Research Note · Elastic · Negotiation

Elastic pricing & negotiation.

Elastic Cloud tier choice moves total cost more than any discount you can negotiate — a 2.7x spread from Standard to Enterprise, before ingest volume enters the picture. This note maps the tier rates, ECK self-managed economics, the ELv2 / SSPL licensing history that sets your leverage, the discount bands by commit, and the four contract levers that move an Elastic deal beyond list.

By James Hill-WoodUpdated Apr 20228 min readData platform research cluster
Bottom line

Tier choice beats discount. Standard lists at $0.1144 per GB RAM/hour and Enterprise at $0.3104 — a 2.7x range that dwarfs the 8–35% you can negotiate. On high-ingest workloads the per-GB ingest charge, not compute, dominates the bill. The single largest lever is a costed OpenSearch BATNA.

01 Key findings

  1. Tier choice outweighs negotiated discount. Standard ($0.1144), Gold ($0.1696), Platinum ($0.2552) and Enterprise ($0.3104) per GB RAM/hour span a 2.7x range — a bigger lever than the 8–35% discount available at any commit level.

  2. Ingest volume, not cluster compute, drives the bill at scale. Above roughly 300 GB/day, per-GB ingest charges ($0.16–$0.50) dominate. Data tiering runs a well-managed estate 40–60% cheaper than the default hot-tier-everything pattern.

  3. Elastic protects ingest and discounts compute. The default vendor position discounts cluster compute while shielding ingest. Aligning ingest discount to cluster discount is the highest-frequency win in these deals.

  4. Licensing history sets your leverage. Buyers who can migrate to OpenSearch (Apache 2.0) hold real negotiating power; those locked to Elastic-only features (advanced ML, Cross-Cluster Search, Endpoint Security) should expect smaller discounts.

  5. ECK can undercut Elastic Cloud by 25–45%. For organisations with an existing Kubernetes platform, self-managed ECK is materially cheaper at equivalent scale — before counting operational overhead.

02 Elastic Cloud tier pricing

Elastic Cloud is the managed Elasticsearch and Kibana service from Elastic NV, sold on AWS, Azure and GCP. Pricing is per GB RAM per hour of running Elasticsearch nodes, plus per-GB storage, plus per-GB ingest for the Observability and Security solutions. Rates below are AWS US East.

TierPer GB RAM / hourKey features included
Standard$0.1144Core search, basic security, monitoring, alerting
Gold$0.1696Standard plus role-based access control, advanced alerting, machine-learning add-on
Platinum$0.2552Gold plus full ML, anomaly detection, cross-cluster replication, JDBC / ODBC drivers, Elastic Maps Service
Enterprise$0.3104Platinum plus searchable snapshots, frozen tier, FIPS-validated security, dedicated support

Cluster sizing is the first cost lever. A typical observability deployment runs 6–16 hot-tier nodes at 64 GB RAM each on Platinum, costing $63–$169 per hour for the hot tier alone. Warm and cold tiers add 30–80% on top; the frozen tier (searchable snapshots, Enterprise only) adds a further 5–15%. Storage is charged separately at $0.024–$0.10 per GB per month by class.

03 Data volume drivers

Since late 2024 Elastic Cloud charges Observability and Security on an ingest-volume basis on top of cluster pricing — a shift that caught many existing customers off guard at first renewal.

SolutionPricing unitRate
Observability ingestPer GB ingested$0.16–$0.40 by retention tier
Observability retentionPer GB stored / month$0.024 (frozen) to $0.10 (hot)
Security ingestPer GB ingested$0.20–$0.50
Security retentionPer GB stored / month$0.024 to $0.10
Machine LearningPer ML node hourFrom $0.1696 per GB RAM/hour (Gold) plus ML add-on fee
Endpoint SecurityPer endpoint / month$5.50 list (EDR, HIPS, behavioural detection)

For high-ingest observability (300 GB/day and above) the ingest charge typically dominates the bill, ahead of cluster compute. Two architectural moves recover the most spend: process logs at source with Logstash, Fluent Bit or Vector and drop low-signal fields before they reach Elastic (a fully parsed Apache access log carries 80–120 fields; production analysis usually needs 12–18, cutting storage 70–85%); and separate ingest and indexing nodes from search nodes, so each scales on its own pattern rather than sizing to peak-plus-peak (20–35% less total cluster RAM on high-ingest workloads).

The tier trap

Buying up-tier to solve a data-volume problem inflates the bill twice. The default hot-tier-everything pattern pays peak per-GB storage on data that should sit in warm, cold or frozen. Route raw logs to the frozen tier with searchable snapshots, summarised metrics to hot, and discard non-essential fields at ingest — a well-tiered estate runs 40–60% cheaper than the default, without changing tier.

04 ECK & self-managed Elastic

Elastic Cloud on Kubernetes (ECK) is the operator that runs Elasticsearch and Kibana on customer-managed clusters. The licence model is the same Elastic tiers (Basic, Gold, Platinum, Enterprise), sold as subscriptions per node or per Elastic Resource Unit (ERU). For customers with an existing Kubernetes platform, ECK can run 25–45% cheaper than Elastic Cloud at equivalent scale, before counting operational overhead.

The Basic tier is the source of the licensing controversy. Basic is free to run, including the proprietary security and alerting features added in 2018 — but it is not open-source software. That distinction is what sets your negotiating position, covered next.

05 Licensing & the OpenSearch BATNA

In early 2021 Elastic re-licensed the previously Apache 2.0 components under the Server Side Public License (SSPL) and the Elastic License v2 (ELv2). ELv2 prohibits offering Elastic as a managed service competitive with Elastic Cloud; SSPL requires anyone offering the software as a service to release the entire service stack under SSPL. Neither is OSI-approved as open source. The pre-2021 codebase forked into OpenSearch, the AWS-led project that remains on Apache 2.0.

Three implications for an enterprise buyer. First, AWS OpenSearch Service runs the fork on Apache 2.0, giving multi-cloud or managed-alternative buyers a viable option. Second, many features added since 2021 (the new APM agent shape, advanced ML, Endpoint Security) are Elastic-only, so migration parity means accepting feature loss. Third, in late 2024 Elastic restored an AGPL v3 option for the core ES and Kibana code, partially walking back the 2021 position — relevant for self-hosting, but it does not change the managed-service competitive picture.

Leverage test

The licensing decision that shapes negotiating power: customers willing to migrate to OpenSearch (Apache 2.0, fully open source, AWS-managed available) hold meaningful leverage in Elastic discussions. Customers locked into ELv2 or SSPL by specific Elastic features — Cross-Cluster Search, advanced ML, the Endpoint Security agent, APM Server — have weaker leverage and should expect smaller discounts.

06 Discount bands by commit

Realised Elastic Cloud discounts observed in advisor-led negotiations, 2024–2026. Note the persistent gap between cluster and ingest discount — Elastic discounts compute more readily than ingest.

Annual commit (TCV)Cluster discountIngest discount
$100K–$250K5–10%0–5%
$250K–$1M8–15%5–12%
$1M–$3M15–25%10–20%
$3M+22–35%18–28%

07 Cost at scale

The tier spread, indexed to Enterprise. Because compute cost scales linearly with tier rate, moving a workload up one tier is a larger and more permanent cost decision than any single negotiation. Per GB RAM per hour, AWS US East:

Standard
$0.1144
Gold
$0.1696
Platinum
$0.2552
Enterprise
$0.3104
Note

Enterprise costs 2.7x Standard for the same GB of RAM. Only buy the tier for features you actually use — FIPS-validated security and frozen-tier searchable snapshots justify Enterprise; role-based access alone does not require Platinum. Right-tiering before negotiating protects the larger number.

08 Contract levers

Four levers move an Elastic contract beyond list. Weight them to your estate before opening the negotiation.

Lever 01

Ingest volume discount

Elastic's default is to discount cluster compute and protect ingest. Push for an ingest discount aligned to the cluster discount — the single most common gap in these deals.

Lever 02

Retention tiering credit

Write the data-tiering architecture into the contract and price warm and cold tiers at a fixed lower rate, locking the 40–60% saving rather than leaving it to operational discipline.

Lever 03

Frozen tier inclusion

Searchable snapshots on the Enterprise tier should be priced at $0.024 per GB/month rather than carrying a separate fee. Fold the frozen tier into the committed rate card.

Lever 04

OpenSearch BATNA

Signal that AWS OpenSearch migration has been costed and validated. This is the single largest lever in an Elastic negotiation — credible only if the migration TCO is actually modelled.

09 Our recommendation

A four-question test resolves most Elastic decisions. Match your estate to the path below before committing.

Choose OpenSearch
When AWS-native

You already run on AWS and the Elastic-only features (ML, Cross-Cluster Search, Endpoint Security) are not actually used. AWS OpenSearch Service on Apache 2.0 is the cheaper path and doubles as your BATNA.

Choose Elastic Cloud
When regulated or lean

You need FIPS-validated security and frozen-tier searchable snapshots (Enterprise), or you run under 200 GB/day with operational headcount as the constraint (Gold or Platinum). Managed service earns its premium.

Choose ECK
When high-volume

You ingest above 500 GB/day and already operate a Kubernetes platform. Self-managed ECK typically wins on TCO at 25–45% below Elastic Cloud — provided you can absorb the operational overhead.

Cost-test Elastic before you renew

Our negotiation practice delivers a defensible cost and BATNA model in 14 days, including AWS OpenSearch migration TCO for position against the incumbent.

Request an Elastic review →

The Licensing Edge

Weekly cloud and licensing intelligence for enterprise IT leaders. 3,000+ subscribers.