Rare analysis
Root cause indication
Forecasting on time series
DsT support

Data frame analysis

Outlier detection
Regression
Classification
Feature importance

Inference and model management

Language identification
Third party model management, for ML nodes
Kibana space access to models
Elastic Learned sparse Encoder (ELsER) - packaged for ML nodes
e5 - packaged for ML nodes
Elastic Rerank
Inference API - Elastic managed (ELsER, e5, Elastic Rerank)
Inference API - support for third party and self managed embeddings, reranking and LLM providers

AIOps

Explain log rate spikes
Log Pattern Analysis
Change Point Detection

Elasticsearch

search server
search management UI
search stack monitoring
Dashboards for web and search analytics
Dev Console
Elastic AI Assistant

Content Management

Content management UI
Ingestion pipeline management
Inference processor management
Extraction service (Beta)

Machine Learning / AI

Third party model management
Elastic Learned sparse Encoder (ELsER) - packaged for ML nodes
e5 - packaged for ML nodes
Elastic Rerank
Inference API - Elastic managed (ELsER, e5 and Elastic Rerank)
Inference API - support for third party and self managed embeddings, reranking and LLM providers
Playground

Query and relevance

search Applications
Elasticsearch query DsL
Es|QL (Elasticsearch Query Language)
Language-specific relevance
Vector search
similarity functions for vector fields
Reciprocal Rank Fusion (RRF) for hybrid search
synonym management
Query Rules
Learning to Rank (LTR)
search Applications (beta)

Clients

Language clients (open source)
search UI (open source)
AI ecosystem client integrations (open source)
Web and search analytics client (Beta)

security

Encrypted communications
Role-based access control
single sign-on (sAML, OpenID Connect, Kerberos, JWT)
Encryption at rest support

Data Ingest & Transformation

Ingest products & features

Filebeat, Metricbeat, Winlogbeat, Packetbeat10, Heartbeat, Auditbeat, real browser-based synthetic monitoring agent (Beta)
Functionbeat
Logstash
Es-Hadoop
File import wizard
Auto Import (Tech Preview)

Fleet

Fleet server
Fleet app
Fleet integrations
Elastic Agent
selective agent binary updates
scheduled agent binary upgrades
selective agent policy reassignment
selective agent unenrollment
Per Policy output assignment
Per Integration output assignment
Reusable Integration policies

Data sources - For a full list of integrations available, check out our Integrations page.

Abuse.ch
Audit system data
Cisco Firepower
Check Point Firewall
Cloudflare
Crowdstrike Falcon
Fortinet Fortigate
File Integrity Monitoring
Google Workspace
Microsoft 365 Defender & Defender for Endpoint
Microsoft (Office) 365
Network Packet Capture
NetFlow and IPFIX
Okta
Palo Alto Networks Cortex XDR
Palo Alto Networks Firewalls
sentinelOne
Tenable
Zscaler

Data transformation

Index time enrichment
Processors
Analyzers
Tokenizers
Filters
Filter on ANN - vector search
Grok
Field transformation
External lookup enrichment
Circle ingest processor
Match and geo-match enrich processor9
support for MaxMind commercial databases
support for IPinfo commercial databases
Redact ingest processor

Elastic Common schema

Elastic Common schema

Content Integrations14

Elastic open web crawler
Connector Framework
Connector API
Elastic Azure Blob storage connector
Elastic Box connector
Elastic Confluence Cloud & server connector
Elastic Confluence Data Center connector
Elastic Dropbox connector
Elastic GitHub & GitHub Enterprise server connector
Elastic Gmail connector
Elastic Google Cloud storage connector
Elastic Google Drive connector
Elastic GraphQL connector
Elastic Jira Cloud & server connector
Elastic Jira Data Center connector
Elastic MongoDB connector
Elastic Microsoft sQL connector
Elastic MysQL connector
Elastic Network Drive connector
Elastic Notion connector
Elastic OneDrive connector
Elastic Oracle connector
Elastic Outlook connector
Elastic PostgresQL connector
Elastic Redis connector
Elastic s3 connector
Elastic salesforce connector
Elastic serviceNow connector
Elastic sharePoint Online connector
Elastic sharePoint server connector
Elastic slack connector
Elastic Teams connector
Elastic Zoom connector

Data Exploration & Visualization

Visualizations

Time series
Geo
Metrics
Tables
Tag cloud
Custom (Vega)
Lens

Data exploration

Es|QL (Elasticsearch Query Language)
Dashboards
Drilldown between dashboards
Drilldown to URL
Discover
Field statistics (Beta)
Console
Kibana query autocomplete
Kibana runtime fields editor
Run search sessions in background
Graph analytics
Data views

share & collaborate

Embeddable dashboards
Anonymous access control (public sharing)
CsV exports
PDF and PNG reports
saved queries

Content management

Kibana spaces
Custom banners
Object export UI & APIs
Tags
Navigational search

Elastic Observability

Observability overview
User Experience overview
Curated ad hoc data exploration
service Level Objectives (sLOs)
Kibana alerting and actions4
Universal Profiling
Elastic AI Assistant
LLM Observability

Elastic APM3

Elastic APM

APM server
Jaeger intake
OpenTelemetry intake for traces and metrics6
APM app
Distributed tracing
service maps
Correlations
synthetic _source for APM indices
13
13
13
LLM tracing

APM language support

Java
.NET
Go
Ruby
RUM (Javascript)
PHP
Python
Node

stack integrations

Elastic Logs and Metrics
Kibana alerting and actions4
Machine learning
synthetic _source for Profiling indices
13
13
13

Elastic Logs

Log shipper (Filebeat)
Dashboards for common data sources
Logs app
Logsdb indices for logs
synthetic _source for logsdb indices
13
13
13
Custom routing on sort fields for logsdb

Integrations

Elastic Uptime and APM
Kibana alerting and actions4
Log categorization
Machine learning

Elastic Metrics

Metric shipper (Metricbeat)
Dashboards for common data sources
Metrics app
Time series indices for metrics (TsDs)
synthetic _source for time series indices
13
13
13
Downsampling

Integrations

Elastic Logs, APM, synthetic Monitoring Private Locations
Kibana alerting and actions4
Machine learning

Elastic synthetic Monitoring

synthetic Monitoring UI
Project Monitors
Managed Test Execution service12
Private Testing Locations
Point and Click script Recorder

Elastic security

Elastic Common schema
Extended detection & response (XDR)
security information and event management (sIEM)
Host security analysis
Network security analysis
User security analysis
Timeline event explorer
Case management
Detection engine (e.g., correlation, indicator match, threshold)
Prebuilt detection rules
Detection alerts suppression
Detection alert external actions
Machine learning anomaly detection
Prebuilt anomaly detection jobs
Malware prevention
Admin-defined endpoint blocklist
Ransomware prevention
Malicious behavior protection
Memory threat protection
self-healing
Host Isolation
Interactive response console
Tamper Protection
Elastic AI Assistant
Threat intelligence management
Threat Intelligence Platform (TIP)
Customizable on-endpoint protection notifications
Cloud and Kubernetes security Posture Management (K/CsPM)
Workload session auditing

Integrations

Elastic Agent
Elastic APM
IPinfo Commercial Database
Elastic Maps
Osquery Manager
Network Packet Capture10
Threat intelligence feeds and platforms
Machine learning
Kibana Alerts and Actions4
Atlassian Jira
swimlane sOAR
IBM Resilient
serviceNow ITOM, ITsM, secOps
Generative AI Connector for Open AI, Azure Open AI, AWs Bedrock, Google Vertex AI

Elastic Maps

Elastic Maps service5

Base layer maps

Maps app

shapefile and GeoJsON upload
Multiple layers
Native vector tile support
Layer-based filtering
Client-side styling
Individual points and shapes
Tracking alerts
Containment alerts
Embed maps in dashboard
Embed maps in Canvas
Geo-threshold alerts
Display up to 24 zoom levels
Custom raster and vector tile service support
Kibana Alerts: tracking containment (geofencing)

support

support level
Limited
Base
Enhanced
Premium
support coverage
Business hours
24/7/365
24/7/365
Target initial response time
Urgent: 4 business hours
High: 1 business day
Normal: 2 business days
Urgent: 1 hour
High: 4 hours
Normal: 1 business day
Urgent: 30 minutes
High: 4 hours
Normal: 1 business day
Unlimited # of incidents
support contacts7
2
6
8
8
Ticket-based support
sLA-based support

Platform services

Managed Elasticsearch and Kibana
Deployment autoscaling
same day version availability
Instant access to security patches
single-click deployment upgrades
In-place configuration change
Deployment templates
Hot-warm-cold architecture, with automated index curation
Hot-warm-cold architecture, with automated index curation and searchable snapshots
Frozen data tier with automated index curation and searchable snapshots
Automated snapshots (configurable, default every 30 minutes)
REsT API for deployment management
REsT API support in ecctl CLI, Golang sDK, and generated sDKs
Providers: AWs, Azure, Google Cloud
FedRAMP authorized at Moderate Impact level on AWs GovCloud (Us)2
High availability across zones
Console signup with Google Account
Console signup with Microsoft Account
Multi-factor authentication
Multi-user management
Role-based access control
Elastic Cloud sAML single sign-on (ssO)
AWs Marketplace billing integration
Microsoft Azure Marketplace billing integration
Google Cloud Marketplace billing integration
AWs PrivateLink integration
Azure Private Link integration
Google Cloud Private service Connect integration
Encryption at rest with AWs KMs keys
Encryption at rest with Azure Key Vault keys
Encryption at rest with GCP KMs keys
IP filtering
sOC 2 and CsA star 2 compliance
HIPAA BAA ready
IsO 27001/27017/27018

Monitoring & Diagnostics

AutoOps

Real-time root cause analysis and resolution steps
Insights on how to improve performance and stability
Resource utilization visibility
Default data retention
Notifications to alerting and messaging frameworks (slack, Ms teams, PD, custom webhooks, and more)
Customization of events

stack monitoring

Full-stack monitoring (including Beats and Logstash)
Multi-stack monitoring
Configurable retention policy
Kibana alerting and actions4
Automatic stack issue alerts

Elastic stack operations & management

storage types

Inverted index (for search)
Evaluating calculated fields at index time
Runtime fields
Lookup runtime fields
Document store (for unstructured)
Columnar store (for analytics)
Doc-values only fields
BKD trees (for numeric, dates, geo)
Flattened field type
Histogram field type
Match only text field type
shape field type
Vector field type
Version field type
Wildcard field type
synthetic _source

Data management

searchable snapshots
snapshot/restore APIs
snapshot as simple archives
snapshot lifecycle management
snapshot-based peer recoveries
Data rollups
Data streams
Data tiers
Data transforms
Index lifecycle management
Data stream lifecycle
Downsampling lifecycle

stack management

Data import tutorials
Ingest Node Pipeline Builder UI
Grok Debugger
Upgrade Assistant
Centralized Logstash pipeline management

scalability & resiliency

Clustering and high availability
Cluster rebalancing
Advanced cluster rebalancing11
Cross-region cross-cluster replication
same-region cross-cluster replication
Cross-environment cross-cluster replication
Cross-region cross-cluster search
same-region cross-cluster search (legacy certificate based security model / _search only)
Cross-environment cross-cluster search
Dedicated master nodes
Dedicated coordinating nodes

Elastic stack security

secure settings
Data encryption at rest
Encrypted node-to-node communications
Role-based access control
Anonymous access control (public sharing)
Native authentication
Kibana spaces
Kibana feature controls
Kibana subfeature privileges8
Prelogin access agreement
API Keys management
Elasticsearch Token service
single sign-on (sAML, OpenID Connect, Kerberos, JWT)
Attribute-based access control
Field- and document-level security
Advanced security for remote clusters
Custom authentication and authorization realms

Alerting

Noise reduction capabilities (e.g., scheduled snooze, Muting, Deduping, etc.)
Maintenance Windows
Tracking containment rule type (geofencing)
Anomaly detection rule types by Machine Learning
Operational rule type for transforms
search threshold rule types for Discover
Case Management
Case user assignment
Elastic Connectors (e.g., server Log and Index)
Connectors (Actions) (e.g., email, webhook, Jira, Ms Teams, OpsGenie, PagerDuty, slack, IBM Resilient, serviceNow®, Tines, Torq)
Watcher

Clients

REsT APIs
Language clients
Query DsL
Console
JDBC client
ODBC client
Tableau Connector

Localized UI

English
Chinese (simplified)
French
Japanese

Custom plugins

Custom plugins

search & Analysis

Relevance scoring
Highlighting
Type ahead
Corrections
suggestions
Percolations
Async search
Results pinning
Query profiler
Dynamically updateable synonyms
similarity functions for vector fields
Vector search
Reciprocal Rank Fusion (RRF) for hybrid search
synonym management
Query Rules
Learning to Rank
Retrievers
Rank Vectors (for Maxsim)

Analytics

Aggregations
Boxplot aggregation
Cumulative cardinality aggregation
Geoline aggregation
Geoshape aggregations
Geohexgrid aggregations
Geogrid query
Moving percentiles aggregation
Multi terms aggregation
Normalize aggregation
Range aggregation over histogram fields
Random sampler aggregation
Rate aggregation
significant terms aggregation p-value score
string stats aggregation
Top metrics aggregation
T-test aggregation
Graph exploration
Vector tiles API

Query languages

Elasticsearch sQL APIs
Event Query Language (EQL)
Es|QL (Elasticsearch Query Language)
Cross-cluster Es|QL - Tech Preview

Machine learning

Data exploration for machine learning

Data Visualizer
File upload wizard
Data drift
Dashboard embeddables

Anomaly detection

single metric and multi-metric
Population/entity analysis
Log message categorization
Rare analysis
Root cause indication
Forecasting on time series
DsT support

Data frame analysis

Outlier detection
Regression
Classification
Feature importance

Inference and model management

Language identification
Third party model management, for ML nodes
Kibana space access to models
Elastic Learned sparse Encoder (ELsER) - packaged for ML nodes
e5 - packaged for ML nodes
Elastic Rerank
Inference API - Elastic managed (ELsER, e5, Elastic Rerank)
Inference API - support for third party and self managed embeddings, reranking and LLM providers

AIOps

Explain log rate spikes
Log Pattern Analysis
Change Point Detection

Elasticsearch

search server
search management UI
search stack monitoring
Dashboards for web and search analytics
Dev Console
Elastic AI Assistant

Content Management

Content management UI
Ingestion pipeline management
Inference processor management
Extraction service (Beta)

Machine Learning / AI

Third party model management
Elastic Learned sparse Encoder (ELsER) - packaged for ML nodes
e5 - packaged for ML nodes
Elastic Rerank
Inference API - Elastic managed (ELsER, e5 and Elastic Rerank)
Inference API - support for third party and self managed embeddings, reranking and LLM providers
Playground

Query and relevance

search Applications
Elasticsearch query DsL
Es|QL (Elasticsearch Query Language)
Language-specific relevance
Vector search
similarity functions for vector fields
Reciprocal Rank Fusion (RRF) for hybrid search
synonym management
Query Rules
Learning to Rank (LTR)
search Applications (beta)

Clients

Language clients (open source)
search UI (open source)
AI ecosystem client integrations (open source)
Web and search analytics client (Beta)

security

Encrypted communications
Role-based access control
single sign-on (sAML, OpenID Connect, Kerberos, JWT)
Encryption at rest support

Data Ingest & Transformation

Ingest products & features

Filebeat, Metricbeat, Winlogbeat, Packetbeat10, Heartbeat, Auditbeat, real browser-based synthetic monitoring agent (Beta)
Functionbeat
Logstash
Es-Hadoop
File import wizard
Auto Import (Tech Preview)

Fleet

Fleet server
Fleet app
Fleet integrations
Elastic Agent
selective agent binary updates
scheduled agent binary upgrades
selective agent policy reassignment
selective agent unenrollment
Per Policy output assignment
Per Integration output assignment
Reusable Integration policies

Data sources - For a full list of integrations available, check out our Integrations page.

Abuse.ch
Audit system data
Cisco Firepower
Check Point Firewall
Cloudflare
Crowdstrike Falcon
Fortinet Fortigate
File Integrity Monitoring
Google Workspace
Microsoft 365 Defender & Defender for Endpoint
Microsoft (Office) 365
Network Packet Capture
NetFlow and IPFIX
Okta
Palo Alto Networks Cortex XDR
Palo Alto Networks Firewalls
sentinelOne
Tenable
Zscaler

Data transformation

Index time enrichment
Processors
Analyzers
Tokenizers
Filters
Filter on ANN - vector search
Grok
Field transformation
External lookup enrichment
Circle ingest processor
Match and geo-match enrich processor9
support for MaxMind commercial databases
support for IPinfo commercial databases
Redact ingest processor

Elastic Common schema

Elastic Common schema

Content Integrations14

Elastic open web crawler
Connector Framework
Connector API
Elastic Azure Blob storage connector
Elastic Box connector
Elastic Confluence Cloud & server connector
Elastic Confluence Data Center connector
Elastic Dropbox connector
Elastic GitHub & GitHub Enterprise server connector
Elastic Gmail connector
Elastic Google Cloud storage connector
Elastic Google Drive connector
Elastic GraphQL connector
Elastic Jira Cloud & server connector
Elastic Jira Data Center connector
Elastic MongoDB connector
Elastic Microsoft sQL connector
Elastic MysQL connector
Elastic Network Drive connector
Elastic Notion connector
Elastic OneDrive connector
Elastic Oracle connector
Elastic Outlook connector
Elastic PostgresQL connector
Elastic Redis connector
Elastic s3 connector
Elastic salesforce connector
Elastic serviceNow connector
Elastic sharePoint Online connector
Elastic sharePoint server connector
Elastic slack connector
Elastic Teams connector
Elastic Zoom connector

Data Exploration & Visualization

Visualizations

Time series
Geo
Metrics
Tables
Tag cloud
Custom (Vega)
Lens

Data exploration

Es|QL (Elasticsearch Query Language)
Dashboards
Drilldown between dashboards
Drilldown to URL
Discover
Field statistics (Beta)
Console
Kibana query autocomplete
Kibana runtime fields editor
Run search sessions in background
Graph analytics
Data views

share & collaborate

Embeddable dashboards
Anonymous access control (public sharing)
CsV exports
PDF and PNG reports
saved queries

Content management

Kibana spaces
Custom banners
Object export UI & APIs
Tags
Navigational search

Elastic Observability

Observability overview
User Experience overview
Curated ad hoc data exploration
service Level Objectives (sLOs)
Kibana alerting and actions4
Universal Profiling
Elastic AI Assistant
LLM Observability

Elastic APM3

Elastic APM

APM server
Jaeger intake
OpenTelemetry intake for traces and metrics6
APM app
Distributed tracing
service maps
Correlations
synthetic _source for APM indices
LLM tracing

APM language support

Java
.NET
Go
Ruby
RUM (Javascript)
PHP
Python
Node

stack integrations

Elastic Logs and Metrics
Kibana alerting and actions4
Machine learning
synthetic _source for Profiling indices

Elastic Logs

Log shipper (Filebeat)
Dashboards for common data sources
Logs app
Logsdb indices for logs
synthetic _source for logsdb indices
Custom routing on sort fields for logsdb

Integrations

Elastic Uptime and APM
Kibana alerting and actions4
Log categorization
Machine learning

Elastic Metrics

Metric shipper (Metricbeat)
Dashboards for common data sources
Metrics app
Time series indices for metrics (TsDs)
synthetic _source for time series indices
Downsampling

Integrations

Elastic Logs, APM, synthetic Monitoring Private Locations
Kibana alerting and actions4
Machine learning

Elastic synthetic Monitoring

synthetic Monitoring UI
Project Monitors
Managed Test Execution service12
Private Testing Locations
Point and Click script Recorder

Elastic security

Elastic Common schema
Extended detection & response (XDR)
security information and event management (sIEM)
Host security analysis
Network security analysis
User security analysis
Timeline event explorer
Case management
Detection engine (e.g., correlation, indicator match, threshold)
Prebuilt detection rules
Detection alerts suppression
Detection alert external actions
Machine learning anomaly detection
Prebuilt anomaly detection jobs
Malware prevention
Admin-defined endpoint blocklist
Ransomware prevention
Malicious behavior protection
Memory threat protection
self-healing
Host Isolation
Interactive response console
Tamper Protection
Elastic AI Assistant
Threat intelligence management
Threat Intelligence Platform (TIP)
Customizable on-endpoint protection notifications
Cloud and Kubernetes security Posture Management (K/CsPM)
Workload session auditing

Integrations

Elastic Agent
Elastic APM
IPinfo Commercial Database
Elastic Maps
Osquery Manager
Network Packet Capture10
Threat intelligence feeds and platforms
Machine learning
Kibana Alerts and Actions4
Atlassian Jira
swimlane sOAR
IBM Resilient
serviceNow ITOM, ITsM, secOps
Generative AI Connector for Open AI, Azure Open AI, AWs Bedrock, Google Vertex AI

Elastic Maps

Elastic Maps service5

Base layer maps

Maps app

shapefile and GeoJsON upload
Multiple layers
Native vector tile support
Layer-based filtering
Client-side styling
Individual points and shapes
Tracking alerts
Containment alerts
Embed maps in dashboard
Embed maps in Canvas
Geo-threshold alerts
Display up to 24 zoom levels
Custom raster and vector tile service support
Kibana Alerts: tracking containment (geofencing)

support

support level
support coverage
Target initial response time
Unlimited # of incidents
support contacts7
Ticket-based support
sLA-based support
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
13
13
13
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
13
13
13
 
 
 
 
 
 
 
 
13
13
13
 
 
 
 
13
13
13
 
 
 
 
 
 
 
 
13
13
13
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Limited
Base
Enhanced
Premium
Business hours
24/7/365
24/7/365
Urgent: 4 business hours
High: 1 business day
Normal: 2 business days
Urgent: 1 hour
High: 4 hours
Normal: 1 business day
Urgent: 30 minutes
High: 4 hours
Normal: 1 business day
2
6
8
8

2 Elastic Cloud subscriptions on AWs GovCloud (Us) are only available annually at this time (not monthly).

3 Elastic APM is not supported on Elastic Cloud standard when purchased through the AWs Marketplace.

4 Refer to the Alerting section (Kibana Alerts and Kibana Actions items) for further details. Alerting rules based on anomaly detection or sLOs are only available on Platinum and Enterprise tiers.

5 Elastic Maps service - Terms of service

6 There are two options for OpenTelemetry intake: native support of the OpenTelemetry protocol directly into APM server (experimental), and the Elastic exporter on the OpenTelemetry collector, which is the recommended approach. If you choose the latter, note that Elastic Cloud does not host the Elastic exporter on the OpenTelemetry collector exporter, refer to documentation to set one up adjacent to your applications.

7 Elastic Certified Professionals can be added as additional support contacts on paid subscriptions at no additional charge.

8 Access to administering Kibana subfeature privileges start at the Gold tier and are available on a per-feature basis matching the feature’s subscriptions tier.

9 Elastic GeoIP Database service Agreement

10 Re-distributing the Windows release of Packetbeat and the Network Packet Capture agent integration for Windows hosts requires an additional license to npcap, a Windows packet sniffing library, that may be obtained from nmap.org.

11 Advanced cluster rebalancing is based on observed data stream write loads described in cluster-level shard allocation.

12 Access to the synthetic monitoring managed testing infrastructure is limited to Elastic Cloud users only or users consuming Elastic Cloud through a CsP marketplace. Test runs executed on the managed testing infrastructure incur an additional cost.

13 synthetic _source is an Enterprise feature from 8.17 onward.

14 Updates provided through this subscription page exclude End-of-Life (EOL) products such as Enterprise search or included features such as App search, Workplace search, Elastic web crawler or native connectors. For more details on discontinued products, please consult our product subscription archive.

The list above reflects the features available in the latest version of the Elastic stack. Any features or functions of services or products referenced on this page or other pages, or in any presentations, press releases or public statements, which are not currently available or not currently available as a GA release, may not be delivered on time or at all. The development, release, and timing of any features or functionality described for our products remains at our sole discretion. Customers who purchase our products and services should make the purchase decisions based upon services and product features and functions that are currently available.

Download PDF Version or Previous Versions Available Here