# Elastic Security

> Open-source SIEM and EDR platform with behavioral detection, threat hunting, and automated response.

Elastic Security is an open-source SIEM and EDR platform from Elastic for threat detection, investigation, and incident response. It combines detection rules, behavioral analytics, and automated remediation in a single unified system available as cloud-hosted, self-managed, or hybrid deployment with a free tier and commercial support options. Listing updated 6 September 2026. Checked by MSP Software 5 September 2026.

- Page: https://mspsoftware.net/software/elastic-security
- Vendor: Elastic, https://mspsoftware.net/vendors/elastic, website https://www.elastic.co/security
- Categories: EDR and XDR (primary)
- Free trial: yes. Free version: yes.
- Deployment: cloud, on-premises and hybrid. Platforms: Windows, macOS, Linux and web. HQ: United States. Founded: 2011.
- Support: email, help desk, knowledge base, phone, 24/7 and community. Training: documentation, videos and webinars.

## From the vendor

Elastic Security is an agentic security operations platform from Elastic that unifies SIEM, XDR, endpoint detection and response, and cloud security into a single open-source platform. It detects threats through behavioral analytics, custom detection rules (over 1,300 publicly available on GitHub), machine learning-based anomaly detection, and entity analytics. Elastic Security suits MSPs and enterprises wanting a self-hosted or flexible-deployment alternative to vendor-locked SIEM solutions, with the flexibility to run across cloud, on-premises, and hybrid environments without vendor lock-in. The platform includes automated threat response through Elastic Workflows (eliminating the need for a separate SOAR system), threat hunting tools with interactive visualizations and entity-based investigation, and incident management capabilities through cases and timeline features. Elastic Security supports Windows, macOS, and Linux endpoints through the Elastic Agent. It integrates with cloud platforms (AWS, Azure, Google Cloud), Elasticsearch data sources, and third-party log ingestion through the open Elastic Stack, with a large library of pre-built connectors and APIs. MSPs can deploy Elastic Security three ways. For self-managed deployments, the open-source core is free to download and run on your own infrastructure, though it requires operational expertise to manage Elasticsearch infrastructure, backups, and updates. For cloud deployments, Elastic Cloud Serverless and Hosted options offer usage-based or resource-based pricing (checked September 2026), with managed infrastructure and support. All tiers include community support; commercial support tiers add email, help desk, knowledge base, phone, and 24/7 options. Elastic was founded in 2011 and is headquartered in Mountain View, California. MSPs should evaluate deployment complexity, confirm integration requirements with existing tools and log sources, and assess whether community support or commercial support tiers align with their operational model.

## Our take

Elastic Security stands out for being open-source with an optional managed cloud tier, which suits MSPs wanting escape from per-endpoint licensing. The unified SIEM, XDR, and SOAR capabilities reduce tool sprawl compared to single-function competitors, though operational overhead is higher if self-hosting. Confirm whether your team can manage Elasticsearch infrastructure or prefers the managed cloud option. Check integrations with your existing log sources and endpoint platforms. Cloud pricing is usage-based, so pilot with a small deployment first to forecast costs. Community support is available; 24/7 support requires a paid subscription.

## Pricing

Elastic Security does not publish a list price.

## Features

| Feature | Supported | Note |
| --- | --- | --- |
| Behavioural detection | yes | Machine learning-based anomaly detection and behavioral analytics built into the platform. |
| Automated remediation | yes | Elastic Workflows enables automated response automation and SOAR-like capabilities. |
| Threat hunting console | yes | Threat hunting console with interactive visualizations and entity analytics. |
| Managed MDR add-on | no | No managed MDR service add-on; platform is for self-managed or MSP-managed operations. |
| SIEM and SOAR integration | yes | SIEM and SOAR capabilities built into the platform; integrates third-party data sources. |
| macOS support | yes | macOS endpoints supported through Elastic Agent. |
| Linux support | yes | Linux endpoints supported through Elastic Agent. |

## Integrations

- Elasticsearch, https://www.elastic.co/elasticsearch
- AWS, https://www.elastic.co/guide/en/cloud/current/ec-aws-regions.html
- Microsoft Azure, https://www.elastic.co/guide/en/cloud/current/ec-azure-regions.html
- Google Cloud, https://www.elastic.co/guide/en/cloud/current/ec-gcp-regions.html
- Elastic Agent, https://www.elastic.co/guide/en/fleet/current/elastic-agent-installation.html

Listed products that integrate with Elastic Security: SentinelOne and UnderDefense MAXI.

## Alternatives

- Huntress: Managed detection and response for MSPs, priced per endpoint from $7.99 a month direct. https://mspsoftware.net/software/huntress. Compare: https://mspsoftware.net/compare/elastic-security-vs-huntress
- WatchGuard Endpoint Security: Endpoint protection and detection response for SMBs and MSPs, cloud-based, priced per endpoint on quote. https://mspsoftware.net/software/watchguard-epdr
- Todyl: A single agent bundling SASE, EDR, SIEM and MXDR, sold in three tiers priced on request. https://mspsoftware.net/software/todyl
- Microsoft Defender for Endpoint: Enterprise EDR bundled with Microsoft 365 E5, with multi-tenant management for MSPs via Lighthouse. https://mspsoftware.net/software/defender-for-endpoint. Compare: https://mspsoftware.net/compare/defender-for-endpoint-vs-elastic-security

## FAQ

### How much does Elastic Security cost?

Elastic Security does not publish a list price. No MSP price reports have been approved yet.

### Does Elastic Security offer a free trial?

Elastic Security offers a free trial. There is a genuinely free version.

### What does Elastic Security integrate with?

Elastic Security lists integrations with Elasticsearch, AWS, Microsoft Azure, Google Cloud and Elastic Agent.

### What integrates with Elastic Security?

SentinelOne and UnderDefense MAXI list an integration with Elastic Security.

### Is Elastic Security cloud or on-premises?

Elastic Security can be run in the cloud or on-premises. Elastic Security supports a hybrid deployment.

### Who is Elastic Security for?

MSPs report using Elastic Security at sizes of 6-15, 16-50, 51-200 and 200+ technicians.

### Is Elastic Security priced per endpoint or does it use a different model?

Elastic Security does not publish per-endpoint pricing. For cloud deployments (Elastic Cloud Serverless and Hosted), Elastic Security uses usage-based or resource-based pricing checked September 2026. For self-managed deployments, it uses license-based pricing. This contrasts with endpoint security products that charge per workstation or server. MSPs should pilot a deployment on Elastic Cloud to forecast usage costs before committing to production scale.

### Can I use Elastic Security with an open-source license?

Yes, Elastic Security's core is open-source and available for free when self-hosted. You can download, install, and run Elastic Security on your own infrastructure at no license cost. However, self-managed deployments require operational expertise to manage Elasticsearch infrastructure, backups, and updates. Commercial support, managed cloud hosting, and higher service levels require paid subscriptions with Elastic.

### Does Elastic Security offer a free trial?

Yes, Elastic Security offers a free trial. MSPs can start a trial on Elastic Cloud (Serverless or Hosted) without commitment to evaluate the platform hands-on. There is no separate free version once the trial period ends, though the open-source core remains available for self-managed deployment.

### What platforms can Elastic Security protect?

Elastic Security supports Windows, macOS, and Linux endpoints through the Elastic Agent. It can be deployed in cloud environments (AWS, Azure, Google Cloud), on-premises data centers, and hybrid configurations. The platform collects logs, metrics, and security telemetry from endpoints and forwards them to a centralized Elasticsearch instance for detection and response.

### Does Elastic Security include automated threat response or do I need a separate SOAR platform?

Elastic Security includes built-in automation through Elastic Workflows, which enables automated threat response and SOAR-like capabilities without requiring a separate platform. This includes automated alerting, case management, and custom response actions integrated into the detection pipeline. This reduces tool sprawl compared to solutions that require a separate SOAR platform.