Breaking query Elastic turns data into answers 24,000 customers Search + observability + security FY2026 revenue: $1.739B

Company profile / Elastic

The Search Engine That Learned Three Jobs

Elastic began with a recipe search problem. Today, the same engine retrieves context for AI agents, traces a failing service and helps a security analyst find the one alert that matters.

Before Elastic became a public company with billions in annual sales, it was a domestic favor. In 2004, software developer Shay Banon wanted to help his wife search recipes while she studied cooking. The project did not become the recipe app he imagined. It did teach him something durable: people rarely suffer from too little data. They suffer because the useful bit is buried inside the pile.

Banon began writing Elasticsearch in 2009 and released it publicly in 2010. Two years later he founded a company with Steven Schuurman, Uri Boness and Simon Willnauer. What followed was not merely a better search box. Elasticsearch became a distributed engine that could ingest unruly data, index it across many machines and return relevant answers quickly. Developers put it behind websites. Operations teams aimed it at logs. Security teams poured events into it and went hunting.

That accidental versatility is now the whole strategy. Elastic sells three solutions - Search & AI, Observability and Security - on one shared platform. The names map to different departments and budgets, but the mechanical act underneath is similar: collect a great deal of evidence, make it searchable, then surface the signal that matters before the moment passes.

Abstract geometric streams of data resolving through a navy index into a precise yellow point
Fig. 01A million colorful distractions enter from the left. One useful answer exits on the right. The index has excellent manners and no small talk.

One engine, three urgent questions

A shopping site asks, “Which shoes did this customer mean?” An SRE asks, “Why did checkout slow down at 2:13 a.m.?” A security analyst asks, “Which login belongs to an intruder?” Elastic's wager is that each question benefits from the same foundation. Elasticsearch stores documents, events, time-series records and vector embeddings. Kibana supplies the visual and investigative workspace. Integrations, Elastic Agent, Beats and Logstash move data in. Machine learning, rules and workflows help people interpret and act on what comes back.

For application builders, Elastic combines classic keyword relevance with semantic and vector search. That matters because large language models are fluent but not reliably informed about a company's private, current information. Retrieval-augmented generation gives the model selected enterprise context before it answers. Elastic wants Elasticsearch to be that retrieval layer: the place an agent goes to find the right policy, case, product or conversation, with the speed and permissions a production system requires.

For operations teams, the indexed material is telemetry - logs, metrics and traces emitted by applications and infrastructure. Elastic Observability connects a symptom to its surrounding evidence. Native OpenTelemetry support lowers the cost of getting data in; APM, dashboards and anomaly detection help find causes. Version 9.4 added native Prometheus and PromQL support plus an agentic Kubernetes investigation that can begin assembling evidence when an alert fires, before the on-call engineer opens it.

For security teams, the data is a record of identities, endpoints, networks and cloud systems. Elastic Security combines SIEM, endpoint protection, threat hunting and response. Its 2026 “Alert Zero” language captures the practical enemy: not zero threats, but a queue so noisy that real attacks disappear inside it. Attack Discovery groups and investigates related signals; Workflows can enrich a case, query threat intelligence, isolate a host or hand the incident to another system.

“Elastic is a search company.”Elastic's Source Code, under the heading “Speed, Scale, Relevance”

Open software, paid gravity

Elastic's route into a company often starts below the procurement line. A developer downloads the software to solve one problem. The code is useful, the project grows, another team borrows it and eventually somebody needs uptime guarantees, security controls, centralized management or a bill that can pass enterprise purchasing. That movement from free use to consequential deployment is the commercial machine.

The company maintains one code base across free and paid distribution rather than a separate enterprise edition. The free core of Elasticsearch and Kibana is available under AGPLv3, which Elastic added in 2024 after several years of licensing conflict with cloud providers. Commercial features remain proprietary. Customers can buy self-managed subscriptions or use Elastic Cloud in hosted and serverless forms across AWS, Microsoft Azure and Google Cloud.

The business in one sentenceGive developers a capable search platform, then charge organizations for managed infrastructure, advanced features and support when that platform becomes important.

Cloud pricing varies with resources or usage. Self-managed subscriptions are tied to licensed deployment capacity. Most Elastic Cloud contracts are consumption-based; larger agreements commonly run one to three years. Support is bundled into paid tiers rather than sold alone. Training and consulting add a smaller service stream. In fiscal 2026, subscriptions accounted for 94 percent of revenue.

24KApproximate customers
$1.739BFiscal 2026 revenue
94%Revenue from subscriptions

The index keeps expanding

FY24
21K customers
FY25
21.5K
FY26
24K
Scale checkElastic also counted more than 1,720 customers spending over $100,000 annually and more than 240 spending over $1 million.

A market with three sets of elbows

Elastic's breadth is a differentiator and a complication. In search, it meets Algolia, Coveo, Apache Solr, cloud search services and specialist vector databases such as Pinecone, Qdrant and Weaviate. In observability, it meets Datadog, Dynatrace, New Relic and Cisco's Splunk and AppDynamics. In security, it meets large platform vendors and specialists selling SIEM, endpoint and cloud defense.

Search & AI

Relevance, vector retrieval, RAG and agent context for developers building applications.

Observability

Logs, metrics, traces and investigations for SRE, DevOps and IT operations teams.

Security

SIEM, endpoint defense, threat hunting and response for security operations centers.

The pitch against narrower rivals is consolidation. A customer can reuse data, skills and infrastructure across several jobs instead of buying a new store and query language for each. Deployment flexibility helps: on-premises, public cloud, private cloud, hybrid or serverless. The shared engine also allows an investigation to cross boundaries. An outage may prove to be an attack; a customer-search problem may actually be a failing service.

The tradeoff is focus. A dedicated vector database can optimize its whole experience for vectors. An observability specialist can design pricing and interfaces around telemetry alone. A security incumbent can bundle a wide suite. Elastic must make a general platform feel purpose-built to each buyer while preserving the architectural commonality that makes the strategy worthwhile. It spends accordingly: research and development expense reached $451.9 million in fiscal 2026.

The retrieval layer gets a pair of hands

The newest chapter moves from finding information to doing something with it. Agent Builder, generally available since January 2026, gives developers tools to ground agents in enterprise data, rank context and expose custom tools. It supports protocols including MCP and A2A, making it easier to connect with external agent systems. Elastic Workflows supplies the deterministic complement: prescribed steps for tasks where a probabilistic model should not improvise.

That division is sensible. Let a model interpret a messy incident; let a rule decide how an approved host-isolation action runs. Let an agent find the relevant customer history; let a workflow update the support system. In Elastic 9.4, Workflows became generally available while Agent Builder gained skills, attachments, connectors and tighter context management. The product direction mirrors the company's updated phrase: data becomes answers, then actions, then outcomes.

The culture uses a software metaphor, too. Elastic has no principal executive office. Its 4,019 employees work across more than 40 countries, following a set of ideas called the Source Code. “Home, Dinner” means work should leave room for life. “IT, Depends” makes nuance an official response. “Progress, SIMPLE Perfection” favors movement. “HUMBLE, Ambitious” ends with a notably direct instruction about not being unpleasant.

A distributed company building distributed systems is almost suspiciously tidy as a story. Yet it explains Elastic's enduring appeal. The product assumes data will be scattered, formats will be awkward and the important question will arrive late. The organization assumes talent will be scattered, time zones will be awkward and useful ideas can arrive from anywhere. Both systems try to turn distribution from a nuisance into an advantage.

The useful thing about search is not the box. It is the moment a mountain of evidence becomes one next move.YesPress

Where Elastic fits now

Elastic sits between databases, developer infrastructure and packaged enterprise applications. It is not a general transactional database, though it stores data. It is not merely a dashboard, though Kibana visualizes. It is not only a security suite, though customers can buy it that way. Its center of gravity is high-volume retrieval and analysis - especially where relevance, latency and flexibility matter at once.

The scale is material: about 24,000 customers in more than 125 countries, including enterprises, schools and governments; more than half of the Fortune 500, according to Elastic; and fiscal 2026 revenue up 17 percent to $1.739 billion. The company remained at a GAAP operating loss for the year, while reporting positive cash generation and non-GAAP operating income. It is a growth software business with the expenses, competition and cloud bills that description implies.

Its future depends on whether “Search AI” becomes a genuine category or stays a useful label draped across three established ones. The case for it is concrete. Models need context. Software teams need unified telemetry. Security teams need faster investigations. All three need a system that can ingest messy evidence and retrieve the consequential piece in real time.

A recipe query and a threat hunt are far apart in consequence, but not in shape. There is too much information, only some of it matters, and somebody is waiting for an answer. Elastic has spent sixteen years making that shape its business.