# Last9 vs Elasticsearch: An Elasticsearch Alternative in Your Cloud

> Last9 vs Elasticsearch compared on AI and MCP, who runs the cluster, log field limits, pricing and feature tiers, support, APM agents, and full-text search, with where each one fits.

Source: https://last9.io/compare/elasticsearch/

Both have an AI agent and an MCP server. Last9 runs its agent on your model provider, with no charge per investigation, inside your own cloud account, on one licence, and Last9 runs the platform for you. Elasticsearch is a full-text search engine first, runs on Elastic Cloud or on your own servers, and runs a SIEM on the same data.

- **Gartner Cool Vendor 2025:** Named a Gartner® Cool Vendor in AI for SRE and Observability, cited for its unified telemetry platform.
- **Your model, your cloud:** The Last9 agent runs on your model provider, with no per-investigation charge, in your own cloud account.
- **One licence:** No RAM-hour or per-GB meters, and no subscription tier for AI. The infrastructure runs on your own cloud bill.

## Last9 vs Elasticsearch at a glance

The questions engineering teams ask when they compare the two.

| | **Last9** | **Elasticsearch** |
|---|---|---|
| What does the AI cost? | ✓ No per-query or per-investigation charge | Billed per conversation turn, on Enterprise or Observability Complete only |
| Is there an AI SRE agent that investigates incidents? | ✓ Yes, generally available. The Last9 agent responds to pages, on your model provider | Elastic nightshift is a private preview on Serverless, with a waitlist |
| Does it have an MCP server for coding agents? | ✓ Yes, hosted. An agent can act through it: add drop rules and edit dashboards | Yes, since February 2026, on Enterprise or Observability Complete only |
| Who operates the cluster? | ✓ Last9 does, in your own cloud account, on AWS or GCP in any region | Your team, if self-managed. Elastic Cloud runs it in Elastic's own cloud accounts |
| How many fields can a log carry? | ✓ No field limit | 1,000 per index by default. Past that, new fields fail to index unless a setting leaves them out |
| How is it priced? | ✓ One licence. The infrastructure runs on your own cloud bill | RAM-hours on Hosted, or GB ingested and retained on Serverless. Self-managed is free or licensed by node |
| Which features need a higher tier? | ✓ None. One licence covers distributed tracing, profiling, custom metrics, custom dashboards, alerting, RBAC, and forward deployed engineers | Slack and PagerDuty alerts, anomaly detection, and SLOs need Platinum or Enterprise. AI and the MCP server need Enterprise |
| What support comes with it? | ✓ A shared channel in Slack, Microsoft Teams, or Google Chat, with forward deployed engineers | It follows the subscription tier. On Serverless, it is billed as a share of usage |
| What about our APM agents and integrations? | OpenTelemetry-native, with 100+ integrations. EDOT sends OTLP, so it needs only a new endpoint | 500+ integrations. The classic Elastic APM agents use Elastic's own protocol |
| What about full-text search and security data? | Log search with filters, LogQL, or plain English | ✓ A full-text search engine that scores matches across every field, with a SIEM on the same data |

## AI on your model, in your cloud

- **Last9:** One assistant in the app, in Slack, and in your IDE through MCP. It investigates, builds a diagnosis dashboard, and hands you the link.
- **Last9:** The production agent, Last9, responds to pages with context from Slack, Linear, and PagerDuty. It runs on your model provider or inference endpoint and picks the model for each step. Customer data is never used for training.
- **Last9:** An agent can do more than read. Through MCP it can add a drop rule and stop ingesting the noisy source it found.
- **Last9:** Click a point on a chart, a table row, an alert, or an exception, and choose Ask Last9 AI. The investigation starts from that value, in its service context.
- **Elasticsearch:** Agent Builder runs the Elastic AI Agent and the MCP server, on the Enterprise or Observability Complete tier only. On Elastic Cloud, each conversation turn is billed, and Elastic's own LLM bills per million tokens. Elastic nightshift, the AI SRE agent, is a private preview.

## Managed in your cloud, on one licence

- **Last9:** Last9 runs single-tenant in your own cloud account, on AWS or GCP in any region, and manages it for you. Last9 sizes the cluster, tunes it, and runs the upgrades.
- **Last9:** One licence covers distributed tracing, profiling, custom metrics, custom dashboards, alerting, RBAC, and forward deployed engineers. The infrastructure runs on your own cloud bill, at your negotiated rates.
- **Last9:** Support is a shared channel in Slack, Microsoft Teams, or Google Chat, with forward deployed engineers who know your setup.
- **Elasticsearch:** Self-managed Elasticsearch runs in your cloud, and your team operates it. Elastic Cloud runs it in Elastic's own cloud accounts, billed by RAM per hour or by GB ingested and retained. Alerts to Slack or PagerDuty, anomaly detection, and SLOs need Platinum or Enterprise, and AI needs Enterprise.
- **Matters most for:** Teams that spend engineering hours on cluster health.

## Logs without field limits, queries without a new language

- **Last9:** No field limit on logs. New attributes from a new service or a new release stay queryable, with no mapping to raise.
- **Last9:** PromQL and LogQL natively, with a builder and plain-English Ask Mode for anyone who does not write queries. Your own Grafana can also query Last9 metrics as a Prometheus data source.
- **Last9:** Metrics keep high-cardinality labels. No hard limit. 20M series per metric per day by default, raised on request, with no sampling and no charge per label or metric name.
- **Last9:** APM starts from your services: discovery, dependency maps, database and external calls, Apdex, exceptions, and trace correlation, from OpenTelemetry.
- **Elasticsearch:** Each index maps 1,000 fields by default. Logs are queried in KQL, Lucene, Query DSL, ES|QL, EQL, or SQL, and metrics in ES|QL or PromQL, which ES|QL supports since 9.5.
- **Tradeoff:** Elasticsearch indexes every field for full-text search, and scores matches by relevance. Test both on the log searches your team runs most.

## Which one fits your team?

**Choose Last9 if:**
- You want an AI agent on your own model provider, with no charge per investigation and no tier to unlock it
- Your team spends hours on shards, heap, and upgrades, and wants the backend managed in your own cloud account
- Your logs carry more fields than one index mapping allows
- You want one licence instead of RAM-hour or per-GB meters, and alerting and SLOs without a higher tier
- You want PromQL and LogQL, or a builder and plain-English Ask Mode, not KQL and ES|QL

**Choose Elasticsearch if:**
- Full-text search with relevance scoring across every log field is your main workflow
- You want observability and a SIEM on the same data, from one vendor
- You want to run the stack yourself, on the free self-managed licence or on your own Kubernetes
- Your dashboards, alerts, and runbooks depend on KQL and ES|QL

## Moving off Elasticsearch

What the switch involves, and what Last9 does for you.

- **Forward deployed engineers:** A Last9 engineer runs the move with your team.
- **Keep your instrumentation:** Services on EDOT or OpenTelemetry already send OTLP, so they need only a new endpoint. Services on the classic Elastic APM agents move to OpenTelemetry SDKs. Logstash forwards logs through the OpenTelemetry Collector, with your parsing intact.
- **Queries without KQL:** A Last9 engineer moves your dashboards and alerts with your team, and rewrites KQL and ES|QL queries in PromQL or LogQL. Anyone who does not write queries uses the builder or plain-English Ask Mode.
- **Run both:** Keep Elasticsearch for full-text search and Elastic Security, and move your Kubernetes and OpenTelemetry services to Last9. Logstash and the OpenTelemetry Collector can send the same data to both while you compare them on your own incidents.

## The objections we hear most

Each one is a fair reason to hesitate.

### Elastic already has Agent Builder and an MCP server. Why switch for AI?

The difference is the tier, the cost, and the agent. Agent Builder is on the Enterprise or Observability Complete tier only, and Elastic Cloud bills each conversation turn. The Last9 agent is generally available, runs on your model provider in your own cloud account, and has no per-investigation charge.

### Elastic Cloud already runs the cluster for us.

Elastic Cloud runs it in Elastic's cloud account, but your team still picks how much RAM to pay for. Last9 runs in your own cloud account and manages it for you.

### Our team writes KQL and ES|QL every day.

KQL and ES|QL run only on Elastic. Last9 runs PromQL and LogQL natively, with a builder and plain-English Ask Mode for anyone who does not write queries. A Last9 engineer moves your dashboards, alerts, and queries with your team.

### We get fast answers from Elastic support.

Last9 support is a shared channel in Slack, Microsoft Teams, or Google Chat, with forward deployed engineers on the account. The engineers who run your migration stay on the account afterwards, so they already know your setup.

### Is Last9 proven at our scale?

Last9 regularly handles 500M+ events a minute and 60M+ concurrent users, and has monitored 12 of the world's 20 largest streaming events. It is SOC 2 Type II certified and PCI ready, with SSO and access controls. Teams across fintech, healthcare, gaming, media, and commerce run it in production, including Replit, Pine Labs, Tata 1mg, and Housing.com.

## FAQ

### Is Last9 a good choice among Elasticsearch alternatives?

Elasticsearch fits teams whose main workflow is full-text log search, who want a SIEM on the same data, or who want to run the stack themselves. Last9 fits teams that want an AI agent on their own model provider with no per-investigation charge, a backend that Last9 manages in their own cloud account, no log field limit, and one licence instead of meters and tiers.

### How does Last9's MCP server compare with the Elasticsearch MCP server?

The Elasticsearch MCP server runs in Kibana through Agent Builder, has been generally available since February 2026, is on the Enterprise or Observability Complete tier only, and its write tools manage cases, workflows, and streams. Last9's hosted MCP server works with any MCP client, such as Claude Code or Cursor, on the one licence, and lets an agent act on what it finds: add drop rules to change what is ingested, and edit dashboards.

### How does Last9's AI compare with Elastic Agent Builder?

Elastic Agent Builder is on the Enterprise or Observability Complete tier only, Elastic Cloud bills each conversation turn, and Elastic's own LLM bills per million tokens. Elastic nightshift, its AI SRE agent, is a private preview. The Last9 agent is generally available, has no per-query or per-investigation charge, and runs on your model provider inside your own cloud account.

### How does Last9 billing compare with Elastic pricing?

Elastic pricing depends on where it runs: Elastic Cloud Hosted bills RAM per hour, Serverless bills each GB ingested and retained, and self-managed Elasticsearch is free or licensed by nodes and RAM. Slack and PagerDuty alerts, anomaly detection, SLOs, and AI need higher tiers. Last9 is one licence, and the infrastructure runs on your own cloud bill at your negotiated rates.

### How does Last9 compare with Metricbeat and Elasticsearch metrics?

Metricbeat ships metrics into Elasticsearch, where they are stored in time series data streams and queried in ES|QL, which supports most of PromQL since 9.5. Last9 answers PromQL natively, takes metrics from Prometheus and OpenTelemetry, and has no hard cardinality limit: 20M series per metric per day by default, raised on request, with no sampling and no charge per label or metric name.

### Is there an Elastic Cloud alternative that runs in our cloud account?

Yes. Elastic Cloud runs in Elastic's own cloud accounts, and self-managed Elasticsearch runs in yours, operated by your team. Last9 runs single-tenant in your own cloud account, on AWS or GCP in any region, and Last9 manages it for you, including the AI.

### Can Last9 replace Elastic APM?

Elastic APM takes data from Elastic's own APM agents or from OpenTelemetry through EDOT. On Serverless, it needs Observability Complete. Last9 covers service discovery, dependency maps, database and external calls, Apdex, exceptions, and trace correlation, from OpenTelemetry, on the one licence.

### Can Last9 run alongside Elasticsearch?

Yes. Elasticsearch is a full-text search engine and Elastic Security runs a SIEM, so keep it for search and security, and move your Kubernetes and OpenTelemetry services to Last9. Logstash and the OpenTelemetry Collector can send the same data to both, and a Last9 engineer plans the split with your team.

### How do I migrate from Elasticsearch to Last9?

Services on EDOT or OpenTelemetry already send OTLP, so they need only a new endpoint, and services on the classic Elastic APM agents move to OpenTelemetry SDKs. A Last9 engineer moves your dashboards and alerts with your team, and rewrites KQL and ES|QL queries in PromQL or LogQL.
