Frequently asked questions

Everything you need to know about Search Guard, licensing, and getting started.

Can't find your answer? Talk to us — we reply within one business day.

About Search Guard

Search Guard is an enterprise security and alerting suite for Elasticsearch and Kibana. It adds authentication, role-based access control, document- and field-level security, audit logging, encryption at rest, and alerting to your Elastic Stack — everything regulated organizations need to run Elasticsearch securely and stay compliant.

Search Guard covers the full security lifecycle of an Elasticsearch cluster: TLS encryption for all traffic, authentication via LDAP, Active Directory, SAML, OpenID Connect, Kerberos, and JSON Web Tokens, role-based access control down to individual documents and fields, Kibana multi-tenancy, comprehensive audit logging, encryption at rest, and the Signals alerting module for monitoring your data and triggering notifications via email, Slack, PagerDuty, Jira, webhooks, and more.

Elasticsearch ships with basic security features free of charge, and for simple setups they may be all you need. Search Guard is built for organizations that need more: enterprise authentication (SAML, OpenID Connect, LDAP/Active Directory), fine-grained document- and field-level security, full audit logging for compliance, encryption at rest, and multi-tenancy — combined with a simple per-cluster license that doesn't grow with your node count, and support delivered directly by the engineers who build the product.

Organizations of every size that run Elasticsearch — with a special focus on regulated industries such as finance, healthcare, government, research, and critical infrastructure, where access control, auditability, and data protection are mandatory. Search Guard is trusted by enterprises, universities, and public institutions worldwide.

Search Guard is developed by floragunn GmbH, a security software company based in Berlin, Germany. We have been securing Elasticsearch clusters since 2013 and develop, host, and support Search Guard entirely from Germany.

The Community Edition is open source under the Apache 2.0 license — free forever, including for commercial use. The Enterprise and Compliance Editions require a license for production use. Search Guard is developed transparently: our source code repositories and issue trackers are publicly viewable.

Editions & Pricing

Search Guard comes in three editions. The Community Edition is free forever and includes essential security features plus the complete Signals alerting module. The Enterprise Edition adds advanced security features such as LDAP/Active Directory, SAML and OpenID Connect authentication, document- and field-level security, and audit logging. The Compliance Edition includes everything in Enterprise and adds features designed for regulatory compliance with GDPR, HIPAA, SOX, PCI, and ISO — such as read-access tracking for sensitive data. See the full feature comparison.

We license Search Guard per production cluster — not per node. You can scale your cluster to any number of nodes without your license cost ever changing. Development, staging, and QA systems are included free of charge. One license, one predictable price, unlimited growth.

Yes. The Community Edition is licensed under Apache 2.0 and is free for any use, including commercial production use, with no time limit and no node limit.

A production cluster is any cluster serving live workloads. All non-production systems that support it — development, staging, testing, QA — are covered by the same license at no extra cost. If your setup doesn't fit neatly into that definition (for example, disaster-recovery or standby clusters), just ask us — we'll find a sensible arrangement.

Yes. Universities, research institutions, and non-profit organizations can obtain Search Guard's full feature set under special conditions. Get in touch and tell us about your institution.

Yes. If you ship a product or managed service built on Elasticsearch, we offer OEM licenses that let you embed and redistribute Search Guard. Contact us for details.

Send us your number of production clusters and the edition you're interested in via the contact form — you'll receive a quote within one business day. Prefer to talk it through? Book a call with our team.

Free Trial & Getting Started

Two ways, depending on how you like to evaluate. Hands-on: start a free trial of the Enterprise or Compliance Edition — the full feature set, on your own infrastructure. Guided: book a demo and one of our engineers will walk you through Search Guard live and answer your questions.

One Docker command gives you a complete Elasticsearch + Kibana + Search Guard environment on your local machine in seconds — see the quick start in our documentation. No configuration required.

No. The trial requires no payment details and ends automatically — there is nothing to cancel.

Nothing disruptive: your cluster keeps running. To continue using Enterprise or Compliance features in production, simply obtain a license. If you need more time to evaluate, tell us — trial extensions are usually no problem.

Yes. Our engineers regularly help teams migrate existing security configurations to Search Guard and can advise on mapping your current users, roles, and permissions. Book a call and tell us about your setup.

Compatibility & Versions

Search Guard supports the current Elasticsearch major version — including the latest Elasticsearch 9.x releases — with critical fixes also provided for the previous major version, following our end-of-life policy. For the exact mapping of Search Guard releases to Elasticsearch and Kibana versions, see the always-current version matrix in our documentation.

Yes — Search Guard ships a Kibana plugin providing login, role-based access, and multi-tenancy, released in lockstep with the Elasticsearch plugin. The version matrix shows the matching versions.

Our build and test pipeline is triggered automatically by new Elasticsearch releases, so matching Search Guard versions typically follow within days.

FLX is the current generation of Search Guard — a rewrite that made configuration simpler and more robust. If you're starting today, FLX is what you'll install; if you're upgrading from an older Search Guard version, our upgrade guide walks you through the transition.

Security, Compliance & Trust

Yes — that is what the Compliance Edition is built for. Field- and document-level security restricts who sees sensitive data, audit logging and read-access tracking document who accessed what and when, encryption at rest protects stored data, and configuration change tracking supports your audit trail. Many Search Guard customers operate under exactly these regulations.

Entirely in Germany. floragunn GmbH is headquartered in Berlin, and Search Guard is developed, maintained, and supported from the EU — relevant for organizations with data-sovereignty requirements or EU-based procurement policies.

We take a security-first approach to our own product: floragunn is an authorized CVE Numbering Authority, and we publish security advisories and maintain a responsible-disclosure process. Details are on our security information page.

We are members of the Alliance for Cybersecurity (an initiative of the German Federal Office for Information Security, BSI) and TeleTrusT, the German IT security association. Our development process includes continuous security scanning of the codebase.

No. Search Guard runs entirely inside your infrastructure and does not transmit telemetry, usage data, or cluster contents to us or anyone else. Your data stays where it belongs: with you.

Support

SLA-based support directly from the people who build Search Guard — your ticket is answered by the engineers who wrote the code, not a first-level call center. Response times are defined in your license agreement.

The community forum is free for everyone, and our team is active there. Documentation, including step-by-step guides and troubleshooting, is freely available at docs.search-guard.com.

Post in the community forum or open an issue in our public issue tracker. License customers can additionally use the support channels defined in their agreement.

Still have questions?

Three ways forward, depending on where you are:

Can't find what you're looking for?

No worries, maybe we can help you find the answer.
contact us
Sign up for Search Guard Newsletter