Elasticsearch logo Last9

Why engineering teams choose Last9 vs Elasticsearch

Both have an AI agent and an MCP server. Last9 runs its agent on your model provider, with no charge per investigation, inside your own cloud account, on one licence, and Last9 runs the platform for you. Elasticsearch is a full-text search engine first, runs on Elastic Cloud or on your own servers, and runs a SIEM on the same data.

100+ native integrations, OpenTelemetry-first. A Last9 engineer runs the move with your team.

Gartner Cool Vendor 2025

Named a Gartner® Cool Vendor in AI for SRE and Observability, cited for its unified telemetry platform.

Your model, your cloud

The Last9 agent runs on your model provider, with no per-investigation charge, in your own cloud account.

One licence

No RAM-hour or per-GB meters, and no subscription tier for AI. The infrastructure runs on your own cloud bill.

At a glance

Last9 vs Elasticsearch at a glance

The questions engineering teams ask when they compare the two.

What does the AI cost?

Last9

No per-query or per-investigation charge

Elasticsearch

Billed per conversation turn, on Enterprise or Observability Complete only

Is there an AI SRE agent that investigates incidents?

Last9

Yes, generally available. The Last9 agent responds to pages, on your model provider

Elasticsearch

Elastic nightshift is a private preview on Serverless, with a waitlist

Does it have an MCP server for coding agents?

Last9

Yes, hosted. An agent can act through it: add drop rules and edit dashboards

Elasticsearch

Yes, since February 2026, on Enterprise or Observability Complete only

Who operates the cluster?

Last9

Last9 does, in your own cloud account, on AWS or GCP in any region

Elasticsearch

Your team, if self-managed. Elastic Cloud runs it in Elastic's own cloud accounts

How many fields can a log carry?

Last9

No field limit

Elasticsearch

1,000 per index by default. Past that, new fields fail to index unless a setting leaves them out

How is it priced?

Last9

One licence. The infrastructure runs on your own cloud bill

Elasticsearch

RAM-hours on Hosted, or GB ingested and retained on Serverless. Self-managed is free or licensed by node

Which features need a higher tier?

Last9

None. One licence covers distributed tracing, profiling, custom metrics, custom dashboards, alerting, RBAC, and forward deployed engineers

Elasticsearch

Slack and PagerDuty alerts, anomaly detection, and SLOs need Platinum or Enterprise. AI and the MCP server need Enterprise

What support comes with it?

Last9

A shared channel in Slack, Microsoft Teams, or Google Chat, with forward deployed engineers

Elasticsearch

It follows the subscription tier. On Serverless, it is billed as a share of usage

What about our APM agents and integrations?

Last9

OpenTelemetry-native, with 100+ integrations. EDOT sends OTLP, so it needs only a new endpoint

Elasticsearch

500+ integrations. The classic Elastic APM agents use Elastic's own protocol

What about full-text search and security data?

Last9

Log search with filters, LogQL, or plain English

Elasticsearch

A full-text search engine that scores matches across every field, with a SIEM on the same data

Differences

Where Last9 and Elasticsearch differ

Three places the two platforms take a different approach, with the tradeoffs stated.

AI on your model, in your cloud

  • One assistant in the app, in Slack, and in your IDE through MCP. It investigates, builds a diagnosis dashboard, and hands you the link.

  • The production agent, Last9, responds to pages with context from Slack, Linear, and PagerDuty. It runs on your model provider or inference endpoint and picks the model for each step. Customer data is never used for training.

  • An agent can do more than read. Through MCP it can add a drop rule and stop ingesting the noisy source it found.

  • Click a point on a chart, a table row, an alert, or an exception, and choose Ask Last9 AI. The investigation starts from that value, in its service context.

Elasticsearch

Agent Builder runs the Elastic AI Agent and the MCP server, on the Enterprise or Observability Complete tier only. On Elastic Cloud, each conversation turn is billed, and Elastic's own LLM bills per million tokens. Elastic nightshift, the AI SRE agent, is a private preview.

Managed in your cloud, on one licence

  • Last9 runs single-tenant in your own cloud account, on AWS or GCP in any region, and manages it for you. Last9 sizes the cluster, tunes it, and runs the upgrades.

  • One licence covers distributed tracing, profiling, custom metrics, custom dashboards, alerting, RBAC, and forward deployed engineers. The infrastructure runs on your own cloud bill, at your negotiated rates.

  • Support is a shared channel in Slack, Microsoft Teams, or Google Chat, with forward deployed engineers who know your setup.

Elasticsearch

Self-managed Elasticsearch runs in your cloud, and your team operates it. Elastic Cloud runs it in Elastic's own cloud accounts, billed by RAM per hour or by GB ingested and retained. Alerts to Slack or PagerDuty, anomaly detection, and SLOs need Platinum or Enterprise, and AI needs Enterprise.

Matters most for

Teams that spend engineering hours on cluster health.

Logs without field limits, queries without a new language

  • No field limit on logs. New attributes from a new service or a new release stay queryable, with no mapping to raise.

  • PromQL and LogQL natively, with a builder and plain-English Ask Mode for anyone who does not write queries. Your own Grafana can also query Last9 metrics as a Prometheus data source.

  • Metrics keep high-cardinality labels. No hard limit. 20M series per metric per day by default, raised on request, with no sampling and no charge per label or metric name.

  • APM starts from your services: discovery, dependency maps, database and external calls, Apdex, exceptions, and trace correlation, from OpenTelemetry.

Elasticsearch

Each index maps 1,000 fields by default. Logs are queried in KQL, Lucene, Query DSL, ES|QL, EQL, or SQL, and metrics in ES|QL or PromQL, which ES|QL supports since 9.5.

Tradeoff

Elasticsearch indexes every field for full-text search, and scores matches by relevance. Test both on the log searches your team runs most.

Which fits you

Which one fits your team?

Choose Last9 if

  • You want an AI agent on your own model provider, with no charge per investigation and no tier to unlock it
  • Your team spends hours on shards, heap, and upgrades, and wants the backend managed in your own cloud account
  • Your logs carry more fields than one index mapping allows
  • You want one licence instead of RAM-hour or per-GB meters, and alerting and SLOs without a higher tier
  • You want PromQL and LogQL, or a builder and plain-English Ask Mode, not KQL and ES|QL

Choose Elasticsearch if

  • Full-text search with relevance scoring across every log field is your main workflow
  • You want observability and a SIEM on the same data, from one vendor
  • You want to run the stack yourself, on the free self-managed licence or on your own Kubernetes
  • Your dashboards, alerts, and runbooks depend on KQL and ES|QL

Migration

Moving off Elasticsearch

What the switch involves, and what Last9 does for you.

01

Forward deployed engineers

A Last9 engineer runs the move with your team.

Talk to an engineer
02

Keep your instrumentation

Services on EDOT or OpenTelemetry already send OTLP, so they need only a new endpoint. Services on the classic Elastic APM agents move to OpenTelemetry SDKs. Logstash forwards logs through the OpenTelemetry Collector, with your parsing intact.

Forward logs from Logstash
03

Queries without KQL

A Last9 engineer moves your dashboards and alerts with your team, and rewrites KQL and ES|QL queries in PromQL or LogQL. Anyone who does not write queries uses the builder or plain-English Ask Mode.

04

Run both

Keep Elasticsearch for full-text search and Elastic Security, and move your Kubernetes and OpenTelemetry services to Last9. Logstash and the OpenTelemetry Collector can send the same data to both while you compare them on your own incidents.

Objections

The objections we hear most

Each one is a fair reason to hesitate.

Elastic already has Agent Builder and an MCP server. Why switch for AI?

The difference is the tier, the cost, and the agent. Agent Builder is on the Enterprise or Observability Complete tier only, and Elastic Cloud bills each conversation turn. The Last9 agent is generally available, runs on your model provider in your own cloud account, and has no per-investigation charge.

Elastic Cloud already runs the cluster for us.

Elastic Cloud runs it in Elastic's cloud account, but your team still picks how much RAM to pay for. Last9 runs in your own cloud account and manages it for you.

Our team writes KQL and ES|QL every day.

KQL and ES|QL run only on Elastic. Last9 runs PromQL and LogQL natively, with a builder and plain-English Ask Mode for anyone who does not write queries. A Last9 engineer moves your dashboards, alerts, and queries with your team.

We get fast answers from Elastic support.

Last9 support is a shared channel in Slack, Microsoft Teams, or Google Chat, with forward deployed engineers on the account. The engineers who run your migration stay on the account afterwards, so they already know your setup.

Is Last9 proven at our scale?

Last9 regularly handles 500M+ events a minute and 60M+ concurrent users, and has monitored 12 of the world's 20 largest streaming events. It is SOC 2 Type II certified and PCI ready, with SSO and access controls. Teams across fintech, healthcare, gaming, media, and commerce run it in production, including Replit, Pine Labs, Tata 1mg, and Housing.com.

67%

Average reduction in observability costs

2.5x

More telemetry retained without sampling

100+

Native integrations, OpenTelemetry-first

24x7

Support from forward deployed engineers


Replit Tata 1mg Pine Labs Jubilant FoodWorks Baylor Genetics Mobile Premier League Evergent

Customers

What do Last9 customers say?

With Last9, we just eliminated the toil. No more worrying about failing dashboards or alerts — we can finally use our metrics. It just works.

Matt Iselin Head of SRE at Replit
Replit

Last9 allowed us to offload the operational overhead of scaling so we could focus on business alerting rather than infrastructure management.

Upendra Singh Associate Director DevOps at Housing.com
More customer stories

Frequently asked questions

Ask AI about this comparison

Do not take our word for it. Send the question to an assistant and check what it finds.

Elasticsearch fits teams whose main workflow is full-text log search, who want a SIEM on the same data, or who want to run the stack themselves. Last9 fits teams that want an AI agent on their own model provider with no per-investigation charge, a backend that Last9 manages in their own cloud account, no log field limit, and one licence instead of meters and tiers.
The Elasticsearch MCP server runs in Kibana through Agent Builder, has been generally available since February 2026, is on the Enterprise or Observability Complete tier only, and its write tools manage cases, workflows, and streams. Last9's hosted MCP server works with any MCP client, such as Claude Code or Cursor, on the one licence, and lets an agent act on what it finds: add drop rules to change what is ingested, and edit dashboards.
Elastic Agent Builder is on the Enterprise or Observability Complete tier only, Elastic Cloud bills each conversation turn, and Elastic's own LLM bills per million tokens. Elastic nightshift, its AI SRE agent, is a private preview. The Last9 agent is generally available, has no per-query or per-investigation charge, and runs on your model provider inside your own cloud account.
Elastic pricing depends on where it runs: Elastic Cloud Hosted bills RAM per hour, Serverless bills each GB ingested and retained, and self-managed Elasticsearch is free or licensed by nodes and RAM. Slack and PagerDuty alerts, anomaly detection, SLOs, and AI need higher tiers. Last9 is one licence, and the infrastructure runs on your own cloud bill at your negotiated rates.
Metricbeat ships metrics into Elasticsearch, where they are stored in time series data streams and queried in ES|QL, which supports most of PromQL since 9.5. Last9 answers PromQL natively, takes metrics from Prometheus and OpenTelemetry, and has no hard cardinality limit: 20M series per metric per day by default, raised on request, with no sampling and no charge per label or metric name.
Yes. Elastic Cloud runs in Elastic's own cloud accounts, and self-managed Elasticsearch runs in yours, operated by your team. Last9 runs single-tenant in your own cloud account, on AWS or GCP in any region, and Last9 manages it for you, including the AI.
Elastic APM takes data from Elastic's own APM agents or from OpenTelemetry through EDOT. On Serverless, it needs Observability Complete. Last9 covers service discovery, dependency maps, database and external calls, Apdex, exceptions, and trace correlation, from OpenTelemetry, on the one licence.
Yes. Elasticsearch is a full-text search engine and Elastic Security runs a SIEM, so keep it for search and security, and move your Kubernetes and OpenTelemetry services to Last9. Logstash and the OpenTelemetry Collector can send the same data to both, and a Last9 engineer plans the split with your team.
Services on EDOT or OpenTelemetry already send OTLP, so they need only a new endpoint, and services on the classic Elastic APM agents move to OpenTelemetry SDKs. A Last9 engineer moves your dashboards and alerts with your team, and rewrites KQL and ES|QL queries in PromQL or LogQL.

Can't find the answer to your question?

Talk to our support team for help.

Contact support
Last9 logo and enter key

Start observing for free. No lock-in.

OpenTelemetry · Prometheus

Just update your config. Start seeing data on Last9 in seconds.

Datadog · New Relic · Others

We've got you covered. Bring over your dashboards & alerts in one click.

Built on Open Standards

100+ integrations. OTel native, works with your existing stack.