Quick ReadPlain-language overview · read this first
Elastic is a subscription-led enterprise software company that sells the mature search foundation into three major use cases: search, observability, and security. It is also extending into vector retrieval and GenAI RAG (retrieval-augmented generation, which feeds large models real-time, trusted, permission-controlled context). The report rates the stock Hold. The product line has moved beyond standalone Elasticsearch into a retrieval-centered relevance engine, multimodal embeddings, and Agent Builder. The company calls itself The Search AI Company.
The fundamentals are already stronger than the market perception. FY2026 revenue was USD 1.739 billion, up 17% year over year; cRPO (current remaining performance obligations, meaning contracted amounts to be recognized over the next year) was USD 1.203 billion, up 20% year over year, faster than revenue, showing that large customers are signing larger and longer contracts. Operating cash flow was USD 327 million, adjusted free cash flow margin was about 20%, and net cash was about USD 795 million. The company can already self-fund and repurchased USD 340 million of stock. GAAP profit was distorted by a one-time reversal of about USD 435 million in deferred tax assets, so the report does not use P/E for valuation. What still needs proof is standalone monetization from Search AI: management only disclosed that more than 600 customers with annual spend above USD 100,000 are using AI, without breaking out AI's ARR (annual recurring revenue) contribution, so more quarters are needed for validation. Competitively, Elastic sits at the intersection of three battlegrounds, facing Datadog, Dynatrace, CrowdStrike, Microsoft Sentinel, MongoDB, and AWS OpenSearch. Its edge is unification rather than being the strongest point solution, while OpenSearch, as a compatible fork, will continue to cap commoditized pricing over the long term.
Valuation should be viewed through EV/Sales (enterprise value to revenue) and the Rule of 40 (revenue growth plus profit margin should exceed 40). At the current price of about USD 60.35 and a market cap of about USD 6.4 billion, forward EV/Sales is about 2.8x, placing it at the cheapest end of the peer group, and FY2026 is close to the Rule of 40. The report classifies the current price as suitable to Hold, with a reasonable holding range of USD 58 to USD 69, a better entry point below USD 52, and a clear overvaluation line above USD 79. There are two main risks: AI adoption rises but does not translate into larger budgets, leaving retrieval as a retention enhancer rather than a new profit pool; and multiple compression toward around 2.1x EV/Sales, implying a maximum drawdown of about 25%. The report takes a restrained view: this is a stock that has not yet completed a rerating but already has the prerequisites for one, and price discipline matters more than chasing the stock.
The above is a summary of the report's views and does not constitute investment advice. The stock market involves risk; invest with caution.
LeadElastic is a subscription-led enterprise software company that sells its search foundation into search, observability, and security, while extending into vector retrieval and GenAI RAG. The improvement in contracts, cRPO, and cash flow has been demonstrated, but independent monetization of Search AI still needs several more quarters of proof. Research rating Hold: the current price of USD 60 sits in an acceptable holding zone, while a more attractive entry point is below USD 52.
Prices in the article are as of publication; see the valuation band above for the live price.
Metadata
Ticker: ESTC.US
Company name: Elastic N.V.
Current price and market cap: USD 60.35 / USD 6.409 billion, as of the latest trading day on 2026-06-12
Currency: USD
Report date: 2026-06-14
Industry classification: Enterprise software
One-sentence positioning: A subscription-led enterprise software vendor that sells a search foundation into search, observability, and security.
The research scope of this report uses 2026-06-14 as the base date and covers Elastic N.V.'s businesses related to search, observability, security, vector retrieval, and GenAI RAG. The investment perspective is an editorially selected comprehensive study, with a horizon covering both the next 12 months and 3 to 5 years. The valuation framework mainly uses common SaaS metrics such as EV/Sales, implied ARR, Rule of 40, and cash-flow look-through, rather than P/E as the basis for the core conclusion. One point needs to be made clear: although Elastic is incorporated in the Netherlands, its latest annual report and quarterly results are disclosed in the U.S. SEC system through Form 10-K and Form 8-K. This report gives highest priority to those primary disclosures.
Research Summary
The most important question for Elastic today is whether it can repackage search, a mature underlying capability, into essential infrastructure for the AI era, rather than whether it is an old-line search company. The company began with Elasticsearch and the Elastic Stack, turning enterprise search and log analytics, which used to be complex, expensive, and hard to scale, into software that developers were willing to adopt and enterprises would then pay for through subscription support and advanced functionality. Its external narrative has clearly changed. The website now defines Elastic as "The Search AI Company," and the product line is no longer just Elasticsearch. It spans search, observability, security, and RAG-related products such as the Elasticsearch Relevance Engine, Elastic Inference Service, Agent Builder, and the Jina multimodal model family. In FY2026, Elastic generated USD 1.739 billion of revenue, up 17% year over year. Q4 revenue was USD 451 million, up 16%; subscription revenue was USD 422 million, up 17%; sales-led subscription revenue was USD 375 million, up 19%; and cRPO was USD 1.203 billion, up 20%. These numbers say two things: the legacy business has not collapsed, and the new narrative is starting to lift contractual commitments.
The market is trading Elastic around a more specific repricing path, rather than the broad question of whether it will suddenly become the next Datadog or CrowdStrike. If, after GenAI applications become widespread, enterprises find that what they truly lack is a retrieval layer that connects private data, real-time context, access control, logs, alerts, and workflows, rather than the large models themselves, Elastic could move from being a diversified player that is not clearly first in any battlefield to one of the few veterans in the AI retrieval foundation that can be deployed directly into production systems. Management repeatedly emphasized on the FY2026 Q4 call that AI use cases have already penetrated more than one-third of the customer cohort with ACV above USD 100,000. More than 600 customers with ACV above USD 100,000 are using AI capabilities. In FY2026, Elastic added more than 30 customers with annual ACV above USD 1 million, taking the total to more than 240, while the number of customers with annual spend above USD 5 million grew 30%. This is already a stage where large contracts, longer agreements, and signs of platform standardization are appearing. It is no longer enough to wave through the story with a simple "AI beneficiary" label.
Elastic's past share-price swings have broadly tracked changes in its capital-market identity. At the 2018 IPO, it told a high-growth SaaS story around the commercialization of open-source search. At the 2021 peak, the market valued it as high-multiple cloud software. Since then, amid rising rates, software-sector multiple compression, slower growth, and concerns that AI might erode the value of traditional software, the share price has retraced sharply. Macrotrends data show that Elastic's all-time closing high was USD 186.78 on 2021-11-16, while by the latest trading day on 2026-06-12 the price had fallen back to USD 60.35. Even after the 2025 analyst day introduced a USD 500 million buyback framework and higher medium-term targets, and after Q4 2026 laid out a new framework of accelerating growth plus higher FY27 margins, the market has not lifted it back into the high-growth SaaS camp. The reason is simple: Elastic's story has become bigger, but investors are still waiting for harder evidence of delivery.
The most important bull-bear debate now centers on three questions. First, can search truly become a second growth curve, rather than a foundational capability steadily eroded by vector databases, cloud-provider retrieval services, and open-source alternatives? Second, is Elastic's "one platform for search, observability, security, and AI retrieval" a cross-sell advantage, or will it cause Elastic to lose to purer best-of-breed vendors in each category? Third, does the current valuation, at roughly 3.2x historical EV/Sales and roughly 2.8x FY2027 guided EV/Sales, mean the stock is cheap, or does it mean the market still does not believe in generative AI monetization? Based on FY2026 year-end cash and marketable securities of USD 1.370 billion, senior notes of USD 575 million, and a market cap of USD 6.409 billion, enterprise value is roughly USD 5.61 billion, materially below comparable assets with cleaner AI software narratives such as Datadog, CrowdStrike, and MongoDB. It is genuinely cheap, but the discount also has real reasons.
In one phrase, I would characterize Elastic as a company "in valuation reconstruction," rather than a high-quality compounder or a mature cash cow. It has moved beyond the pure cash-burn phase of an early SaaS company. FY2026 operating cash flow was USD 327 million, adjusted free cash flow margin was about 20%, management set a FY2027 non-GAAP operating margin target of roughly 19% and an adjusted free cash flow margin target of roughly 21.5%, and it lifted the FY2029 medium-term non-GAAP operating margin target from above 20% to around 25%. This shows that the company is moving from proving it can grow to proving it can expand profitability while growing. At the same time, FY2026 GAAP net income was boosted by a one-off reversal of about USD 435 million in deferred tax valuation allowance, stock-based compensation remained as high as roughly USD 308 million for the full year, and the long-term price ceiling created by the OpenSearch fork still exists. This is not a name where one can simply conclude that GAAP profitability has turned positive and stop the analysis.
My qualitative label is: in valuation reconstruction. There are three reasons. First, fundamentally it is already stronger than the market's impression: subscription-based, net cash, ongoing buybacks, accelerating cRPO, and more million-dollar ACV customers. Second, commercially it is still shifting from "log and search tool" to "AI retrieval and operations foundation," and the transition is not yet complete. Third, capital-market pricing remains clearly conservative, meaning a rerating has not happened, or has happened only halfway. Whether the stock can complete a genuine valuation reconstruction will depend on two hard outcomes, not on how well it talks about AI: whether Elastic Cloud consumption and commitments continue to rise, and whether ESRE, vector retrieval, multimodal embeddings, and Agent Builder can turn "interested in trying AI" into "sustained expansion of AI consumption."
Company Development History
Origins and IPO Path
Elastic began as a classic technical community project, not as an enterprise software company that first built a sales motion and then searched for a product. Shay Banon became interested in search in 2004 while looking for a better search solution for his wife's recipe application. He wrote the initial Elasticsearch code in 2009. In 2012, Steven Schuurman, Uri Boness, Simon Willnauer, and Shay Banon co-founded Elastic. This origin matters because it shaped Elastic's DNA: it started from the real problems of developers and operations engineers, then gradually became enterprise-ready, rather than first defining a budget category and then inserting itself into an IT procurement process. In its own corporate history, Elastic places the Lucene community, distributed search, and an open ecosystem near the front, which also explains why it later expanded naturally into log analytics, observability, and security.
The industry backdrop was also clear. This was a period when data volumes were exploding, system architectures were migrating from monoliths to distributed systems, and traditional relational database queries and old enterprise search were increasingly unable to meet the need for real-time indexing and full-text search. When Elasticsearch was born, the first problem it solved was the searchability of massive, heterogeneous, real-time data, rather than AI retrieval in today's sense. Its early competitors were more like traditional search engines, log analytics tools, and in-house Lucene solutions, not pure vector databases such as Pinecone. Elastic later managed to extend search into observability and security because logs, metrics, and alerts also need a foundation that can index and retrieve in real time.
The IPO path was relatively standard, but the capital market's initial understanding was clear: this was a high-growth software company converting open-source community momentum into commercial subscription revenue. Elastic announced IPO pricing on 2018-10-04, issuing 7 million ordinary shares at USD 36 per share and raising about USD 252 million. External media at the time put the market capitalization at roughly USD 2.5 billion at the offer price. The stock almost doubled on its first trading day and closed near USD 70, showing that the market strongly bought the combination of open-source commercialization, enterprise subscription, and high growth.
At the IPO, Elastic's capital-market story was essentially: "I control a data retrieval and analytics foundation that developers already widely use, and I am now commercializing advanced features, support services, and managed cloud." It was not: "I sell a search box." That story worked from 2018 to 2021 because the market was willing to pay high valuations for developer tools, infrastructure software, and subscription revenue. The problem was that after listing, the story quickly began to change. On one side, scale forced Elastic into heavier enterprise sales and large contracts. On the other, cloud providers such as AWS started packaging similar capabilities as managed services. Elastic's path to today was already embedded at the moment of listing: move up into a platform, while defending the foundation below.
Stages and Key Milestones
I divide Elastic's development before and after listing into five stages, rather than cutting mechanically by year.
The first stage was community product validation. The core growth driver in this stage was organic developer adoption, not the sales team. Elasticsearch, Kibana, Logstash, and Beats gradually formed the Elastic Stack, solving problems that engineering teams repeatedly encountered in real environments: collection, indexing, search, and visualization. The company chose to start from the open-source community rather than from closed licensed software because search and log analytics naturally require ecosystem expansion and use-case experimentation. Gaining installation volume and user habits mattered more than locking in a licensing model from day one. The long-term impact of this choice was deep: it later gave Elastic a community dividend with low CAC, while also leaving it with the permanent question of how to turn open-source enthusiasm into commercial pricing.
The second stage was enterprise transformation and IPO narrative formation. In 2017, Steven Schuurman handed the CEO role to Shay Banon, marking the move from co-founder-led expansion to direct leadership by the founder-product person. The 2018 IPO meant Elastic had to give the public market a more standardized answer: can growth continue, can subscription scale, and how will losses narrow? In this stage, the market believed in the imagination of open-source commercialization and in the natural retention and expansion space that developer infrastructure tools gain once they enter enterprise core systems. The high enthusiasm at listing effectively set a high long-term bar: afterward Elastic could not remain merely a tool that many engineers liked. It had to become a platform that could survive budget cycles.
The third stage was expansion from search foundation into security and platform. In 2019, Elastic announced the USD 234 million acquisition of Endgame, formally adding endpoint security capability. This was a key turning point in the company's history because it clearly moved beyond search and logs for the first time and entered security as an independent large market. At closing, total consideration was roughly USD 234 million, partly paid with about 2.2 million Elastic ordinary shares, plus cash to repay Endgame bank debt and transaction expenses. In hindsight, the significance of the deal was that Elastic gained the possibility of putting SIEM, EDR, logs, and investigation workflows on the same data layer. It was not mainly about short-term revenue. The large eight-figure AI-driven SIEM deal management mentioned on the Q4 call is essentially an extension of this path.
The fourth stage was commercial protection and valuation compression. In 2021, Elastic changed the Apache 2.0 portions of Elasticsearch and Kibana to dual licensing under SSPL and the Elastic License. Management described this as a way to reduce market confusion and protect the business model. AWS had earlier launched OpenSearch, explicitly defining it as an open-source fork based on Elasticsearch 7.10.2 and emphasizing compatibility with existing REST APIs and query syntax. This event had a major long-term impact on Elastic. On one hand, the license change allowed it to protect its commercial moat more clearly. On the other, it permanently created a low-cost or even free alternative, especially convenient for AWS customers. Even though Elastic added AGPL back as an option in 2024 and repaired part of the ecosystem relationship, the price ceiling and customer migration option created by the fork will not disappear.
The fifth stage is Search AI narrative rewriting. In 2022, Ashutosh Kulkarni became CEO and Shay Banon returned to the CTO role. This personnel arrangement itself says a lot: the company needed a CEO with stronger execution and a closer fit with enterprise product and sales systems, while retaining the founder's pull on the technical direction. In 2025, Elastic combined with Jina AI and made a clear bet on multimodal embeddings, rerankers, small models, and AI retrieval. In 2026, the company launched jina-embeddings-v5-omni, unifying text, image, video, and audio embeddings into a single vector space, while packaging Jina v5 omni, Agent Builder GA, third-party data connectors, Cross Project Search, and native Prometheus support on the call as the next "AI infrastructure" message. The core change in this stage is that Elastic no longer says only "we help you search data." It says, "we are the retrieval layer that provides real-time, trusted context to LLMs." If this narrative proves true, Elastic's growth ceiling can reopen. If it does not, Elastic remains a mid-growth enterprise software company fighting across multiple fronts.
Longitudinal Financial Review
Viewed over time, Elastic's financial changes in recent years are healthier than many investors assume. Operating cash flow in FY2024, FY2025, and FY2026 was USD 149 million, USD 266 million, and USD 327 million, respectively, showing steady improvement. FY2026 capital expenditure was only about USD 5.1 million, which shows this is not a model that requires sustained heavy capital investment to maintain growth. At the end of fiscal 2026, the company held USD 1.370 billion of cash, cash equivalents, and marketable securities, while carrying only USD 575 million of senior notes due 2029, leaving ample liquidity. An even more important signal is that FY2026 financing cash flow was negative USD 312 million, mainly because the company repurchased USD 340 million of stock. That means the company has entered a stage where, after creating cash, it has started active capital allocation.
Looking only at FY2026 GAAP net income would lead to a completely different conclusion. The reason Elastic's FY2026 GAAP net income looked strong was the release of a deferred tax valuation allowance, which generated a one-time tax benefit of about USD 435 million, rather than a sudden explosion in operating profit. Both the financial statements and the call made clear that this item did not affect operating results, non-GAAP EPS, free cash flow, or cash levels. This is exactly why this report does not use P/E as the core valuation tool: Elastic's accounting profit in fiscal 2026 was materially distorted by tax items. Using that number to judge whether the stock is cheap or expensive means looking at the wrong statement.
There is another issue in profit quality that must be faced: stock-based compensation remains high. In FY2026, the company disclosed roughly USD 308 million of stock-based compensation and related taxes in GAAP to non-GAAP adjustments. The 10-K cash-flow statement showed stock-based compensation of USD 298 million. Both are a high share of revenue. In a sense, the buyback is meant to offset this dilution. In FY2026, the company repurchased about 4.4 million shares at an average price of USD 76.91, totaling USD 340 million. But because equity incentives and employee stock purchase plans coexist, the buyback looks more like a dilution offset than the kind of capital return from a mature cash cow that genuinely reduces the share count. This is not rare for software companies, but it raises investor requirements for FCF conversion and true per-share returns.
Revenue drivers are increasingly skewed toward subscription and cloud. FY2026 full-year revenue was USD 1.739 billion, up 17% year over year, and Q4 subscription revenue accounted for about 94% of quarterly revenue. In Q1 FY2026, Elastic Cloud revenue was USD 196 million, up 24%, or about 47% of total quarterly revenue. The company also specifically noted in Q4 that large public-sector deals tilted the commitment mix toward Elastic Cloud, affecting the timing of revenue recognition in the quarter, but as usage ramps toward committed levels this should benefit future revenue. Combining these disclosures, it is reasonable to judge that Elastic Cloud has moved from a faster-growing product form to the core engine that determines revenue cadence and valuation elasticity. The company did not separately disclose full-year cloud revenue in the FY2026 full-year release, so the exact full-year share cannot be verified from primary disclosures.
Share Price and Valuation History
Elastic's share-price history can broadly be divided into four phases. The first ran from the 2018 listing through the pandemic period in 2020, when the market mainly valued it as a high-growth SaaS business commercializing open source. The second was 2020 to 2021, when abundant liquidity lifted cloud software valuations broadly and Elastic reached its all-time closing high of USD 186.78 on 2021-11-16. The third was 2022 to 2024, when rising rates and software multiple compression combined with slowing growth, leading to a clear retracement. The fourth is 2024 to 2026, when the market again started to price around AI/RAG, platform integration, and margin expansion, but the valuation center did not return to 2021 levels. In other words, Elastic's commercial story has not disappeared. The market is simply no longer willing to buy it on pure imagination.
The change in the valuation center reflects both market preference and a redefinition of business quality. At the preference level, the software sector's overall valuation in 2021 was far higher than today. At the business-quality level, Elastic has moved from a relatively easy-to-understand "search SaaS" into a more complex hybrid: it does search, observability, security, and AI retrieval; it has both self-managed and cloud; it has an open-source community and commercial protection; it wants AI retrieval budgets while defending the traditional log and analytics base. Complexity has risen, so the multiple investors are willing to pay has naturally fallen. Based on FY2026 year-end cash, debt, and the latest trading-day market cap, Elastic's EV/Sales is about 3.2x, and based on the FY2027 revenue guidance midpoint it is about 2.8x. This is clearly lower than Datadog, Dynatrace, CrowdStrike, and MongoDB. The valuation discount is real, but it also shows that the market wants Elastic to first prove that Search AI is more than an attractive concept.
Business Model and Industry Position
Business Model and Moat
Elastic's commercial machine looks on the surface like a pile of products, but underneath it has only one core: using the same indexable, searchable, compressible, and scalable data foundation to cover three scenarios with strong willingness to pay: search, observability, and security. In the financial statements, revenue is split into subscription and services rather than by solution. FY2026 Q4 subscription revenue was USD 422 million, while services were a small share, meaning profit still mainly comes from subscription rather than consulting or labor-intensive services. One layer deeper, Elastic is trying to earn three kinds of long-term money, not one-off licenses: managed cloud subscriptions, sales-led enterprise subscriptions, and expansion purchases around advanced capabilities and cross-scenario platformization.
I think its real moat has four parts. The first is data gravity. Elastic management explicitly made "the LLM must come to the data" a core argument in FY2026 Q4, based on enterprise reality rather than slogan. Once logs, metrics, text, vectors, audio and video, and permission systems already sit inside Elastic, the cost of moving them is high, especially in security and observability, where continuity matters. The second is integrated multimodal retrieval and hybrid semantic/lexical search. ESRE is more than a vector database. It puts keyword search, vector similarity, reranking, filtering, aggregation, and document-level permissions into one retrieval stack. The third is cross-scenario reuse: the same engine can support user search, log retrieval, SIEM investigation, and an AI RAG context layer. The fourth is deployment flexibility: Elastic can be deployed on-premises or in the cloud, which matters for large enterprises with security sensitivity, high regulatory requirements, or complex existing architectures.
But it is important to distinguish between what can be marketed as a moat and what can actually withstand competition. The open-source brand itself is no longer the moat that automatically converts into commercial advantage as it once did. After the 2021 license change, Elastic's commercial protection strengthened, but the story around community goodwill and pure open source weakened. At the same time, AWS OpenSearch, a fork based on Elasticsearch 7.10, continues to serve a large portion of "good enough" demand through API compatibility and managed-service convenience. Elastic's real moat is therefore not "I am the most open-source." It is "I iterate much faster than the fork, and I have integrated search, AI, observability, and security into a higher-value data layer." If a customer only wants a cheap, usable, convenient search and log service inside AWS, OpenSearch will continue to pressure Elastic's pricing.
At the management level, Elastic's governance structure in recent years is better suited to enterprise execution than in the early stage. Before becoming CEO in 2022, Ash Kulkarni was the company's chief product officer, with experience from McAfee, Akamai, Informatica, and Sun Microsystems, clearly skewed toward product and enterprise software operations. After Shay Banon returned to the CTO role, he remained on the board and continued to guide the technical direction. CFO Navam Welihinda has a background at Grammarly, HashiCorp, and investment firms. The significance of this combination is that the founder's technical perspective remains, while a team more focused on scale and go-to-market drives margins and sales discipline. Seven consecutive quarters of execution above guidance in FY2026, the launch of buybacks, and the higher FY2029 margin target show that the governance focus has indeed shifted from expansion first to expansion with discipline. As of the FY2026 10-K, the company had not disclosed material litigation that would have a material adverse effect on the business.
Industry and Cyclicality
Elastic sits at the intersection of three profit pools in enterprise infrastructure software, rather than in a single industry: search/retrieval, observability, and security analytics. The benefit of this position is that underlying technology can be reused. The downside is that each profit pool has its own strong players. The real sources of industry growth are no longer just the broad idea of rising enterprise IT spend, but three more specific forces: cloud-native environments have lifted the volume of logs, metrics, and traces; security operations centers increasingly rely on real-time analytics and long-term retention; and GenAI/RAG needs a retrieval layer to feed large models real-time, trusted, permission-controlled context. Elastic itself has rewritten its product narrative as a "search, analytics, and AI platform" and puts search, vector database, analytics engine, search engine, and geospatial engine under the same engine.
In cyclical terms, Elastic is not a macro cyclical stock in the traditional sense, but it is certainly not cycle-free. It is closer to a compound of a technology iteration cycle, an enterprise software spending cycle, and an interest-rate-sensitive valuation cycle. Historically, Elastic has felt pressure when enterprises cut cloud spending or extended procurement cycles. During rate-hiking periods, valuations compressed even when fundamentals were stable. When AI, cloud-native, and security budgets accelerated, contract growth improved visibly. A typical FY2026 Q4 phenomenon was that cRPO and RPO grew faster than revenue, meaning customer signing willingness improved first and revenue recognition followed with a lag. For this kind of company, the market usually trades backlog and guidance first, not GAAP profit.
Regulation and geopolitics affect Elastic mainly through data processing, AI compliance, and cross-border deployment, rather than tariffs or supply chains. The 10-K lists AI risk, data security, third-party vendor security, and global data regulations as key risk items, and it specifically adds a risk that AI tools may change how buyers discover products and affect organic website traffic. This is interesting: management already recognizes that AI is not only a sales story, but may also change product distribution and customer acquisition. By comparison, Elastic does not have meaningful hardware supply-chain risk and is not directly constrained by export controls in the way semiconductor companies are. Security and data-compliance requirements, however, will continue to increase product delivery and sales complexity.
Horizontal Competitor Analysis
Elastic's horizontal competition cannot be assessed only through a parameter table because it is not a pure player in a single vertical. A more accurate view is that Elastic stands at the intersection of three battlefields. In observability, it faces Datadog and Dynatrace. In security analytics and SOC platforms, it faces CrowdStrike, Microsoft Sentinel, and Cisco's Splunk. In search, vectors, and AI retrieval, it will meet general data platforms such as MongoDB, while also being diverted by more specialized or cheaper solutions such as AWS OpenSearch, Pinecone, and Algolia.
What has Datadog become? It is a company that has pushed an out-of-the-box cloud-native observability and security console to the extreme. Q1 2026 revenue was USD 1.006 billion, up 32% year over year, non-GAAP operating margin was 22%, cash and marketable securities were USD 4.8 billion, and it had about 4,550 large customers with ARR above USD 100,000. It has also embedded AI features such as MCP Server, Bits AI Security Analyst, and GPU Monitoring directly into observability/security workflows. Datadog's commercial focus is smoother product experience, a more complete front-end visualization layer, and higher cross-sell density, so the market is willing to give it a very high multiple. When Elastic competes head-on with Datadog, Elastic's advantages are a more unified underlying data layer, stronger retrieval and historical data analysis capabilities, self-managed/hybrid deployment, and potentially lower total cost. Its weakness is that, as a pure observability tool, it lacks Datadog's "buy it and roll it out broadly" product perception and capital-market label.
Dynatrace is a different kind of competitor. It is less oriented around developer mindshare and cloud-native visualization than Datadog, and positions itself as an AI-driven end-to-end platform and enterprise automation control plane. FY2026 revenue was USD 2.018 billion, up 19%; ARR was USD 2.054 billion, up 18%; and free cash flow was USD 529 million. The company continues to emphasize deterministic AI, contextual analytics, and control plane this year, while guiding FY2027 revenue growth of about 15% to 16% and non-GAAP operating margin of about 29.5%. Compared with Elastic, Dynatrace looks more like a pure observability asset, with clearer margin and ARR disclosure, so its valuation is also higher. Elastic's relative advantage is that search and security share the same data layer. Its weakness is that the observability story is less pure, making it harder for investors to value it on a single metric as they do with Dynatrace.
CrowdStrike's threat comes from the security budget pool. In Q1 FY2027, CrowdStrike revenue was USD 1.39 billion, up 26%; ARR reached USD 5.51 billion, up 24%; quarterly net new ARR was USD 255.8 million; operating cash flow was USD 590.9 million; free cash flow was USD 468.5 million; and multi-module adoption continued to rise. In security, CrowdStrike sells a motion of first controlling endpoint and threat detection, then expanding into SIEM, identity, cloud security, and automation. It is one of the few security software companies that has already created real platform effects. Elastic's security approach is different: Elastic emphasizes logs, SIEM, data retention, search investigation, and a unified data layer. CrowdStrike emphasizes native endpoint capability, detection efficacy, and module expansion. Which is stronger depends on where the customer budget originates. If the budget comes from SOC modernization and security analytics platforms, Elastic has a chance. If the budget starts from endpoint protection and XDR, CrowdStrike is more likely to control the account.
MongoDB is another type of rival for Elastic in the AI data layer. MongoDB's website already describes Atlas as integrating an operational database and vector database in one platform. Its Q1 FY2027 revenue was USD 687.6 million, up 25%; it held about USD 2.4 billion of cash and short-term investments; and RPO and cRPO grew 88% and 69% year over year, respectively. MongoDB is attractive because many development teams already use Atlas as the primary database. Adding vector search and agent memory can reduce incremental procurement. Elastic is attractive because it is naturally better suited to retrieval, log analytics, full-text search, hybrid search, and a large-scale real-time context layer. Simply put, MongoDB is more like "first a database, then AI retrieval capability grows out of it." Elastic is more like "first a retrieval engine, then AI data-layer capability grows out of it." The two will meet in more and more RAG projects.
OpenSearch is the most troublesome and easily underestimated competitor because it wins customers by being compatible enough, cheap enough, and convenient enough, rather than by being better. In 2021, AWS explicitly defined OpenSearch as a fork of Elasticsearch 7.10.2. The official FAQ states that it pursues backward REST API compatibility. AWS and OpenSearch official documents have also made vector search, serverless vector database, and hybrid retrieval standard capabilities. This means that in sufficiently commoditized scenarios such as search, log analytics, and basic vector retrieval, Elastic will always face a price anchor provided by the world's largest cloud provider. Elastic has only two ways to respond. Either it widens the functional gap enough, through more mature hybrid retrieval, permissions, multimodality, compression, and cross-product collaboration; or it makes the total cost of a unified platform clear enough that customers compare more than single-point unit price.
From an ecosystem-position perspective, Elastic is a platform challenger, not a single-point champion. The gap it fills is not "no one does a certain subfunction." It is: when enterprises already have search, logs, and security data and want to turn those assets directly into an AI context layer with minimal migration cost, who can receive that workload? The profit pools it most directly competes for are log analytics, SIEM storage/retrieval, security investigation platforms, and the AI retrieval layer. The profit pools most likely to be taken from it are low-cost substitutes such as AWS OpenSearch and strong players with established category mindshare in their own core arenas, such as Datadog, CrowdStrike, and MongoDB. If the industry enters technological substitution or price war, Elastic's position will polarize. If enterprise budgets tighten and customers prioritize platform consolidation rather than adding isolated tools, Elastic becomes stronger. If customers prefer to buy best-of-breed products separately for observability, security, and vector retrieval, it becomes weaker.
Current Fundamentals and Valuation Analysis
Recent Four Quarters and Current Trading Narrative
Over the past year, Elastic has delivered financial results that show growth restabilizing, contracts starting to lift, and margins continuing to expand, rather than explosive growth. In Q1 FY2026, revenue was USD 415 million, up 20% year over year, including Elastic Cloud revenue of USD 196 million, up 24%, and cRPO of USD 956 million, up 18%. By FY2026 Q4, full-year revenue was USD 1.739 billion, up 17%; Q4 revenue was USD 451 million, up 16%; sales-led subscription grew 19%; cRPO growth accelerated to 20%; and RPO growth reached 28%. From this cadence, the key change is that contractual commitments and large-customer tiers are moving up, rather than that single-quarter revenue slowed from 20% to 16%. This suggests FY2027 growth is not coming from thin air.
Management's FY2027 guidance also clearly leans toward slightly accelerating revenue and another step up in margin. The company guided FY2027 revenue to USD 1.985 billion to USD 2.000 billion, implying midpoint growth of 14.6%; sales-led subscription to USD 1.673 billion to USD 1.688 billion, implying midpoint growth of 16.9%; non-GAAP operating margin of about 19.0%; and adjusted free cash flow margin of about 21.5%. On the call, management also raised the FY2029 non-GAAP operating margin target to about 25% and said the company remains on track toward exceeding Rule of 40 by FY2029. For the current share price, the market's core trade is whether this company can stabilize growth in the 15% to 17% range while expanding margins faster than expected, rather than whether Elastic will suddenly grow 30%.
The capital market reaction to the Q4 result was positive, but not a euphoric rerating. Investing's earnings summary showed that quarterly revenue and EPS both slightly beat expectations, and the stock rose about 6.7% after hours following the release. This captures Elastic's current position well: as long as it keeps proving that the AI narrative is not empty and that margin expansion is real, the stock has elasticity. But the market is not yet willing to pay the kind of very high long-term AI software premium it gives Datadog or CrowdStrike.
The market currently trades Elastic on four overlapping themes. The first is AI retrieval and RAG. The second is platform integration, especially binding search, observability, and security to the same data layer. The third is margin repair and the path toward Rule of 40. The fourth is improved capital discipline from buybacks. The company launched a USD 500 million buyback plan in 2025 and executed about USD 340 million in FY2026. Management also said the current capital allocation strategy is to return 50% of free cash flow unless attractive M&A opportunities arise. Compared with many software companies that talk about AI without cash discipline, Elastic has at least entered a stage where narrative and capital allocation validate each other.
Bull-Bear Debate
The first core bull argument is that cRPO and large-customer tiers are accelerating ahead of revenue. FY2026 Q4 cRPO growth of 20% and RPO growth of 28% both exceeded quarterly revenue growth of 16%. At the same time, customers with ACV above USD 1 million exceeded 240, and the number of customers with annual consumption above USD 5 million grew 30%. This shows that high-value customers are signing larger and longer contracts. For a software company, this usually implies higher certainty for recognized revenue over the next 2 to 4 quarters.
The second bull argument is that Elastic's AI retrieval is more than adding a vector field. ESRE has been positioned from the start as a toolset for building RAG applications. It includes vector storage, lexical and vector hybrid search, reranking, filtering, document-level security, and integration with LLMs. Together with Jina v5 omni multimodal embeddings, Agent Builder GA, third-party real-time connectors, and Elastic Inference Service, Elastic is trying to lift itself from search engine to the context layer for enterprise AI. If that judgment proves correct, the ceiling for Elastic's search business will be redefined.
The third bull argument is that the company no longer depends on financing to stay alive. At the end of FY2026, Elastic held USD 1.370 billion of cash and marketable securities against USD 575 million of long-term notes, implying net cash of roughly USD 795 million. FY2026 operating cash flow was USD 327 million, and adjusted free cash flow margin was about 20%. For a stock still classified by many investors as a growth company that has not fully delivered, this financial buffer is important. It means that even if the AI opportunity materializes more slowly than expected, Elastic is not dependent on the financing window for survival.
The first bear argument is that Elastic has still not proved itself to be category number one in any single battlefield. In observability, Datadog has stronger brand momentum and growth speed, while Dynatrace has stronger ARR and margin discipline. In security, CrowdStrike is stronger. In underlying retrieval and vector capabilities, Elastic faces pressure from OpenSearch, MongoDB, and specialist vector databases. Elastic's integrated platform narrative is appealing, but the common problem with integrated platforms is that customers may not want to allocate every budget line to the same vendor.
The second bear argument is that AI customer adoption and AI monetization are not the same thing. Management mentioned more than 600 customers with ACV above USD 100,000 using AI capabilities. That is clearly positive, but the company did not directly disclose how much incremental ARR these AI features contributed, nor did it break out the separate pull from GenAI retrieval workloads on Elastic Cloud consumption. A more realistic possibility is that many enterprises view vector retrieval and RAG as incremental capabilities for existing data platforms, rather than a new budget large enough to expand independently. As long as this point is not quantified in the financials, the market will continue to discount Elastic.
The third bear argument is that stock-based compensation and licensing history will continue to limit valuation. FY2026 stock-based compensation was still close to USD 300 million. The post-2021 license changes protected commercial interests, but they also cost Elastic part of the valuation halo of a pure open-source company and allowed OpenSearch to exert long-term pricing pressure in commoditized use cases. In other words, Elastic's current discount is not entirely a mispricing. Part of it is the necessary cost of its own business-model evolution.
Valuation Analysis
Historical Valuation
On a SaaS basis, Elastic is clearly not expensive today. Based on a market cap of USD 6.409 billion on 2026-06-12 and FY2026 year-end net cash of roughly USD 795 million, enterprise value is about USD 5.61 billion. That equals about 3.2x FY2026 revenue of USD 1.739 billion and about 2.8x the FY2027 revenue guidance midpoint of USD 1.993 billion. If Q4 FY2026 subscription revenue of USD 422 million is annualized as a rough proxy for implied ARR, implied ARR is about USD 1.688 billion, implying EV/implied ARR of about 3.3x. Management itself uses adjusted free cash flow margin to measure Rule of 40. FY2026 was 17% revenue growth plus 20% adjusted FCF margin, or 37%; FY2027 guidance is 14.6% plus 21.5%, or 36.1%. This is a software company close to Rule of 40, but valued far below high-premium SaaS peers.
Historically, Elastic's valuation center has clearly fallen from the software mania of 2021. Macrotrends shows its 2021 all-time closing high at USD 186.78. The current share price is only about one-third of that peak. The reason the valuation center has not returned with AI is that the market has become much more selective about who the true AI software winners are, not that Elastic's revenue collapsed. Elastic does not have Datadog's high-growth single-line observability narrative, nor CrowdStrike's security-platform premium. Its rerating must be triggered by more specific financial delivery.
Peer Valuation
The horizontal comparison is the clearest illustration. Datadog's current market cap is about USD 83.85 billion, Q1 2026 annualized revenue already roughly exceeds USD 4 billion, and full-year guidance is USD 4.30 billion to USD 4.34 billion, implying EV/Sales well above 18x. Dynatrace's market cap is about USD 12.36 billion, FY2026 revenue was USD 2.018 billion, FY2027 guidance midpoint is about USD 2.326 billion, and based on its roughly USD 1.097 billion of cash, forward EV/Sales is about 4.8x. MongoDB's market cap is about USD 27.97 billion, it has about USD 2.4 billion of cash and short-term investments, Q1 FY2027 annualized revenue is close to USD 2.75 billion, and forward EV/Sales is around 9x. CrowdStrike's revenue and valuation are much higher. Elastic's current forward EV/Sales of about 2.8x sits at the cheapest end of this comparable group. The discount has rational causes, including slower growth, more complex commercial positioning, and weaker category leadership, but the absolute discount is already large enough that if Elastic can prove more clearly that AI retrieval is incremental, there is room for valuation repair.
Cash-Flow Look-Through and Absolute Valuation
Start with cash-flow look-through. FY2026 operating cash flow was USD 326.9 million, and capital expenditure was about USD 5.1 million. Based on the software-company characteristic that capex is mainly maintenance and expansion capex is light, owner earnings are roughly USD 322 million. That implies an equity FCF yield of about 5.0% and an EV basis yield of about 5.7%. Looking only at the FY2026 OCF/GAAP net income ratio of 0.89 does not look attractive, but this is entirely due to the one-time tax distortion. Excluding the roughly USD 435 million valuation allowance reversal, GAAP profit itself is not a sustainable profitability indicator. For Elastic, cash flow is closer to reality than net income.
Based on this, the more suitable approach is to use forward SaaS EV/Sales and cash-flow discipline for a three-scenario valuation, rather than net-income discounting. This is a valuation scenario analysis under the research framework, not investment advice.
| Dimension | Bear | Base | Bull |
|---|---|---|---|
| Revenue/margin assumptions | FY2027 revenue of USD 1.95 billion to USD 1.98 billion; non-GAAP operating margin of 17% to 18%; AI use-case expansion falls short of expectations | FY2027 revenue near guidance midpoint of USD 1.99 billion to USD 2.00 billion; non-GAAP operating margin around 19%; normal conversion of Cloud and large deals | FY2027 revenue of USD 2.03 billion to USD 2.08 billion; non-GAAP operating margin of 20% to 21%; stronger AI retrieval pull |
| Cash-flow assumptions | Adjusted FCF margin of 19% to 20% | Adjusted FCF margin of 21% to 22% | Adjusted FCF margin of 22.5% to 23.5% |
| Valuation multiple assumptions | EV/Sales 2.1x to 2.4x | EV/Sales 2.7x to 3.3x | EV/Sales 3.8x to 4.5x |
| Key catalysts | Stable renewal from existing customers, with no obvious price war | cRPO converts into revenue, and million-dollar customers continue to increase | Search AI becomes a clearer budget item, and valuation moves closer to platform AI software |
| Key risks | Low-cost OpenSearch substitution, AI monetization fails to form | Growth stabilizes without reacceleration, and valuation stays in place | High-valuation recovery happens too quickly, AI budget momentum cools |
| Implied return space | -25% to -14% | -4% to +14% | +31% to +57% |
| Permanent loss risk | Trigger: revenue falls to low double digits, cRPO slows for consecutive periods, and the multiple falls below 2x | Trigger: AI revenue contribution is hard to quantify, and platform integration does not generate cross-sell | Trigger: the market discounts AI too early, then the multiple gives back gains after delivery falls short |
Under the assumptions above, and using FY2026 year-end net cash of roughly USD 795 million and FY2027 diluted shares of roughly 107 million as approximations, the bear case implies about USD 46 to USD 52 per share, the base case about USD 58 to USD 69, and the bull case about USD 79 to USD 95. The meaning of this range is "where the current price sits under different growth and multiple combinations," not "what Elastic is worth."
Expectation Gap and Margin of Safety Review
The market's current implied expectations are not aggressive. At roughly 2.8x FY2027 EV/Sales, the market is not pricing Elastic as a core AI platform. It is closer to saying: you are an enterprise software company with mid-teens growth, decent cash flow, and a second curve still to prove. The variables that could create the real expectation gap are three leading operating indicators, rather than 50 basis points more single-quarter margin: whether cRPO growth can remain above revenue growth, whether customers with ACV above USD 1 million can continue to increase net, and whether AI use-case penetration can move up from one-third.
On margin of safety, my judgment is not optimistic. The current price of USD 60.35 is still about 16% above the bear-case upper bound of USD 52, which means margin of safety is zero relative to conservative value. The most fragile assumption across the three scenarios is that AI retrieval and platform integration will bring a higher multiple rather than merely preserve the current one. If the base-case multiple assumption is cut by 30%, valuation quickly compresses into the low USD 50s. If earnings and cash flow are close to zero growth over the next three years while valuation does not expand, investors are likely to earn only low-single-digit annualized returns. For a software stock with no dividend and still-high SBC, that is not a sufficient margin of safety. My conclusion among four choices is: margin-of-safety sufficiency is not obvious.
Key Data Table
| Metric | Elastic | Datadog | Dynatrace | CrowdStrike | MongoDB |
|---|---|---|---|---|---|
| Latest share price | 60.35 | 229.90 | 40.75 | 682.80 | 342.80 |
| Current market cap | USD 6.409 billion | USD 83.852 billion | USD 12.357 billion | USD 176.081 billion | USD 27.966 billion |
| Latest disclosed revenue | FY2026 USD 1.739 billion | Q1 2026 USD 1.006 billion | FY2026 USD 2.018 billion | Q1 FY2027 USD 1.390 billion | Q1 FY2027 USD 688 million |
| YoY growth | 17% | 32% | 19% | 26% | 25% |
| Cash measure | USD 1.370 billion cash and marketable securities | USD 4.8 billion cash and marketable securities | USD 1.097 billion cash | USD 4.55 billion cash | USD 2.4 billion cash and short-term investments |
| Operating/free cash flow profile | FY2026 OCF USD 327 million | Q1 OCF USD 335 million, FCF USD 289 million | FY2026 FCF USD 529 million | Q1 OCF USD 591 million, FCF USD 469 million | Q1 OCF USD 202 million, FCF USD 198 million |
The business meaning behind this table is direct. Datadog's and CrowdStrike's high valuations come from purer category leadership and higher growth certainty. Dynatrace's premium comes from more stable ARR and high margins. MongoDB's premium comes from database platform repricing in the AI era. Elastic is cheap because it carries three discount factors in the market's eyes, rather than because the company is poor: an impure category, too broad a competitive surface, and AI monetization still under validation. Conversely, once validation succeeds, it also has more rerating elasticity than many peers that are already expensive.
Risks, Catalysts, and Tracking Metrics
Risk Analysis
The first risk that could truly cause permanent capital loss is the commoditization shock to Elastic's base business from OpenSearch and cloud-native substitutes. I rate its probability as medium and its impact as high. Observable indicators include cRPO growth continuously falling below revenue growth, sales-led subscription growth stepping down, and customer contracts shrinking toward shorter periods and lower commitments. If this happens, the transmission path usually hits pricing and cloud consumption first, then revenue, then valuation multiples, rather than profit first. AWS is dangerous because it is compatible enough and cheap enough, not because it is more advanced than Elastic.
The second risk is that GenAI/RAG adoption runs ahead of budget formation, leading to more feature use without meaningful paid expansion. I rate its probability as medium-high and its impact as high. Observable indicators include continued growth in the number of customers using AI capabilities, but slower growth in million-dollar ACV customers; continued AI use-case penetration without a visible lift in Elastic Cloud revenue or sales-led subscription growth; and management continuing to emphasize customer interest on calls without giving clearer AI monetization metrics. If this risk materializes, Elastic ultimately becomes a company whose technology everyone recognizes as important, but without forming an independent profit pool. The share price would then remain in a low-multiple range for a long time.
The third risk is the multi-front problem: every product is decent, but none is strong enough to control the budget. The probability is medium and the impact is medium-high. Observable indicators include management continuing to package observability and security solution growth in broad terms, rather than showing a clearer share breakthrough in a particular vertical; and more large security or observability replacement cases without forming a continuous industry breakthrough. The transmission path for this risk is that revenue growth may not suddenly fall, but valuation never lifts because investors find it hard to classify Elastic into any subcategory that deserves a high multiple.
The fourth risk is the tug-of-war between stock-based compensation and buybacks. I rate its probability as high and its impact as medium. FY2026 stock-based compensation was close to USD 300 million, while buybacks were USD 340 million. On the surface, this looks like returning cash to shareholders, but in substance a large part of the cash is used to offset dilution from equity incentives. Observable indicators include whether SBC as a percentage of revenue declines meaningfully, whether share count truly falls after buybacks, and whether free cash flow per share grows faster than total free cash flow. If buybacks can only offset dilution in place over the long term, per-share value creation will be weaker than headline cash-flow figures suggest.
The fifth risk is compliance and reputational risk from AI, data security, and third-party dependencies. The probability is medium and the impact is medium. Elastic lists AI regulation, AI tool use, third-party vendor security, cybersecurity, and data protection as key risks in the 10-K. These risks usually show up first in sales cycles, public-sector project progress, and compliance costs in certain geographies, rather than appearing immediately in quarterly revenue. For a software company that sells security, AI, and cross-border cloud services at the same time, such risks are not fatal, but they continuously raise operating complexity.
Catalysts and Tracking Dashboard
Among positive catalysts, the most important is that revenue in the first half of FY2027 truly starts to convert the cRPO and RPO accumulated at the end of FY2026, rather than another AI feature launch. Management has explicitly tied strong FY2026 sales execution, contract acceleration, and FY2027 revenue acceleration together. If the next two quarters show revenue, sales-led subscription, and cRPO all remaining strong, the market will be more willing to believe that contracts represent real demand, not pull-forward signing.
The second positive catalyst is continued expansion of large AI deals, especially in the customer cohorts above USD 1 million and USD 5 million ACV. Elastic has already given a fairly specific direction: FY2026 added more than 30 customers with ACV above USD 1 million, bringing the total to more than 240, while the number of customers above USD 5 million grew 30%. If this trend continues in FY2027, it would show that the Search AI narrative has moved beyond proof of concept.
Negative catalysts mainly fall into three categories. The first is cRPO growth falling back below revenue growth, suggesting that the FY2026 Q4 commitment acceleration may have been seasonal. The second is a widening mismatch between Elastic Cloud commitments and consumption, where backlog exists but revenue cannot convert. The third is peers commoditizing AI features too quickly, such as OpenSearch, MongoDB, or Datadog turning vector retrieval, context enhancement, and AI agent debugging into lower-friction standard features, compressing Elastic's differentiation.
| Tracking metric | Current reading | Normal range | Warning threshold |
|---|---|---|---|
| Total revenue YoY growth | FY2026 was 17%, FY2027 guidance 14.6% | 15% to 18% | Below 12% for two consecutive quarters |
| Sales-led subscription YoY growth | Q4 was 19%, FY2027 guidance 16.9% | 16% to 20% | Below 14% |
| cRPO YoY growth | Q4 was 20% | Above revenue growth | Below revenue growth for two quarters |
| RPO YoY growth | Q4 was 28% | High double digits | Falls below 15% |
| $100k+ ACV customers | 1,720+ | Continued net additions | Net additions slow materially or stall |
| AI capability penetration | Already more than one-third of the $100k ACV customer cohort | Continued improvement | Stays around one-third for a long time |
| Adjusted FCF margin | FY2026 about 20%, FY2027 guidance 21.5% | 20% to 22% | Below 17% |
| Non-GAAP operating margin | FY2026 was 16.4%, FY2027 guidance about 19% | 17% to 19% | Below 15% |
| SBC as % of revenue | FY2026 about 17% to 18% | Gradual decline | Returns above 19% |
Among these indicators, the three most important to watch are sales-led subscription growth, the lead of cRPO growth over revenue growth, and AI capability penetration in the large-customer cohort. The first two determine short- to medium-term performance, and the third determines long-term valuation. Looking only at revenue is too late, and looking only at AI launches is too vague. Watching these three tells us whether Elastic's second curve is real.
Research Uncertainties
This research has four blind spots that need to be stated clearly. First, the company did not separately disclose full-year Elastic Cloud revenue in the FY2026 full-year release, so the precise value of "full-year cloud share" cannot be directly verified from primary disclosures. Second, the company emphasizes AI customer adoption, but it does not separately disclose AI-related ARR or revenue contribution, so the degree of AI monetization can only be inferred indirectly through large customers, penetration, and contract trends. Third, Elastic does not publicly disclose ARR in the way Dynatrace or CrowdStrike does, so EV/ARR can only use annualized Q4 subscription revenue as an approximation of "implied ARR." Fourth, among the latest four quarters, this report's quantitative breakdown of Q2 FY2026 is less complete than for the other quarters. This should be treated as a local limitation in data completeness, not a conclusive gap.
Reference Sources
This report is mainly based on the following public materials: Elastic's FY2026 Q4 earnings release on its investor relations website, SEC Form 10-K and Form 8-K, and FY2026 Q4 earnings call transcript; Elastic product and blog documents on ESRE, Elasticsearch, Jina v5 omni, Agent Builder, and licensing evolution; the latest official earnings disclosures from Datadog, Dynatrace, CrowdStrike, and MongoDB; AWS and OpenSearch official documents on fork history, compatibility, and vector retrieval capabilities; and public market databases used to review historical share-price highs. The corresponding key sources have been marked paragraph by paragraph in the body text.
Cross-Sectional and Longitudinal Synthesis
What Elastic has truly proved on its path to today is its ability to repeatedly rewrite an underlying technology into effective products for different budget pools, rather than merely having a popular open-source project. It was first rewritten into enterprise search and log analytics, then into observability and security, and now it is trying to be rewritten into the AI context layer. Many software companies face a problem where, after the first-generation product succeeds, all subsequent growth comes from expanding the sales force. Elastic is different. In its growth path, every important leap has involved a redefinition of the technology route: from Elasticsearch to the Elastic Stack, from logs and search to an underlying platform, from the Endgame acquisition to security products, from license changes to commercial protection, and then to Jina, ESRE, and multimodal retrieval. The company's strongest point is that it truly has the ability to reuse the underlying engine across scenarios. The question is not whether it can tell a story.
Past success, however, clearly benefited from the era. From 2018 to 2021, capital markets were willing to pay high multiples for almost all cloud software, developer tools, and open-source commercialization stories, and Elastic naturally benefited. After 2022, that tailwind receded and the real question remained: are you a search company, a log company, a security company, or an AI company? So far, Elastic has not had any product line strong enough for investors to define it with one word without hesitation. This weakness matters because capital markets most like software companies with a single strong label. Elastic can be understood as a platform company, or as a company that is hard to classify. Platform has synergy; classification difficulty has a discount.
Do those success factors still exist today? Some do, and some have changed shape. Developer penetration, the search foundation, and data gravity remain. The natural halo of the open-source brand has weakened. Platform integration capability remains, but each individual battlefield is harder to fight. The AI wave has given Elastic a rare new opportunity by putting search back at center stage. The real change is that Elastic has finally met a market environment where people are again willing to recognize retrieval as the key layer that determines the usability of large models, rather than a side function in a database corner. For Elastic, this matters far more than saying "we also added an AI button," because retrieval is what it has always been best at.
Horizontally, Elastic's truest advantage versus competitors is unity, not single-function strength. Elastic's search, logs, analytics, security investigation, and access control can indeed sit on a shared data layer, giving it a natural position in platform integration, long-term retention, and the AI context layer. Its weaknesses are equally real. Datadog looks more like an out-of-the-box observability cash register, CrowdStrike more like a controller of the security budget, MongoDB more like the natural extension of a database developers already use, and OpenSearch is the ever-present low-cost alternative. Elastic's problem has always been that delivery lags narrative by half a beat, not that the story is too small.
Is the current valuation rewarding the past or discounting the future too aggressively? I think it is neither. More precisely, the current valuation gives Elastic a ticket to keep proving itself, not a graduation certificate that says it has already been accepted. Forward EV/Sales of around 2.8x and pricing close to Rule of 40 without an obvious premium show that the market recognizes the company is no longer a fragile loss-making SaaS business, but also clearly does not believe it will easily become a core AI platform winner. In other words, today's price is not rewarding the past peak and is not fully pre-discounting future GenAI success. It sits between "cheap" and "needs stronger evidence."
The market's most likely misjudgment is one critical point: many people view Elastic as "a mature search business plus a new AI concept," but the more likely reality is that AI will first rewrite the budget importance of search, then turn Elastic's mature business back into a growth asset. RAG, agentic workflows, real-time permission context, and multimodal retrieval need a system that can connect semantic retrieval, keyword search, log analytics, filtering, permissions, connectors, and real-time data in complex enterprise environments, rather than a pure vector database. Elastic happens to have stood at this intersection for many years. If the market ultimately confirms that enterprise AI truly lacks a retrieval layer rather than more models, Elastic's discount will look too deep. Conversely, if RAG is quickly commoditized into a standard cloud-provider feature, Elastic may continue to be held at low multiples.
The most important variables for the next 1 year, 3 years, and 5 years are not the same. Over the next 1 year, the question is whether backlog can convert into revenue, meaning whether the strong cRPO/RPO at the end of FY2026 turns into FY2027 subscription and cloud consumption. Over the next 3 years, the question is whether ESRE, Jina, Agent Builder, and platform integration can rebuild search as a higher-growth business. Over the next 5 years, the question is harsher: can Elastic harden itself into the context infrastructure for enterprise AI, rather than remaining a diversified software company that constantly switches narratives among search, observability, and security? The first two variables determine share-price elasticity. The third determines the valuation center.
Bull and Bear Reasons
Bull Reasons
cRPO accelerated to 20% in FY2026 Q4 and RPO accelerated to 28%, showing contractual commitments strengthening ahead of revenue.
AI use cases have penetrated more than one-third of the USD 100,000 ACV customer cohort, and more than 600 USD 100,000 ACV customers use AI capabilities. Search AI is not castles in the air.
FY2026 year-end net cash was about USD 795 million, operating cash flow was USD 327 million, and buybacks were USD 340 million. The company has entered a self-funding stage.
Current forward EV/Sales is about 2.8x, materially below Datadog, Dynatrace, MongoDB, and CrowdStrike, so the valuation already reflects a fair amount of skepticism.
Elastic's full-text retrieval, vector, hybrid search, access control, and multimodal capabilities are already built on the same foundation, making it naturally suited to enterprise RAG.
Bear Reasons
Elastic is not the strongest brand in any of the three battlefields of observability, security, and AI retrieval. The platform narrative may not automatically become budget control.
OpenSearch, as an AWS fork compatible with Elasticsearch 7.10, will remain in the market for a long time and continue to pressure commoditized pricing for basic search and log analytics.
Management has disclosed AI adoption, but not ARR or revenue directly contributed by AI, so the market still cannot see the independent monetization strength of Search AI.
FY2026 stock-based compensation was still close to USD 300 million, and buybacks largely offset dilution. Real per-share return improvement is slower than headline cash flow.
FY2026 GAAP profit was distorted by the roughly USD 435 million deferred tax reversal. If investors mistake this for an operating inflection, they may overestimate profit quality.
Pre-mortem
Scenario one: by the end of 2027, enterprise GenAI projects enter production at scale, but the retrieval-layer budget does not expand independently. Customers more often choose to make vector retrieval an add-on inside AWS OpenSearch, MongoDB Atlas, or existing cloud stacks. Elastic's AI customer count continues to rise, but sales-led subscription growth slips from 16% to 19% down to 12% to 13%, and cRPO growth falls back near revenue growth. The market realizes that Search AI is only enhancing retention, not creating a new profit pool. The valuation multiple falls from about 2.8x forward EV/Sales to around 2.1x, and the stock returns to roughly USD 45, down about one-quarter from the current level. The risk clue supporting this scenario is already visible today: the company emphasizes AI adoption, but has not separately disclosed AI revenue.
Scenario two: by 2028, Datadog continues to strengthen platform mindshare in observability and AI operations, while CrowdStrike strengthens platform mindshare in security analytics and automation. Elastic keeps winning some replacement projects, but cannot form "must-buy" control in any single budget pool. At the same time, SBC as a percentage of revenue declines slowly, and buybacks are used mainly to offset dilution. Operating margin rises to the high teens, but revenue growth stays in the low teens. The capital market prices it entirely as mid-growth infrastructure software, and the valuation hovers around 2x to 2.5x sales for years, with the share price moving sideways or even down. This scenario is closer to "a good company, neither bad enough to be very cheap nor good enough to stand out."
Final Research Conclusion
Elastic's investment thesis today is to judge who has the best chance to turn retrieval into a new infrastructure layer after AI pushes enterprise data back to the center, not to judge whether AI will change the world. On this question, Elastic is at least standing in the right place: it has an existing search foundation, integrated vector and hybrid search, a data layer across search, observability, and security, gradually forming large-customer contracts, and net cash plus free cash flow to survive the validation period. The problem is that it has not yet turned these advantages neatly into a growth curve that the market will buy without hesitation. Today's Elastic is neither obviously undervalued nor bubble-like AI software. It is more like a stock that has not completed rerating, but already has the prerequisites for one.
At the current price, my biggest concern is whether Search AI's incremental contribution can be fast enough to change the valuation center, rather than the balance sheet or single-quarter margin. As long as this question lacks a clearer financial answer, Elastic will struggle to move from "potential platform challenger" to "high-quality compounder." Conversely, because the market remains skeptical, the stock has not pre-discounted success to an absurd degree. My stance is therefore restrained: this is not a name to avoid completely, but it is not yet one with an obvious margin of safety that deserves a large position chased at current prices. The better strategy is to maintain price discipline while fundamentals continue to validate.
【Company Profile Score】
Fundamental quality: Medium
Growth: Medium
Moat: Medium
Financial resilience: Strong
Management credibility: Medium
Valuation attractiveness: Medium
Risk level: Medium
Suitable investor type: Long-term growth
【Investment Rating】
Rating: Hold
One-sentence investment thesis: Contract and cash-flow improvement has been proven, but independent monetization of Search AI still needs several more quarters of validation.
Acceptable holding price: 58–69 USD
Clearly overvalued price: Above 79 USD
Current price classification: Acceptable to hold
Worth waiting for a better price: Yes. A more attractive entry point is below USD 52, or the buy point can be raised after FY2027 first-half validation continues through cRPO-to-revenue conversion and sustained expansion of large AI deals. The opportunity cost of waiting is that if Search AI delivers materially faster than expected, valuation may repair first and pull back later.
Target holding period: 1–3 years
Expected annualized return: Bear -12% to -7%; base 0% to 7%; bull 10% to 16%
Maximum loss risk: About 25%, triggered by AI adoption failing to turn into budget expansion, cRPO slowing, and multiple compression toward roughly 2.1x EV/Sales
Signals triggering reassessment: If cRPO growth is below revenue growth for two consecutive quarters
If sales-led subscription growth falls below 14%
If AI use-case penetration remains around one-third and expansion in million-dollar ACV customers slows
If SBC as a percentage of revenue rises back above 19% and buybacks cannot reduce share count
If OpenSearch, MongoDB, or major observability/security competitors clearly take AI retrieval orders that originally belonged to Elastic
【Ideal/Fair Buy Price】46–52 USD
Basis: This corresponds to the valuation range under the bear case of 2.1x to 2.4x FY2027 EV/Sales and requires at least some cushion against conservative value. In this range, investors are paying more for the existing subscription and cash-flow business than for the still-unproven Search AI option.
【Valuation Range】
current: 60.35 (based on the 2026-06-12 closing price)
bear (conservative, ideal buy zone): [46, 52]
base (reasonable, acceptable holding zone): [58, 69]
bull (optimistic, above the clearly overvalued line): [79, 95]
Other Securities Mentioned in This Report
DDOG.US — A pure observability leader, used to compare Elastic's product purity, growth, and valuation premium in observability.
DT.US — An enterprise observability platform, used to compare Elastic's differences in ARR, margin, and platform automation narrative.
CRWD.US — A security platform leader, used to compare Elastic's relative position in SIEM/XDR and the security budget pool.
MDB.US — A database platform and vector retrieval competitor, used to compare Elastic's competitive relationship in the AI data layer and RAG scenarios.
CSCO.US — The parent company of Splunk, representing traditional SIEM/log analytics incumbents.
MSFT.US — The company behind Microsoft Sentinel, representing the threat from cloud-platform-native security analytics and operations stacks.
AMZN.US — The parent company of AWS OpenSearch, Elastic's long-term competitor in commoditized search and cloud-managed retrieval.
This report is based on public information and does not constitute investment advice. Markets carry risk; invest with caution.
Full report
Sign in to read the full report
Sign up free to unlock the full text, the Baillie growth scorecard, and full-text search.
Log in / Sign up free