Everything Elasticsearch needs to be enterprise-ready

Security, alerting, encryption at rest, and index management — one plugin, one flat license per cluster, unlimited nodes. Built and supported in Germany since 2013.
  • No credit card
  • Full feature set
  • Dev & staging always free

Why teams choose Search Guard

Security beyond the basics

Elasticsearch ships with essential security built in. Search Guard adds what enterprises actually run on: SAML, OpenID Connect, LDAP and Active Directory, document- and field-level security, Kibana multi-tenancy, and audit logging that satisfies your compliance team.

One flat license per cluster

Licensed per production cluster — never per node. Scale from 3 nodes to 300 without your costs moving an inch. Development, staging, and QA systems are always free.

One plugin instead of five tools

Alerting, encryption at rest, index lifecycle management, and anomaly detection ship in the same plugin as security. One download, one upgrade path, one support contact — no integration project.

Support by the people who build it

Your ticket is answered by the engineers who wrote the code — with SLAs, directly from Berlin. Developed, hosted, and supported entirely in Germany.

One plugin. The complete toolkit.

Search Guard grew from securing Elasticsearch into everything around it — alerting, encryption, and index operations included.

Security

Authentication, role-based access control down to fields and documents, multi-tenancy, and full audit logging.

Alerting

Watch your data around the clock. Escalate through email, Slack, PagerDuty, Jira, and webhooks — free in every edition.

Encryption at Rest

Encrypt indices at the Lucene level. Keys stay in memory, never on disk — ready for the EU Cyber Resilience Act.

Index ManagementPreview

Automate rollover, retention, and deletion policies. Keep clusters lean without cron-job archaeology.

Anomaly DetectionPreview

AI-assisted detection of unusual patterns in your data — find what rule-based alerting can't.

Preview features are included in every trial — try them and tell us what you think.

Search Guard is trusted by

  • Red Hat
  • ObjectRocket
  • Würth Phoenix
  • SieMonster
  • UNIL Universite de Lausanne
  • Mitratech
  • KubeDB
  • Siren Investigate

Trusted where security is non-negotiable

Since 2013

Securing Elasticsearch clusters for over a decade

CVE Numbering Authority

Authorized by MITRE to issue CVEs

BSI Alliance & TeleTrusT

Member of the Alliance for Cybersecurity and TeleTrusT

Made in Germany

Developed, hosted, and supported in the EU

See it running in 60 seconds

docker run -it --rm -p 5601:5601 -p 9200:9200 floragunncom/search-guard-flx-demo

One command: Elasticsearch, Kibana, and Search Guard, preconfigured on your machine.

Full quickstart guide

Simple pricing: per cluster, not per node

One flat license per production cluster — unlimited nodes, dev and staging free. Your cluster grows; your costs don't.
standard editions
academic & custom
community icon
Search Guard Community Edition
  • Free forever. Apache 2.0 licensed
  • Essential security plus full alerting
  • Unlimited nodes, unlimited clusters
enterprise icon
Most popular
Search Guard Enterprise Edition
  • SAML, OIDC, LDAP / Active Directory
  • Document- and field-level security
  • Audit logging and SLA support
compliance icon
Search Guard Compliance Edition
  • Everything in Enterprise, plus:
  • GDPR, HIPAA, SOX and ISO tooling
  • Read-access tracking for sensitive data
We offer an
Academic & Scientific License
, as well as
Custom Licenses
for your personal needs.

What our clients say

  • quote icon
    Search Guard met all of our needs and more. Not only have we found open source tools that meet our needs, but we've found a partner that's worked with us through the development of the new platform. They've been responsive and engaged every step of the way.
    - Steve Croce
    Senior Product Manager and Head of User Experience
    ObjectRocket
    quote icon
  • quote icon
    Security is paramount to the protection of our customer's data. ICHEC chose Search Guard to protect its ELK-Stack environment because of its Single Sign-On authentication integration, access control measures and audit features. The licensing model is also flexible enough as we continue to grow our services.
    - Tim Murphy
    System Administrator
    Irish Centre for High-End Computing (ICHEC)
    quote icon
  • quote icon
    Security is the prerequisite for every project in the IT industry, especially when it comes to data. HEAnet chooses Search Guard to protect its ELK cluster because it provides node-to-node encryption (TLS) and more features such as multi-tenancy, compliance, unlike its competitors who only provide security on the REST layer.
    - Yasvanth Babu
    Middleware System Administrator
    HEAnet CLG
    quote icon
  • quote icon
    The Steinbuch Centre for Computing at KIT is using Search Guard to secure Elasticsearch instances operated in the World Wide LHC Computing Grid Tier-1 center "GridKa" and in the Large Scale Data Facility. Without fine-grained access control we would be unable to expose Elasticsearch to individual users or use single instances for both private and public data. The multitenancy features for Kibana offered by Search Guard are specially useful, enabling us to also use Kibana for public dashboards.
    - Andreas Petzold
    Manager "GridKa" WLCG Tier-1 Center
    Karlsruhe Institute of Technology (KIT) Steinbuch Centre for Computing (SCC)
    quote icon
  • quote icon
    Search Guard makes it possible for us to use the ELK-Stack in a productive environment. We chose Search Guard primarily because of the Active Directory and role-permission features. We find their licensing model incredibly helpful, as well as the fact that we are able to use an unlimited amount of nodes.
    - Arno Haß
    Project Manager
    Max-Delbrück Centre for Molecular Medicine
    quote icon
  • quote icon
    We have chosen SearchGuard because it matches our values of technical rigor, openness, and auditability. It has enabled us to ensure that data in transit is secure against eavesdropping in off-prem environments, to implement verifiable and granular access to our Elastic clusters, and most importantly to give our analysts access to restricted data sets with confidence that PII remains protected and confidential.
    - Tom
    Deflect (DDoS protection CDN) & Deflect Labs (DDoS research)
    quote icon
  • quote icon
    In 2019 we planned to install one large logging infrastructure cluster for about 100TB of data. Not as SIEM, but mainly to have logs available centrally for developers and admins. We chose one Elasticsearch instance as a large log repository. We decided to install the 8 data nodes and 10 VMs with one contractor. He proposed two solutions to us for the "role-based access control" software. After testing, we quickly adopted SearchGuard. We actually send all our critical logs to this cluster. About 15 users can log in to the system and see what they are looking for. With SearchGuard we can easily limit access to the logs of their applications only. The right segregation is working well, and we are happy with the solution we chose for the user's access control.
    - Y. Ghennai
    Universite de Lausanne
    quote icon

Ready when you are

Try it yourself

Full feature set on your infrastructure. No credit card, nothing to cancel.

See it live

30 minutes with an engineer who builds Search Guard. Your questions, live answers.

Get your quote

Tell us your cluster count — quote within one business day.
Sign up for Search Guard Newsletter