Observability TCO Comparison

Compare true total cost of ownership — infrastructure and human operational costs — across observability platforms

Estimation purposes only

This tool is not validated by Elastic Product, Marketing, or Competitive Intelligence for accuracy. List rates reconciled as of July 2026 against the Elastic Cloud Serverless and Cloud Hosted pricing tables plus ad hoc field feedback (e.g. Serverless estimator alignment). See also Serverless Observability pricing (TSDS metrics effective July 1, 2026). Other vendor rates and unit conversions are approximate. Confirm all figures with official pricing, contracts, and measured usage before customer-facing quotes.

Elastic Serverless (design in this tool)

  • Observability Complete ingest + retention tier table (AWS us-east-1 list rates).
  • Metrics (TSDS): 25% of Complete ingest + retention tiers (list floors July 1, 2026: $0.023/GB ingest, $0.005/GB-month retained); logs, traces, and security use full Complete rates.
  • Logs: metered ingest uses ~1.66× raw GB (enriched size per Elastic estimator).
  • Elastic Streams TCO is always on: per-signal drop, aggregate, downsample, and retention (default Streams policies) — adjust in Configuration.
  • Retention slider affects the unshaped baseline only; billed Serverless totals include Streams policies.

Elastic Cloud Hosted — ECH (design in this tool)

  • 1-day hot · ILM → blob (writable frozen) 1-day data hot (RAM-hour) plus 25-day ILM on blob (writable frozen, queryable in Kibana).
  • Applies to metrics, logs, traces, and security variable backbone — not the legacy “flat $/GB ingest + Complete retention months” workbook model.
  • Full-fidelity ingest on ECH; Streams sampling is not applied to ECH rows (Serverless-only shaping).
  • List rates from elastic.co/pricing/cloud-hosted / cloud pricing table (data hot, snapshot storage, transfer).
  • Cluster minimums ($200 metrics, etc.) still apply where modeled.

Schemaless data blocks: Observability ingest is priced on GB/TiB committed, not separate metrics vs logs vs traces SKUs — one block can carry mixed OTLP. See the Schemaless observability · data blocks table below for illustrative $/TiB-month at 1, 50, 100, and 500 TiB/mo. Per-tab comparisons may still apply signal-specific metering for vendor parity (TSDS 25%, logs 1.66×, etc.).

Not included: Datadog/Splunk/etc. use approximate public list pricing; operational FTE is optional. Excludes synthetics, LLM observability, Agent Builder, support ECUs, Cross-project Search mounted-GB charges, and negotiated discounts.

Schemaless observability · data blocks

Elastic Observability is schemaless at ingest: OpenTelemetry, Elastic Agent, and Beats can land logs, metrics, and traces in the same project without picking a separate SKU per signal. For planning, think in committed data blocks — monthly ingested tebibytes (TiB) on the wire — not “metrics SKU + logs SKU + APM SKU.” ES|QL, Kibana, and alerting run across those bytes in one place; Streams and ILM shape cost per stream, not per product line item.

One block, any signal

1 TiB/month of mixed OTLP (logs + metrics + traces) bills the same backbone GB as 1 TiB/month of logs-only — volume is ingested GB, not index type.

ECH data block

1-day hot · ILM → blob (writable frozen). Enterprise commits often quote $/TiB-month on this hot + frozen architecture.

Serverless data block

Observability Complete ingest + retention tiers per cloud.elastic.co, with Streams TCO applied by default in this calculator.

Illustrative effective rates at 1 TiB/month steady ingest (1024 GiB/mo): ECH ~$8/TiB-mo · Serverless (Streams) ~$407/TiB-mo. Scale rows below multiply roughly linearly with committed TiB when tier tables are flat; at 50–500 TiB/mo, Complete tiering lowers $/TiB.

Committed ingest blockECH / monthECH / year$/TiB-mo (ECH)Serverless / monthServerless / year$/TiB-mo (Serverless)
1 TiB/mo~34 GiB/day wire$8$100$8$407$4.9K$407
50 TiB/mo~1,683 GiB/day wire$457$5.5K$9$7.0K$83.6K$139
100 TiB/mo~3,367 GiB/day wire$919$11.0K$9$11.8K$142.1K$118
500 TiB/mo~16,833 GiB/day wire$4.6K$55.4K$9$47.8K$573.4K$96

Per-tab TCO comparisons above may still show signal-specific assumptions (e.g. TSDS metrics at 25% of Complete on Serverless, logs 1.66× metering) for vendor parity. This table is the unified schemaless block view: same ingested TiB/month for any mix of logs, metrics, and traces. Serverless column uses Complete-tier math with Streams defaults; retention slider (1 mo) applies to Serverless tiering. ECH column ignores that slider and uses 1d hot + 25d blob. Not a quote — confirm with your account team and Elastic Cloud pricing.

Configuration

100/sec
1/sec1.00M/sec
10

Each tag multiplies your metric volume by this number

Elastic Serverless retention (Complete tiers)

Serverless only: baseline comparison when Streams shaping is off. Billed Elastic Serverless costs always include Streams policies below. ECH ignores this slider — it uses fixed 1-day hot · ILM → blob (writable frozen) per Cloud Hosted pricing.

1 mo13 mo15 mo

Default: Observability Complete tier table from cloud.elastic.co — Complete tier table × 25% for TSDS metrics on Serverless. ECH metrics bill 1d hot + ILM blob on indexed volume (plus $200/mo cluster minimum).

Elastic Cloud Hosted (ECH)

All ECH rows always use 1-day hot · ILM → blob (writable frozen) — 1-day data hot (RAM-hour) plus 25-day ILM on blob (writable frozen, queryable in Kibana). Full-fidelity ingest; no Streams sampling on ECH.

Elastic Serverless · Streams TCO (always on)

All Serverless Elastic pricing uses default Streams policies: drop (~35% logs), aggregate (TSDS metrics), downsample, and per-signal retention — plus Observability Complete ingest/retention tiers. Adjust levers below; ECH is not shaped by Streams.

Serverless savings vs unshaped
26%
~$3/mo on this tab
Retention: 90d
Open Streams in Kibana →
Example wired streamSignalProcessingRetention
metrics-generic-defaultmetricsDownsample · TSDS90d
metrics-apm.internal-defaultmetricsAggregate · ILM90d

Datadog host licensing

Infrastructure Pro ($15/host/mo) on Metrics and APM Pro ($31/host/mo) on Tracing. Host count comes from infrastructure inventory or log GB/day (10 GB/day ≈ 250 hosts) — not from metrics/sec volume.

Estimated 250 hosts (linux/windows/k8s-node inventory, or log GB/day ÷ 0.04 GB/host/day)

Human / Operational Costs

Self-hosted platforms require engineering time to operate. Enable to see true TCO.

$60/hr$120/hr$250/hr

Default $120/hr ≈ $250k/yr fully-loaded (salary + benefits + overhead)

Network Egress Costs

Egress costs excluded from calculations. Enable to see full TCO including data transfer costs.

Metric Volume Impact

Metric Source
Mixed
320 bytes/datapoint
Metrics per Second
100/sec
Monthly Metrics
259.20M

Federated data sources

Query and land observability data without treating object storage as a dead archive. Elastic can read federated datasets for ES|QL and dashboards, and write snapshots, exports, and connector pipelines back to cloud storage — data stays under your IAM policies.

Example · Amazon S3
Object storage

SSE-KMS · bucket policies · lifecycle to Glacier optional

Federated
connector · repository
IAM role · least privilege
ES|QL FROM externalSLM / connector sync
Elastic Serverless
Origin project
  • Kibana · Discover · ES|QL · dashboards
  • Cross-project search to linked o11y projects
  • Same query plane for hot data + federated S3
FROM s3://elastic-o11y-archive/logs/*
| WHERE @timestamp > NOW() - 24 hours
| STATS count = COUNT(*) BY service.nameRead: federated ES|QL over s3://elastic-o11y-archive/logs/*
Write: SLM repository + connector bulk index
Read path

Analysts query cold archives and partner buckets in place. No full re-ingest into hot tier unless you choose to promote data via a connector.

Write path

ILM searchable snapshots, compliance exports, and connector sync jobs write structured objects back to S3 for durability and cross-region DR.

TCO note

S3 storage + API requests are billed by AWS; Elastic charges ingest/retention on promoted or hot-tier data. Federated read avoids duplicating bytes on hot RAM.

Illustrative architecture for customer conversations. See Cross-project search, S3 snapshot repository, and Elastic connector docs for your deployment type.

TCO Comparison*

Internal estimates only — not validated by Elastic Product, Marketing, or Competitive Intelligence. Confirm with official pricing and customer usage before external quotes.

Compare platforms — ECH, Serverless & Datadog shown by default
Elastic Serverless
$968$11,612/yr· 0.2× max
21%
Elastic Cloud Hosted (ECH)
$1,161$13,928/yr· 0.2× max
25%
Datadog
$4,710$56,520/yr
100%

Costs include estimated operational overhead ($120/hr fully-loaded engineer rate). Toggle in Configuration panel.

Pricing is based on publicly available list rates as of July 2026 (AWS us-east-1 Serverless and Cloud Hosted pricing tables). Elastic Observability Serverless Complete and TSDS metrics rates per elastic.co pricing (TSDS metrics effective July 1, 2026). All figures are estimates — actual costs vary with negotiated discounts, committed use, and deployment configuration. Use the Full Stack TCO tab for a complete cross-signal comparison. Contact your SA for a custom TCO analysis.