Elastic is the outlier among scaled security vendors because it is not primarily a security vendor. It is a search company whose technology proved unusually well suited to storing and querying the enormous volumes of log data that modern security monitoring generates, and which built a security business on top of that capability. The same engine powers an observability business and, since the arrival of generative AI, a claim to be the retrieval layer beneath enterprise AI applications. Revenue reached $1.739bn in the financial year to April 2026 and is guided to approximately $2.0bn for the current year, with growth settling in the mid-teens after several years of deceleration.
The investment case rests on whether a platform that is credible in three markets can be dominant in any of them, and whether the AI retrieval story converts into revenue rather than customer counts. If it succeeds, Elastic becomes the default data layer beneath search, monitoring and security operations, with economics that improve as one engine serves more workloads. If it fails, it remains a well-engineered mid-teens-growth infrastructure company holding respectable second and third positions in three markets each dominated by a specialist.
The franchise
Elastic began in 2010 with Elasticsearch, an open-source distributed search and analytics engine built on Apache Lucene. Its significance was operational rather than theoretical: it made full-text search across very large and untidy datasets fast, horizontally scalable and approachable for ordinary developers. Combined with Logstash for ingestion and Kibana for visualisation it became the ELK stack, and for most of the 2010s it was the default answer whenever an engineering team needed to search or analyse a large volume of log data.
That origin produced a franchise of a particular kind. Elastic did not sell its way into enterprises; it was adopted by developers and commercialised afterwards. Cumulative downloads run to billions, and the company reports that roughly 17% of professional developers use Elasticsearch. The commercial estate now stands at approximately 24,000 subscription customers, of which more than 1,800 spend at least $100,000 a year and more than 240 spend over $1m. That larger cohort accounts for 90% of what the company calls sales-led subscription revenue, up from 87% a year earlier, so the business is concentrating upmarket while the developer base underneath it continues to generate new demand.
The strategic consequence of a search engine at the centre is that Elastic can enter adjacent markets cheaply. Logs, metrics, traces, security telemetry and, more recently, vector embeddings are all data to be indexed and queried. That is why a single company competes with Datadog, with Splunk, with Microsoft and with a set of specialist vector databases simultaneously. Whether this constitutes leverage or dilution is the oldest argument about Elastic and it remains unresolved.
Business model
Revenue is almost entirely subscription. Professional services account for 6% and function as a delivery cost rather than a business. The subscription base divides by how the software is run. Elastic Cloud, the managed service available on the major cloud platforms, produced $235.2m in the July quarter and represents 49% of revenue; the remainder is self-managed software licensed to customers running their own clusters. Elastic is one of relatively few vendors at this scale that genuinely supports both, which matters in regulated industries, government and air-gapped environments where a managed service is not permitted.
Within cloud, a newer disclosure repays attention. Annual Elastic Cloud, meaning committed contracts, grew 27% to $185.0m in the July quarter. Monthly Elastic Cloud, the self-serve book used by smaller customers, grew 1% to $50.2m and has been broadly flat for some time. Management now foregrounds a measure called sales-led subscription revenue, which is total subscription revenue with the monthly line removed, and reports it growing 18%. The construct is defensible, since the two books behave differently and are sold differently, but it also excludes the slowest-growing part of the business, and should be read with that in mind.
Consumption is the underlying economic driver. Customers commit to a capacity and draw it down, so revenue follows data volume, retention periods and query activity rather than seat counts. This makes Elastic a beneficiary of data growth and a hostage to customer cost discipline, because when budgets tighten the first response is to retain less data for a shorter period, which reduces consumption without cancelling anything.
Profitability has improved substantially and consistently. Non-GAAP operating margin moved from breakeven in the year to April 2022 through 4%, 11% and 15% to 16.4% in FY2026, with approximately 19.4% guided for the current year. Adjusted free cash flow was $345.5m in FY2026, a 20% margin. The balance sheet holds $1.461bn of cash and securities against $575m of 4.125% notes due 2029, leaving roughly $886m of net cash, and the company has been repurchasing stock, including approximately $340m during FY2026.
Search and AI: the origin and the vector claim
The original business is enterprise search: making an organisation’s own documents, catalogues, tickets and records findable. It remains a substantial and durable market, and Elastic was placed a leader in industry research evaluation of cognitive search platforms in late 2025.
Generative AI changed the pitch. Large language models are trained on general data and cannot answer questions about a specific company’s internal information. The prevailing solution, retrieval-augmented generation, retrieves relevant passages from a private corpus and supplies them to the model as context. Retrieval quality therefore determines answer quality, and retrieval requires a store capable of semantic rather than keyword matching, which means vector search: representing text as numerical embeddings and finding the nearest matches in that space.
Elastic’s argument is that this is search, that it has been doing search at enterprise scale for fifteen years, and that a specialist vector database solves only part of a problem which in practice requires keyword matching, filtering, permissions, aggregation and vector similarity in the same query. It has added a dedicated vector index mode, acquired Jina AI in October 2025 for embedding and reranking models, and released an agent builder together with support for the emerging Model Context Protocol. The chief executive has described hybrid retrieval as the decisive differentiator in competitive evaluations.
The disclosed adoption is real and improving. AI use cases now reach 37% of the customers spending over $100,000 a year, roughly 670 accounts, against about 21% a year earlier. What has never been disclosed is a single dollar of AI-attributable revenue. Every metric the company publishes on this subject is a customer count or a penetration rate, and the gap between the two is precisely where the argument sits.
Observability: the largest and most contested business
Observability is the monitoring of software systems through logs, metrics and traces, and it is the natural extension of a log search engine. Elastic has been a leader in industry research observability quadrant for three consecutive years, most recently in June 2026, which is the strongest external validation the company holds in any category.
It is also the most competitive of the three. Datadog is the category leader and sells a polished, opinionated product to buyers who value not operating infrastructure. Splunk, now inside Cisco, holds the largest incumbent log estate. Grafana has captured much of the open-source constituency Elastic once owned by default. Elastic competes on cost at volume and on the argument that monitoring data and security data are the same data and should not be stored twice.
The most recent product work targets exactly this. A columnar storage mode for metrics reduces storage to approximately 3 bytes per sample against double-digit requirements previously, cutting cost by around 20%, and native ingestion of the Prometheus format with its query language allows teams to migrate without retraining. Management conceded on the August call that adoption of the new metrics capability is early and offered no adoption figures, which is the appropriate level of scepticism to apply.
Elastic Security: SIEM, XDR and the undisclosed number
Elastic Security is what brings the company onto a cybersecurity site, and it is genuinely substantial in capability. It combines security information and event management, which is the collection and correlation of security telemetry from across an estate, with extended detection and response, endpoint protection, cloud security and, following the acquisition of Keep in 2025, native orchestration and automated response. The company describes it as an agentic security operations platform.
The architectural argument is coherent. A SIEM is fundamentally a very large log store with detection logic on top, which is what Elasticsearch already is. An organisation already running Elastic for observability can add security detections against telemetry it is collecting anyway, avoiding the duplicate ingestion and duplicate storage that separate observability and security platforms require. In a market where SIEM costs are driven by data volume and have risen faster than security budgets, that is a real commercial argument, and it is the basis on which Elastic has pursued Splunk’s installed base through a migration programme offering credits and automated import tooling since 2024.
The evidence that it works is genuine but almost entirely supplied by management. Elastic won a place on the CISA security-information-and-event-management-as-a-service programme in December 2025 through prime contractor ECS, a $26m base contract with options to $130m, consolidating telemetry across federal civilian agencies; management stated in May 2026 that the base commitment had already been exceeded. It has since achieved FedRAMP High authorisation. Reported wins include an eight-figure consolidation at a Fortune 50 financial institution and a public sector displacement completed in under a month. No win rates, no competitive loss data and no results from the Splunk migration programme have ever been published.
The external assessment is more measured than the company’s own framing. Elastic was named a leader in industry research security analytics evaluation in 2025 and in industry research SIEM assessment in June 2026. But in industry research SIEM quadrant of October 2025 it was placed a visionary rather than a leader, and in industry research extended detection and response evaluation of June 2026 it was a strong performer rather than a leader. The pattern is consistent: Elastic is a leader in observability and search, and a credible but second-tier presence in the security rankings that security buyers watch most closely.
Which returns to the number that does not exist. Management called security growth outstanding in the quarter to April 2026 and highlighted it again in August, but when asked directly on the August call what proportion of revenue security represents, the chief financial officer said the company does not disclose it. For a business repeatedly described as a growth driver, that is a conspicuous omission, and any assessment of Elastic as a security investment has to be made without it.
The licensing war and OpenSearch
In January 2021 Elastic moved Elasticsearch and Kibana off the Apache 2.0 licence to a dual arrangement under the Server Side Public License and its own proprietary licence, stating that the change was aimed at Amazon Web Services, which had been selling a managed Elasticsearch service without contributing to it. Within three months AWS forked the last Apache-licensed release and created OpenSearch.
The fork did not fail. OpenSearch passed a billion downloads, and in September 2024 AWS transferred it to the Linux Foundation under neutral governance with SAP and Uber as founding members alongside a commercial ecosystem that includes Aiven, NetApp and, relevant to security specifically, the open-source detection platform Wazuh. Elastic itself changed course in August 2024, adding the AGPL as a third licence option, and signed a five-year strategic collaboration agreement with AWS in May 2025.
What that episode cost cannot be established from public sources, and this profile will not pretend otherwise. Neither Amazon nor Elastic quantifies OpenSearch’s revenue, share or customer displacement. Elastic’s growth did decelerate sharply in the years following the licence change, from 42% in FY2022 to 24% in FY2023 and 19% in FY2024, but that period coincided exactly with the broader contraction in software spending after the end of zero interest rates, and the company’s own commentary at the time cited the demand environment. The correlation is real; the causation is not demonstrated. What can be said is that the confrontation ended in accommodation, that a durable and well-funded alternative now exists permanently at the free end of the market, and that Elastic’s licence changes were reversed far enough to suggest the strategy did not produce what was intended.
The moat
Elastic’s moat is the engine and the position it occupies in customer architecture. Elasticsearch is genuinely difficult to replicate at scale: distributed indexing, sharding, replication and query performance across petabyte estates represent fifteen years of engineering, and the operational knowledge accumulated by the customers running it is a switching cost in its own right. Query languages, index mappings, dashboards, ingestion pipelines and detection rules all become embedded in daily work.
The second element is breadth of deployment. Elastic runs as a managed service on all three major clouds and as self-managed software in data centres and air-gapped environments, which very few competitors match. This is why federal, defence and regulated customers reach it, and FedRAMP High authorisation converts that capability into addressable procurement.
The third is the developer base. Adoption starts below the procurement process, which lowers customer acquisition cost and seeds accounts years before they are sold to. Billions of downloads produce a supply of engineers who already know the technology, which is a hiring argument customers make to themselves.
The limits are equally clear. Elastic is not the leader in any of its three markets. Datadog is larger and growing faster in observability; Microsoft, Splunk and CrowdStrike are ahead in the SIEM rankings that matter to security buyers; and search is being contested by both specialist vector databases and the cloud providers’ own retrieval services. A free, credibly governed fork of the core technology exists and caps pricing at the low end. Net expansion of 111% is respectable but not the mark of a product customers cannot help expanding on. And a company generating roughly $2bn of revenue is funding research across three fronts against competitors who concentrate the same or greater resources on one.
Competitive landscape
Elastic fights three separate wars, which is the central difficulty in assessing it. The security contest is the one that matters here, and it turns on whether an organisation would rather buy a purpose-built security platform or run detection on the data platform it already operates.
| Competitor | Where it is strongest | Elastic advantage | Elastic vulnerability |
|---|---|---|---|
| Splunk (Cisco) | The largest incumbent SIEM estate and deep enterprise entrenchment | Materially lower cost at high data volumes; migration tooling and credits aimed directly at that base | Cisco can bundle across networking and security; switching a SIEM is slow and rarely urgent |
| Microsoft Sentinel | Identity, endpoint and cloud telemetry plus enterprise licence bundling | Independent of any single cloud, and runs self-managed where Sentinel cannot | Arrives inside agreements the customer has already signed, at an incremental price hard to beat |
| CrowdStrike Falcon Next-Gen SIEM | Endpoint control point, threat intelligence and an index-free store with fast hot retention | Broader ingestion ecosystem, mature integrations, and observability on the same data | Positions explicitly as an Elastic replacement and can attach to an agent already deployed |
| Palo Alto Networks XSIAM | Automation-first security operations tied to a broad platform | Simpler data economics and no requirement to adopt a wider vendor stack | Consolidation pressure favours vendors selling the whole security estate at once |
| Datadog | Observability breadth, product polish and sales execution | Cost at volume, self-managed deployment and shared storage across monitoring and security | Datadog grows faster and is the default choice where operating infrastructure is unwelcome |
| OpenSearch and AWS | Free, Apache-licensed, Linux Foundation governance and AWS distribution | Proprietary features, security detections, support and a coherent product roadmap | Caps pricing at the low end and removes the entry-level tier from monetisation entirely |
The most consequential competitor is Microsoft, for the same reason it is consequential everywhere in security. Sentinel does not have to be better than Elastic Security; it has to be adequate and already paid for. Against that, Elastic’s answer is cost at high ingestion volumes and independence from any one cloud, which is a real argument in large hybrid estates and a weak one in organisations already standardised on a single vendor.
CrowdStrike is the competitor most often cited as displacing Elastic, and it markets Falcon Next-Gen SIEM explicitly as a replacement, with an index-free architecture offering cheaper hot retention. The claim is genuine but narrower than it appears. It applies to security workloads, whereas Elastic customers frequently run observability on the same cluster, and a migration that solves the SIEM problem while leaving monitoring behind splits an estate rather than consolidating it. Coexistence, with Falcon telemetry ingested into Elastic, remains common. No public data establishes which way the balance is moving, and claims in either direction should be treated as marketing until win-loss evidence exists.
The investment debate
Elastic trades near $90 a share after closing at $89.58 on 2 September, giving a market capitalisation around $9.4bn and, against roughly $886m of net cash, an enterprise value near $8.5bn. That is approximately 4.3 times guided revenue for the year to April 2027. The range over the past twelve months has been extreme: a low of $42.05 in April 2026 and a high near $108 reached immediately after the August results.
The results on 27 August were the strongest print in two years. Revenue of $478.1m grew 15%, non-GAAP earnings of $0.70 beat a consensus near $0.58, the $100,000-plus customer cohort added more than 80 accounts in a single quarter for the first time, current remaining performance obligations grew 21%, adjusted free cash flow margin reached 30%, and full-year guidance was raised on revenue, margin and earnings. The shares rose 19.3% the following day.
The bull argument is that this is the inflection the company has been promising. Growth decelerated for four years as the post-pandemic software correction worked through a consumption model, and the August quarter is the first evidence of it turning. AI penetration of the large-customer base has gone from 21% to 37% in a year, which is the leading indicator of consumption on a platform where customers pay for what they use. Operating margin has expanded every year without exception, from breakeven to a guided 19.4%, demonstrating that the model produces leverage as it scales. The company holds net cash, generates a 20% free cash flow margin, is buying back stock, and by the standards of infrastructure software at mid-teens growth with expanding margins, a little over 4 times revenue is not a demanding multiple.
For a security-focused assessment the debate narrows further, and it narrows to a question that cannot currently be answered. Elastic Security may be a genuine SIEM contender taking share from Splunk on economics, or it may be a capable feature of an observability platform that wins where it is already installed and loses competitive evaluations to Microsoft and CrowdStrike. Management asserts the first. industry research and industry research place it closer to the second. Without segment disclosure, an outside observer cannot adjudicate between them, and should be honest about that rather than adopting whichever version suits the argument.
What to watch
Net expansion rate is the single most informative number. It has sat at 111% to 112% for roughly three years after falling from near 130%, and management expects it to improve within four quarters as constant-currency growth accelerates. If AI adoption genuinely drives consumption, this is where it must appear. If penetration keeps rising while net expansion does not, the AI narrative is a customer-count story rather than a revenue one.
Monthly Elastic Cloud is the second. It has been flat at around $50m while the committed book grows 27%, and management has been content to describe this as expected. A return to growth would indicate the self-serve funnel is working; continued flatness suggests the bottom of the market has been ceded, most plausibly to OpenSearch-based alternatives.
On security specifically: whether the company ever begins disclosing revenue by solution, which would transform the quality of any assessment; whether Elastic advances from visionary to leader in the industry research SIEM quadrant; whether the CISA programme continues to expand against its $130m ceiling and whether FedRAMP High converts into further federal awards; and whether any independent evidence emerges on win rates against Microsoft and CrowdStrike.
Finally, execution. Whether the guided 19.4% operating margin is delivered while growth holds, whether the reorganisation following the June restructuring and the departure of the chief product officer produces shipped capability from the Deductive AI and Jina acquisitions, and whether the company can report two consecutive quarters without the share price falling on the guidance that accompanies good results.
Bottom line
Elastic is a genuinely good piece of technology attached to a company that has spent four years being repriced from a hypergrowth story to an infrastructure one. The engineering is not in question and neither is the financial discipline: margins have expanded every year, cash generation is strong, the balance sheet holds net cash, and the August quarter was the first in some time to give the optimists something concrete.
The unresolved question is whether breadth is an advantage or the reason Elastic leads nothing. Being second or third in search, observability and security simultaneously is a defensible commercial position and a difficult investment case, because each market has a specialist willing to spend more to win it. For a security buyer the calculus is more favourable than for an investor: the argument that security telemetry and observability telemetry should live in one store, queried by one engine, is sound, and the cost advantage at high ingestion volumes is real.
What a reader should not accept from any source, including this one, is a confident claim about how large or how fast-growing Elastic Security is. The company does not disclose it, the sell side estimates only the search share, and the external analyst rankings place Elastic behind the security leaders while the company describes its security growth as outstanding. Until that disclosure changes, the security case rests on architecture and economics rather than on evidence.