Why engineering teams choose Last9 vs Elasticsearch
Both have an AI agent and an MCP server. Last9 runs its agent on your model provider, with no charge per investigation, inside your own cloud account, on one licence, and Last9 runs the platform for you. Elasticsearch is a full-text search engine first, runs on Elastic Cloud or on your own servers, and runs a SIEM on the same data.
100+ native integrations, OpenTelemetry-first. A Last9 engineer runs the move with your team.
Named a Gartner® Cool Vendor in AI for SRE and Observability, cited for its unified telemetry platform.
The Last9 agent runs on your model provider, with no per-investigation charge, in your own cloud account.
No RAM-hour or per-GB meters, and no subscription tier for AI. The infrastructure runs on your own cloud bill.
At a glance
Last9 vs Elasticsearch at a glance
The questions engineering teams ask when they compare the two.
What does the AI cost?
No per-query or per-investigation charge
Billed per conversation turn, on Enterprise or Observability Complete only
Is there an AI SRE agent that investigates incidents?
Yes, generally available. The Last9 agent responds to pages, on your model provider
Elastic nightshift is a private preview on Serverless, with a waitlist
Does it have an MCP server for coding agents?
Yes, hosted. An agent can act through it: add drop rules and edit dashboards
Yes, since February 2026, on Enterprise or Observability Complete only
Who operates the cluster?
Last9 does, in your own cloud account, on AWS or GCP in any region
Your team, if self-managed. Elastic Cloud runs it in Elastic's own cloud accounts
How many fields can a log carry?
No field limit
1,000 per index by default. Past that, new fields fail to index unless a setting leaves them out
How is it priced?
One licence. The infrastructure runs on your own cloud bill
RAM-hours on Hosted, or GB ingested and retained on Serverless. Self-managed is free or licensed by node
Which features need a higher tier?
None. One licence covers distributed tracing, profiling, custom metrics, custom dashboards, alerting, RBAC, and forward deployed engineers
Slack and PagerDuty alerts, anomaly detection, and SLOs need Platinum or Enterprise. AI and the MCP server need Enterprise
What support comes with it?
A shared channel in Slack, Microsoft Teams, or Google Chat, with forward deployed engineers
It follows the subscription tier. On Serverless, it is billed as a share of usage
What about our APM agents and integrations?
OpenTelemetry-native, with 100+ integrations. EDOT sends OTLP, so it needs only a new endpoint
500+ integrations. The classic Elastic APM agents use Elastic's own protocol
What about full-text search and security data?
Log search with filters, LogQL, or plain English
A full-text search engine that scores matches across every field, with a SIEM on the same data
| Capability | Last9 | Elasticsearch |
|---|---|---|
| What does the AI cost? | No per-query or per-investigation charge | Billed per conversation turn, on Enterprise or Observability Complete only |
| Is there an AI SRE agent that investigates incidents? | Yes, generally available. The Last9 agent responds to pages, on your model provider | Elastic nightshift is a private preview on Serverless, with a waitlist |
| Does it have an MCP server for coding agents? | Yes, hosted. An agent can act through it: add drop rules and edit dashboards | Yes, since February 2026, on Enterprise or Observability Complete only |
| Who operates the cluster? | Last9 does, in your own cloud account, on AWS or GCP in any region | Your team, if self-managed. Elastic Cloud runs it in Elastic's own cloud accounts |
| How many fields can a log carry? | No field limit | 1,000 per index by default. Past that, new fields fail to index unless a setting leaves them out |
| How is it priced? | One licence. The infrastructure runs on your own cloud bill | RAM-hours on Hosted, or GB ingested and retained on Serverless. Self-managed is free or licensed by node |
| Which features need a higher tier? | None. One licence covers distributed tracing, profiling, custom metrics, custom dashboards, alerting, RBAC, and forward deployed engineers | Slack and PagerDuty alerts, anomaly detection, and SLOs need Platinum or Enterprise. AI and the MCP server need Enterprise |
| What support comes with it? | A shared channel in Slack, Microsoft Teams, or Google Chat, with forward deployed engineers | It follows the subscription tier. On Serverless, it is billed as a share of usage |
| What about our APM agents and integrations? | OpenTelemetry-native, with 100+ integrations. EDOT sends OTLP, so it needs only a new endpoint | 500+ integrations. The classic Elastic APM agents use Elastic's own protocol |
| What about full-text search and security data? | Log search with filters, LogQL, or plain English | A full-text search engine that scores matches across every field, with a SIEM on the same data |
Differences
Where Last9 and Elasticsearch differ
Three places the two platforms take a different approach, with the tradeoffs stated.
AI on your model, in your cloud
-
One assistant in the app, in Slack, and in your IDE through MCP. It investigates, builds a diagnosis dashboard, and hands you the link.
-
The production agent, Last9, responds to pages with context from Slack, Linear, and PagerDuty. It runs on your model provider or inference endpoint and picks the model for each step. Customer data is never used for training.
-
An agent can do more than read. Through MCP it can add a drop rule and stop ingesting the noisy source it found.
-
Click a point on a chart, a table row, an alert, or an exception, and choose Ask Last9 AI. The investigation starts from that value, in its service context.
Elasticsearch
Agent Builder runs the Elastic AI Agent and the MCP server, on the Enterprise or Observability Complete tier only. On Elastic Cloud, each conversation turn is billed, and Elastic's own LLM bills per million tokens. Elastic nightshift, the AI SRE agent, is a private preview.
Managed in your cloud, on one licence
-
Last9 runs single-tenant in your own cloud account, on AWS or GCP in any region, and manages it for you. Last9 sizes the cluster, tunes it, and runs the upgrades.
-
One licence covers distributed tracing, profiling, custom metrics, custom dashboards, alerting, RBAC, and forward deployed engineers. The infrastructure runs on your own cloud bill, at your negotiated rates.
-
Support is a shared channel in Slack, Microsoft Teams, or Google Chat, with forward deployed engineers who know your setup.
Elasticsearch
Self-managed Elasticsearch runs in your cloud, and your team operates it. Elastic Cloud runs it in Elastic's own cloud accounts, billed by RAM per hour or by GB ingested and retained. Alerts to Slack or PagerDuty, anomaly detection, and SLOs need Platinum or Enterprise, and AI needs Enterprise.
Matters most for
Teams that spend engineering hours on cluster health.
Logs without field limits, queries without a new language
-
No field limit on logs. New attributes from a new service or a new release stay queryable, with no mapping to raise.
-
PromQL and LogQL natively, with a builder and plain-English Ask Mode for anyone who does not write queries. Your own Grafana can also query Last9 metrics as a Prometheus data source.
-
Metrics keep high-cardinality labels. No hard limit. 20M series per metric per day by default, raised on request, with no sampling and no charge per label or metric name.
-
APM starts from your services: discovery, dependency maps, database and external calls, Apdex, exceptions, and trace correlation, from OpenTelemetry.
Elasticsearch
Each index maps 1,000 fields by default. Logs are queried in KQL, Lucene, Query DSL, ES|QL, EQL, or SQL, and metrics in ES|QL or PromQL, which ES|QL supports since 9.5.
Tradeoff
Elasticsearch indexes every field for full-text search, and scores matches by relevance. Test both on the log searches your team runs most.
Which fits you
Which one fits your team?
Choose Last9 if
- You want an AI agent on your own model provider, with no charge per investigation and no tier to unlock it
- Your team spends hours on shards, heap, and upgrades, and wants the backend managed in your own cloud account
- Your logs carry more fields than one index mapping allows
- You want one licence instead of RAM-hour or per-GB meters, and alerting and SLOs without a higher tier
- You want PromQL and LogQL, or a builder and plain-English Ask Mode, not KQL and ES|QL
Choose Elasticsearch if
- Full-text search with relevance scoring across every log field is your main workflow
- You want observability and a SIEM on the same data, from one vendor
- You want to run the stack yourself, on the free self-managed licence or on your own Kubernetes
- Your dashboards, alerts, and runbooks depend on KQL and ES|QL
Migration
Moving off Elasticsearch
What the switch involves, and what Last9 does for you.
Forward deployed engineers
A Last9 engineer runs the move with your team.
Talk to an engineerKeep your instrumentation
Services on EDOT or OpenTelemetry already send OTLP, so they need only a new endpoint. Services on the classic Elastic APM agents move to OpenTelemetry SDKs. Logstash forwards logs through the OpenTelemetry Collector, with your parsing intact.
Forward logs from LogstashQueries without KQL
A Last9 engineer moves your dashboards and alerts with your team, and rewrites KQL and ES|QL queries in PromQL or LogQL. Anyone who does not write queries uses the builder or plain-English Ask Mode.
Run both
Keep Elasticsearch for full-text search and Elastic Security, and move your Kubernetes and OpenTelemetry services to Last9. Logstash and the OpenTelemetry Collector can send the same data to both while you compare them on your own incidents.
Objections
The objections we hear most
Each one is a fair reason to hesitate.
Elastic already has Agent Builder and an MCP server. Why switch for AI?
The difference is the tier, the cost, and the agent. Agent Builder is on the Enterprise or Observability Complete tier only, and Elastic Cloud bills each conversation turn. The Last9 agent is generally available, runs on your model provider in your own cloud account, and has no per-investigation charge.
Elastic Cloud already runs the cluster for us.
Elastic Cloud runs it in Elastic's cloud account, but your team still picks how much RAM to pay for. Last9 runs in your own cloud account and manages it for you.
Our team writes KQL and ES|QL every day.
KQL and ES|QL run only on Elastic. Last9 runs PromQL and LogQL natively, with a builder and plain-English Ask Mode for anyone who does not write queries. A Last9 engineer moves your dashboards, alerts, and queries with your team.
We get fast answers from Elastic support.
Last9 support is a shared channel in Slack, Microsoft Teams, or Google Chat, with forward deployed engineers on the account. The engineers who run your migration stay on the account afterwards, so they already know your setup.
Is Last9 proven at our scale?
Last9 regularly handles 500M+ events a minute and 60M+ concurrent users, and has monitored 12 of the world's 20 largest streaming events. It is SOC 2 Type II certified and PCI ready, with SSO and access controls. Teams across fintech, healthcare, gaming, media, and commerce run it in production, including Replit, Pine Labs, Tata 1mg, and Housing.com.
67%
Average reduction in observability costs
2.5x
More telemetry retained without sampling
100+
Native integrations, OpenTelemetry-first
24x7
Support from forward deployed engineers
Customers
What do Last9 customers say?
With Last9, we just eliminated the toil. No more worrying about failing dashboards or alerts — we can finally use our metrics. It just works.
Last9 allowed us to offload the operational overhead of scaling so we could focus on business alerting rather than infrastructure management.
Frequently asked questions
Ask AI about this comparison
Do not take our word for it. Send the question to an assistant and check what it finds.
Can't find the answer to your question?
Talk to our support team for help.
Start observing for free. No lock-in.
OpenTelemetry · Prometheus
Just update your config. Start seeing data on Last9 in seconds.
Datadog · New Relic · Others
We've got you covered. Bring over your dashboards & alerts in one click.
Built on Open Standards
100+ integrations. OTel native, works with your existing stack.