Three Fronts

Three Fronts

Elastic sells one platform into three markets — search/AI, observability, and security — and on each it faces a larger, faster-growing, better-funded focused leader. Its consolidated 17.3% revenue growth is the slowest in the peer set bar one, and Datadog alone spends nearly Elastic's entire revenue on research and development. Yet independent analysts rank Elastic a Leader in observability and SIEM, and its near-breakeven GAAP operating margin beats most peers. The position is credible on every front and dominant on none.

Where Elastic actually competes

The competitor list in Elastic's own 10-K is the cleanest map of the battlefield, and how it has changed is itself a finding. In FY2022 the first bucket was "Enterprise Search," pitched against Apache Solr, Lucidworks, Google Programmable Search, and workplace-search tools like Coveo and Oracle's Endeca [1]. By FY2026 that bucket had been renamed "Search & AI" and repopulated: alongside Algolia, Solr, and Coveo now sit native vector databases (Pinecone, Qdrant, Weaviate), database platforms with integrated vector search (MongoDB Atlas), and hyperscaler AI-search services — Google Gemini Enterprise (formerly Vertex AI) and Microsoft Azure AI Search [2]. The search front stopped being a contest against legacy enterprise-search vendors and became a contest for the AI-retrieval layer — the same shift that re-armed the open-source funnel (Open Source Moat).

No Results

Source: Elastic FY2026 Annual Report (Form 10-K), Competition [3]; Cisco's 2024 acquisition of Splunk per Dynatrace FY2026 10-K [4].

The three markets are also consolidating around scale. Cisco absorbed Splunk in 2024 — until then Elastic's most-cited rival in both observability and security — and Palo Alto acquired Chronosphere, moves a peer's own filing flags as evidence of low barriers letting large platforms buy their way in [5]. Elastic remains independent and mid-sized while the competitive fields around it gather behind fewer, larger names.

The scale and growth gap

Against every focused peer, Elastic is smaller and — bar tiny Coveo — slower-growing. The point is not that any one number is alarming; it is that the pattern repeats across all three fronts. Datadog, the observability leader, is roughly twice Elastic's size and grew 27.7% last year. CrowdStrike, the security leader, is nearly three times larger. MongoDB, the closest scaled comparison on the search/vector front, is larger and growing faster. Elastic's 17.3% sits at the bottom of the scaled group.

No Results

Source: latest fiscal-year financials as reported (Elastic FY2026; peers FY2025–FY2026 10-Ks); growth, R&D, and operating margin computed from reported figures.

Loading...

Source: latest fiscal-year revenue as reported, each company's most recent 10-K; growth computed from reported figures.

The resource gap is starker than the revenue gap. Elastic spent $452M on research and development in FY2026, about 26% of revenue — a healthy rate [6]. But Datadog's $1.55B and CrowdStrike's $1.39B research budgets each run more than three times larger in absolute dollars, and on the search/AI front the relevant rivals are Microsoft, Google, and Amazon, whose platform R&D is measured in tens of billions. Elastic's own filing states the point plainly: many competitors have "substantially greater financial, technical and other resources," larger sales forces, and more mature intellectual-property portfolios [7]. A consumption-priced platform can out-innovate on focus, but it cannot out-spend these balance sheets.

One caveat bounds this comparison. Elastic reports revenue as a single line and does not break out search, observability, or security [8]. Datadog's 28% is a pure-observability number; Elastic's 17% blends three businesses of unknown relative health. Whether Elastic is losing observability share or simply carrying a slower mix cannot be settled from the disclosure — an absence that is itself part of the discount the market applies (What the Price Pays).

Credible on capability

Sub-scale is not the same as losing, and the capability evidence cuts the other way. Independent analysts place Elastic among the leaders on the fronts where it is measured: a Leader in the 2025 Gartner Magic Quadrant for Observability Platforms, a Leader in the IDC MarketScape for Worldwide SIEM 2026, and a Strong Performer in the Forrester Wave for Extended Detection and Response — recognition that spans both observability and security, not a single niche. These are third-party assessments of vision and execution, and they are consistent with a platform that competes on features rather than being out-engineered.

The GAAP margin comparison reinforces the same read. Elastic's operating margin of −1.9% is thinner than Dynatrace's genuinely profitable 12.2%, but it is better than Datadog (−1.3%), CrowdStrike (−6.1%), MongoDB (−5.6%), and SentinelOne (−32.1%). All of these figures are distorted by heavy stock-based compensation, so the level matters less than the ranking: Elastic is not spending its way to growth any more aggressively than the peers who are outgrowing it. Its own filing rests the defense on breadth — few competitors "have the capabilities to address our entire range of use cases" [9]. A customer that wants one data store across logs, search, and security telemetry has fewer alternatives than the front-by-front lists suggest. Whether that breadth wins deals faster than focused rivals grow cannot be settled from the single-line disclosure.

The retrieval bet and the hyperscaler paradox

The part of the case most exposed to competition is also the part carrying the most upside: AI retrieval. Elastic has repositioned Elasticsearch as a vector database and retrieval layer for enterprise AI, and the high-value AI cohort is growing (Growth Engine). But the FY2026 competitor list shows who owns the other side of that market — Pinecone, Weaviate, and Qdrant as well-funded pure-plays, MongoDB Atlas as an integrated incumbent, and Google and Microsoft embedding AI search directly into their clouds [10].

Elastic names the threat itself. Its risk factors warn that competitors may "more successfully incorporate AI," secure superior access to AI technologies, and win "more strategic partnerships with key AI providers," and — the sharper risk — that "enterprise adoption of AI may significantly transform our competitive landscape" as customers vertically integrate or use AI to build their own tooling, "reducing the need to purchase third-party solutions such as ours" [11]. This is the same paradox that runs through the moat: the hyperscalers Elastic runs on — AWS, Google Cloud, Microsoft Azure — are simultaneously its distribution channel and, on the search/AI and security fronts, its most resourced competitors. AWS already ships a forked OpenSearch; Google and Microsoft now offer native AI search and SIEM. The channel that carries Elastic Cloud is also building the "good-enough" bundle that could cap it.

The competitors, for their part, act like they are winning. Datadog told investors it has "not observed any significant changes in our competitive landscape" and continues to "gain market share from larger competitors" [12]. That is a scale leader's read, not a neutral one, but it is the posture Elastic must displace on the observability front.

Reading the position

The measured read is mixed. Elastic carries analyst-Leader placements and a respectable margin profile, which argues the product is not the problem; it also carries the slowest growth and the smallest research budget in its scaled peer group, which argues that focus and balance-sheet depth are winning the compounding race. The breadth thesis — one platform beating three point solutions — is plausible but unproven in the disclosure, because Elastic does not show revenue by front.

The strongest fact against a bearish reading: near-breakeven GAAP margins that beat most faster-growing peers, plus independent Leader status, mean "sub-scale" is not "outcompeted." What would move the read toward the bull case is evidence that platform consolidation is actually winning multi-solution deals faster than focused rivals grow — visible in net expansion re-accelerating and the sales-led base outrunning peer growth — together with AI-retrieval consumption compounding ahead of hyperscaler bundling. What would move it the other way is the reverse: Datadog and CrowdStrike holding their growth premium while Elastic's search/AI edge is absorbed into the clouds it depends on for distribution.