That's the whole model. No node counting, no resource metering, no surprises at renewal.
Every feature, every edition — in detail:
Works with Kibana, Logstash, Beats, cross-cluster search and replication, Elastic Stack Monitoring and Machine Learning — in every edition.
| Feature | Community Free forever · Apache 2.0 | Enterprise Most popular Per production cluster · unlimited nodes | Compliance Everything in Enterprise, plus audit-grade compliance |
|---|---|---|---|
| Enterprise authentication & SSO | |||
| LDAP / Active Directory Authenticate and authorize users against LDAP or Active Directory | – | ||
| Kerberos / SPNEGO Ticket-based single sign-on in Kerberos and Active Directory environments | – | ||
| JSON web tokens Stateless authentication with signed JSON web tokens | – | ||
| OpenID Connect Log in via any OIDC identity provider, e.g. Keycloak or Okta | – | ||
| SAML Single sign-on with SAML 2.0 identity providers | – | ||
| Custom authentication backends Plug in your own authentication and authorization implementations | – | ||
| Kibana Single Sign-On Sign in to Kibana once through your identity provider | – | ||
| Fine-grained access control | |||
| Document-level security Control which documents each user can see within an index | – | ||
| Field-level security Show or hide individual fields per role | – | ||
| Kibana multi-tenancy Separate dashboards and saved objects per team or tenant | – | ||
| Field anonymization Mask sensitive values like names or IPs before they are returned | – | – | |
| Immutable indices Write-once storage for tamper-proof data | – | – | |
| Audit & compliance logging | |||
| Security audit logging Record login attempts, missing privileges and security events | – | ||
| Read-access tracking Document who read which sensitive data, and when | – | – | |
| Write-access tracking Track every change to monitored indices | – | – | |
| Configuration change tracking Track every change to the security configuration | – | – | |
| System change tracking Monitor the integrity of your Elasticsearch configuration | – | – | |
| Alerting integrations | |||
| PagerDuty action Open PagerDuty incidents directly from your alerting watches | – | ||
| Jira action Create Jira issues automatically when alerts fire | – | ||
| Operations & configuration | |||
| REST management API Manage the entire security configuration via API | – | ||
| Configuration GUI Point-and-click administration in Kibana | – | ||
| Support | |||
| Community forum Ask questions and get answers from the community and the team | |||
| SLA-based support Tickets answered by the engineers who build Search Guard | – | ||
Everything in Community, plus:
Everything in Enterprise, plus:
Not sure which edition fits? Talk it through with an engineer →
Tell us how many production clusters you run and which edition you're interested in — you'll have a quote within one business day. No calls unless you want one.
Prefer a conversation? Book a demo with an engineer →
More questions? See the full FAQ →