Elastic NV Stock price
Compare with Peer Group
📊 Peer Group
📈 What is it?
The peer group consists of the companies with the most similar business model. They serve as a benchmark for putting a stock into context.
🧮 How is it selected?
Based on similarity of business model, meaning companies from the same industry with comparable products and a similar customer base. That's the only way to compare apples to apples.
🏛️ Why does it matter?
Whether a stock is cheap or expensive is best judged by comparison. A P/E of 18 or an EV/FCF of 20 can look cheap or expensive depending on the yardstick. The peer group gives you the most accurate one: companies with a similar business model that operate under the same conditions.
🎯 What does it mean for investors?
When a metric sits below the peer average, the stock is valued more cheaply relative to its competitors, and above the average more expensively. A discount to the peer group can be an opportunity, but it can also have a reason (for example lower growth). The comparison is a starting point, not a verdict.
AI Insights on Elastic NV
Insights
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Is Elastic NV a Top Scorer Stock based on the Dividend, High-Growth-Investing or Leverman Strategy?
As a Free StocksGuide user, you can view scores for all 9,127 stocks worldwide.
StocksGuide Premium
StocksGuide Unlimited
Key metrics
📘 Market Capitalization
📈 What is it?
Market capitalization shows how much a company is currently worth on the stock market.
🧮 How is it calculated?
🏛️ Why is it important?
It helps classify companies by size (Large, Mid, Small Cap) and indicates their market presence and relative stability.
🧮 Calculation
🎯 What does this mean for investors?
- Large-cap companies tend to be more stable, often pay dividends, but may grow more slowly.
- Smaller firms may offer higher growth potential but come with more volatility.
- Market capitalization is a useful indicator of company size — but not a measure of whether a stock is undervalued or overvalued.
📘 Enterprise Value (EV)
📈 What is it?
Enterprise Value represents the total cost to acquire a company — including its debt and excluding its cash reserves.
🧮 How is it calculated?
(= Market Cap + Net Debt)
🏛️ Why is it important?
EV gives a more complete picture of a company's value than market cap alone and is used in key valuation ratios like EV/FCF or EV/Sales.
🧮 Calculation
🎯 What does this mean for investors?
- Enterprise Value shows the true cost of buying a company, including all financial obligations.
- It is more accurate than just looking at market cap, especially when comparing companies with different levels of debt or cash.
- Professional investors prefer EV-based multiples because they better reflect the company’s full financial footprint.
📘 Net Debt
📈 What is it?
Net Debt shows how much debt remains after subtracting a company’s available cash reserves.
🧮 How is it calculated?
🏛️ Why is it important?
It indicates how dependent a company is on borrowed money and how easily it can service its debt in the short term.
🧮 Calculation
🎯 What does this mean for investors?
- Low or negative net debt signals financial strength and flexibility.
- Companies with strong cash positions are better positioned in crises.
- High net debt increases financial risk — especially in environments with rising interest rates or economic downturns.
📘 Cash
📈 What is it?
Cash represents all liquid assets a company can access immediately — including cash, bank deposits, and short-term investments.
🧮 How is it calculated?
🏛️ Why is it important?
It reflects a company’s financial flexibility and resilience — enabling investments, buybacks, or buffer in downturns.
🧮 Calculation
🎯 What does this mean for investors?
- A strong cash position means greater room for maneuver and crisis resistance.
- Cash-rich companies can invest, pay down debt, or repurchase shares.
- But excess idle cash might indicate a lack of growth opportunities.
📘 Shares Outstanding
📈 What is it?
Shares outstanding represent the total number of a company’s shares currently held by investors — excluding treasury stock.
🧮 How is it calculated?
🏛️ Why is it important?
It’s the basis for key metrics like Earnings Per Share (EPS), Market Capitalization, or the Price/Earnings ratio (P/E).
🧮 Calculation
🎯 What does this mean for investors?
- Fewer shares in circulation typically increase earnings per share — making each share more valuable.
- Share buybacks reduce the number of shares and boost per-share metrics.
- Issuing new shares does the opposite — diluting shareholder value and lowering per-share figures.
📘 Price-to-Earnings Ratio (P/E)
📈 What is it?
The P/E ratio shows how many times a company's earnings per share are reflected in its current share price — in other words, how "expensive" the stock appears relative to its profits.
🧮 How is it calculated?
🏛️ Why is it important?
The P/E ratio is one of the most widely used valuation metrics. It helps investors assess whether a stock appears cheap or expensive compared to its earnings power.
🧮 Calculation
📊 P/E (TTM) = Based on earnings from the last 12 months (Trailing Twelve Months):🎯 What does this mean for investors?
- A low P/E may indicate undervaluation — or signal underlying issues.
- A high P/E may reflect strong growth expectations — or an overvalued stock.
📘 Price-to-Sales Ratio (P/S)
📈 What is it?
The P/S ratio shows how much investors are paying for $1 of the company’s revenue – regardless of profitability.
🧮 How is it calculated?
🏛️ Why is it important?
P/S is especially useful for evaluating growth companies or businesses not yet profitable. It reflects how the market values the company’s sales.
🧮 Calculation
Market Cap = $9.58b | Revenue (TTM) = $1.80b
Market Cap = $9.58b | Estimated Revenue = $2.05b
🎯 What does this mean for investors?
- A low P/S may indicate undervaluation — or low profitability.
- A high P/S can reflect strong growth expectations — or excessive optimism.
- Especially helpful when evaluating companies where profits are low, volatile, or negative.
📘 Enterprise Value to Sales (EV/Sales)
📈 What is it?
EV/Sales shows how much investors are paying for $1 of revenue — considering not just equity, but also debt and cash. It’s the capital structure–adjusted version of the P/S ratio.
🧮 How is it calculated?
🏛️ Why is it important?
It’s ideal for comparing companies with different levels of debt. It reflects a company's true cost relative to its revenue.
🧮 Calculation
Enterprise Value = $8.78b | Revenue (TTM) = $1.80b
Enterprise Value = $8.78b | Forward Revenue = $2.05b
🎯 What does this mean for investors?
- EV/Sales allows for capital structure–neutral company comparisons.
- A lower ratio may indicate undervaluation; a higher one may signal strong growth expectations or overvaluation.
- Especially helpful when evaluating high-growth companies with low or negative earnings.
📘 Enterprise Value to Free Cash Flow (EV/FCF)
📈 What is it?
EV/FCF shows how many years it would take for a company to "pay back" its enterprise value using its free cash flow.
🧮 How is it calculated?
🏛️ Why is it important?
It focuses on real cash generation, ignoring accounting noise — ideal for assessing profitability and value based on liquidity, not earnings.
🧮 Calculation
🎯 What does this mean for investors?
- A low EV/FCF may signal undervaluation and strong cash generation.
- A high EV/FCF might reflect weak recent cash flow or aggressive growth expectations.
- Best suited for stable, mature businesses with predictable free cash flows.
📘 Price-to-Book Ratio (P/B)
📈 What is it?
The P/B ratio compares a company’s market value to its book value — showing how much investors are paying for each dollar of net assets.
🧮 How is it calculated?
🏛️ Why is it important?
P/B is commonly used for asset-heavy industries like banks or industrials. It helps assess whether a stock is trading above or below its net asset value.
🧮 Calculation
🎯 What does this mean for investors?
- A P/B below 1 may signal undervaluation — or weak profitability.
- A P/B above 1 implies the market expects future value creation (e.g., brand, IP, growth).
- Best used for companies with tangible assets and strong balance sheets.
📘 Equity Ratio
📈 What is it?
The equity ratio indicates what portion of a company’s total assets is financed by shareholders’ equity – in other words, how much it relies on its own capital.
🧮 How is it calculated?
🏛️ Why is it important?
A high equity ratio reflects financial strength and stability, especially during downturns. It’s a key indicator of a company’s solvency and long-term risk profile.
🎯 What does this mean for investors?
- Companies with high equity ratios are generally more resilient and less dependent on external debt.
- Low equity ratios can signal higher risk or aggressive financial strategies.
- Important: Always assess the equity ratio in combination with the return on equity (ROE). This shows not just how stable the company is – but also how efficiently it uses shareholder capital.
📘 Return on Equity (ROE)
📈 What is it?
Return on equity (ROE) shows how efficiently a company uses its shareholders’ equity to generate profit. In other words: how much net income is earned per dollar of equity.
🧮 How is it calculated?
🏛️ Why is it important?
ROE is a core profitability metric. It helps investors understand whether a company delivers attractive returns on the capital provided by its shareholders.
🎯 What does this mean for investors?
- A high ROE indicates that the company is using its capital efficiently and profitably.
- It’s especially meaningful for capital-intensive businesses or firms with high equity bases.
- Important: A very high ROE can also result from high debt levels – always interpret it alongside the equity ratio to assess financial health.
📘 Return on Capital Employed (ROCE)
📈 What is it?
ROCE measures how efficiently a company generates profits from its total capital – including both equity and interest-bearing debt.
🧮 How is it calculated?
It evaluates the return on all capital employed, regardless of how it’s financed.
🏛️ Why is it important?
ROCE is ideal for comparing companies with different financing structures. It shows how well management uses capital to create value for both shareholders and creditors.
🧮 Calculation
🎯 What does this mean for investors?
- A high ROCE means the company uses its capital efficiently – regardless of whether it's funded by debt or equity.
- The higher the ROCE compared to peers, the more value the company creates with its invested capital.
- Especially relevant for capital-intensive sectors like industrials, energy, or infrastructure.
📘 Return on Invested Capital (ROIC)
📈 What is it?
ROIC measures how efficiently a company generates returns from the capital invested in its core operations – regardless of whether the capital comes from equity or debt.
🧮 How is it calculated?
- NOPAT = Net Operating Profit After Taxes
- Invested Capital = Operating assets minus non-interest-bearing liabilities
🏛️ Why is it important?
ROIC is one of the most accurate indicators of capital efficiency. Unlike return on equity, it is not distorted by leverage and shows how much value is created for all capital providers.
🧮 Calculation
🎯 What does this mean for investors?
- A high ROIC shows how effectively a company uses the capital that is truly invested in its core operations.
- Unlike ROCE, ROIC focuses only on the capital that is actively used to run the business – and that requires a return (i.e. interest-bearing).
- Especially useful when comparing companies with large amounts of excess cash or non-interest-bearing liabilities – giving a more realistic picture of capital efficiency.
📘 Leverage Ratio (Debt-to-Equity)
📈 What is it?
The leverage ratio indicates how much a company relies on interest-bearing debt (such as loans and bonds) relative to its shareholders’ equity.
🧮 How is it calculated?
🏛️ Why is it important?
This ratio helps assess a company’s financial structure and risk profile. High leverage can enhance returns – but also increases exposure to interest rate changes and financial stress.
🧮 Calculation
🎯 What does this mean for investors?
- A low leverage ratio signals financial strength and independence.
- A higher ratio can improve returns in good times but increases risk during downturns or rising interest rate periods.
- 👉 Always interpret in the context of industry, capital intensity, and interest rate environment.
📘 Revenue
📈 What is it?
Revenue shows how much a company earns in total from selling its products and services – the gross income before any costs are deducted.
🧮 How is it calculated?
🏛️ Why is it important?
Revenue is one of the key figures to assess a company’s size, market position, and growth potential.
🧮 Calculation
🎯 What does this mean for investors?
- Growing revenue indicates rising demand and can be an early signal of future earnings growth.
- Comparing actual and expected revenue reveals trends in the market environment and analyst sentiment.
- Note: Strong revenue alone isn’t enough – margins and profitability matter just as much.
📘 EBITDA
📈 What is it?
EBITDA stands for “Earnings Before Interest, Taxes, Depreciation, and Amortization.” It reflects a company’s operating profit before the effects of financing, taxes, and accounting depreciation.
🧮 How is it calculated?
🏛️ Why is it important?
EBITDA is widely used to evaluate a company’s operating performance – especially across capital-intensive sectors or international comparisons.
🧮 Calculation
🎯 What does this mean for investors?
- A high or growing EBITDA indicates strong operational profitability – independent of taxes, interest, or accounting methods.
- It’s especially useful for comparing companies across sectors or geographies.
- Important: EBITDA is not a net income figure – it excludes key costs like depreciation and interest.
📘 EBIT
📈 What is it?
EBIT stands for “Earnings Before Interest and Taxes.” It reflects a company’s operating profit after depreciation, but before interest and tax expenses.
🧮 How is it calculated?
🏛️ Why is it important?
EBIT is a core profitability metric that shows how well the company performs in its main business operations – independent of capital structure and tax environment.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBIT indicates strong profitability from the company’s core business – before financial and tax effects.
- It allows better comparison between companies with different debt levels or tax structures.
- Compared to EBITDA, EBIT already accounts for depreciation and reflects capital intensity more clearly.
📘 Net Income
📈 What is it?
Net income is the company’s total profit – the amount left after all expenses, taxes, interest, and depreciation have been deducted.
🧮 How is it calculated?
🏛️ Why is it important?
Net income is the most comprehensive measure of a company’s profitability – showing how much actual profit remains after all business and financing costs.
🧮 Calculation
🎯 What does this mean for investors?
- Growing net income indicates that the company is managing all of its costs efficiently.
- It directly influences valuation metrics like P/E ratio and the company’s dividend capacity.
- Over time, net income trends reveal how resilient and profitable the business model really is.
📘 Free Cash Flow (FCF)
📈 What is it?
Free Cash Flow shows how much actual cash remains after a company covers its operating expenses and capital expenditures.
🧮 How is it calculated?
🏛️ Why is it important?
FCF reflects a company’s real financial strength – regardless of accounting profits. It shows how much flexibility a company has for dividends, share buybacks, or debt reduction.
🧮 Calculation
🎯 What does this mean for investors?
- High free cash flow means the company generates real, usable cash – independent of reported net income.
- It’s often the most reliable base for sustainable dividends and buybacks.
- Declining FCF can be an early warning sign – even when profits appear stable.
📘 Revenue Growth
📈 What is it?
Revenue growth shows how much a company’s sales have changed compared to the previous year – both on a trailing basis (TTM) and based on forward projections.
🧮 How is it calculated?
Forward = (Expected revenue ÷ Revenue in prior year − 1) × 100
Forward growth is based on analyst estimates for the current fiscal year.
🏛️ Why is it important?
Rising revenue signals growing demand, business expansion, and market share gains – especially important for growth-oriented companies.
🧮 Calculation
🎯 What does this mean for investors?
- Growth is the engine of long-term value creation – especially in tech and growth sectors.
- What matters is not just current growth, but its sustainability.
- Forward projections reflect whether analysts expect continued momentum – or a slowdown.
📘 EBITDA Growth
📈 What is it?
EBITDA growth shows how much a company’s operating profit (before interest, taxes, depreciation, and amortization) has increased or decreased compared to the previous year.
🧮 How is it calculated?
Forward = (Expected EBITDA ÷ EBITDA from prior year − 1) × 100
The forward estimate is based on analyst projections for the current fiscal year.
🏛️ Why is it important?
Growing EBITDA indicates improving operational profitability – regardless of financing or accounting effects.
🧮 Calculation
🎯 What does this mean for investors?
- Strong EBITDA growth signals operational efficiency and scalability – especially during growth phases.
- EBITDA growth can be an early indicator of margin and earnings expansion – but should be assessed alongside revenue and EBIT.
📘 EBIT Growth
📈 What is it?
EBIT growth shows how much a company’s operating profit (after depreciation, but before interest and taxes) has increased compared to the previous year.
🧮 How is it calculated?
Forward = (Expected EBIT ÷ EBIT from prior year − 1) × 100
The forward estimate is based on analyst projections for the current fiscal year.
🏛️ Why is it important?
EBIT growth is a direct indicator of a company’s business performance – taking into account capital intensity through depreciation.
🧮 Calculation
🎯 What does this mean for investors?
- Rising EBIT signals improving operating profitability – even after accounting for depreciation.
- It’s especially important for evaluating companies with significant capital expenditures.
- Combined with revenue and EBITDA growth, EBIT growth provides a well-rounded view of operational progress.
📘 Net Income Growth
📈 What is it?
Net income growth shows how much a company’s bottom-line profit has increased or decreased compared to the previous year – both on a trailing basis (TTM) and based on analyst projections.
🧮 How is it calculated?
Forward = (Expected net income ÷ Net income from prior year − 1) × 100
The forward estimate reflects analysts’ expectations for the current fiscal year.
🏛️ Why is it important?
Net income is the ultimate measure of profitability. Growing net income signals stronger efficiency, cost control, and sustainable earnings power.
🧮 Calculation
🎯 What does this mean for investors?
- Stronger net income boosts valuation, dividend potential, and investor confidence.
- If profits stall while revenue grows, it may signal margin pressure.
📘 Free Cash Flow Growth
📈 What is it?
Free cash flow (FCF) growth shows how a company’s available cash – after covering operating expenses and capital expenditures – has changed compared to the previous year.
🧮 How is it calculated?
🏛️ Why is it important?
Free cash flow reflects real financial strength. Growing FCF indicates more flexibility for dividends, share buybacks, and reinvestment.
🧮 Calculation
🎯 What does this mean for investors?
- Declining FCF may point to rising investments, increasing costs, or weaker operating performance.
- Especially for dividend investors, FCF growth is critical – since dividends are paid from actual available cash.
- A negative trend isn't always bad, but it deserves closer attention.
📘 Gross Margin
📈 What is it?
Gross margin shows how much of a company’s revenue remains after deducting the direct costs of goods sold (like materials and production). It represents the company’s “raw profit” before fixed costs, taxes, and interest.
🧮 How is it calculated?
Or simply: Gross Margin = Gross Profit ÷ Revenue × 100
🏛️ Why is it important?
Gross margin indicates how efficiently a company can produce or procure what it sells. It is a key measure of product-level profitability and pricing power.
🧮 Calculation
🎯 What does this mean for investors?
- A high gross margin suggests strong pricing power and efficient production.
- Falling margins may signal rising input costs or competitive pressure.
- Compared to peers, gross margin offers insights into the quality of a business model.
📘 EBITDA Margin
📈 What is it?
The EBITDA margin shows how much of a company’s revenue remains as operating profit before interest, taxes, depreciation, and amortization.It reflects operating efficiency without being distorted by financing or accounting factors.
🧮 How is it calculated?
🏛️ Why is it important?
The EBITDA margin reveals how much operating income a company generates per dollar of revenue – independent of capital structure and tax effects.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBITDA margin reflects strong core profitability – before accounting distortions.
- It allows for effective comparisons across companies and sectors.
- A stable or growing margin signals efficient cost control and business scalability.
📘 EBIT Margin
📈 What is it?
The EBIT margin shows what percentage of revenue remains as operating profit after depreciation but before interest and taxes.
🧮 How is it calculated?
🏛️ Why is it important?
The EBIT margin reflects a company’s core profitability while accounting for capital intensity (e.g. machinery, infrastructure). It’s especially useful for comparing businesses with different levels of depreciation.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBIT margin shows that the company remains efficient even after factoring in depreciation.
- It’s especially relevant for capital-intensive industries.
- Stable or rising EBIT margins over time are a strong indicator of pricing power and business quality.
📘 Net margin
📈 What is it?
Net margin shows how much of a company’s revenue remains as bottom-line profit after deducting all costs, interest, taxes, and depreciation.
🧮 How is it calculated?
🏛️ Why is it important?
Net margin reflects a company’s overall efficiency – across operations, financing, and taxation. It shows how much actual profit is generated from each dollar of revenue.
🧮 Calculation
🎯 What does this mean for investors?
- A high net margin means the company is not only strong operationally but also manages financing and taxes efficiently.
- Peer comparisons reveal business quality and competitiveness.
- Declining margins despite revenue growth can be a red flag for rising costs or inefficiencies.
📘 Free cash flow margin
📈 What is it?
The free cash flow (FCF) margin shows how much of a company’s revenue remains as actual free cash after covering all operating expenses and capital expenditures.
🧮 How is it calculated?
🏛️ Why is it important?
This margin reflects the true liquidity generated by the business – independent of accounting rules or depreciation. It’s especially relevant for dividends, buybacks, and reinvestment decisions.
🧮 Calculation
🎯 What does this mean for investors?
- A high FCF margin means a company consistently generates strong cash flow.
- It’s a positive signal for financial stability and shareholder returns.
- The long-term trend is key – a declining margin may indicate rising investments or weakening operating efficiency.
📘 Earnings per share (EPS)
📈 What is it?
Earnings per Share (EPS) shows how much profit is attributable to a single share – and is one of the most important metrics for evaluating a company's performance.
🧮 How is it calculated?
The diluted share count reflects potential new shares that could be issued through options, convertible bonds, or other rights.
🏛️ Why is it important?
EPS is the basis for many key valuation metrics like P/E ratio, PEG ratio, or payout ratio. It enables comparisons of profitability across companies, regardless of their size.
🧮 Calculation
🎯 What does this mean for investors?
- EPS captures per-share profitability and is especially useful for comparisons over time or with analyst estimates.
- Rising EPS may signal consistent growth or share buybacks.
- Important: Always use diluted EPS for more realistic valuations – especially in companies with stock-based compensation.
📘 Free cash flow per share (FCF per share)
📈 What is it?
Free Cash Flow per Share shows how much free cash flow a company generates per outstanding share – after investments, but before dividends or debt repayments.
🧮 How is it calculated?
Free cash flow is calculated as operating cash flow minus capital expenditures (CapEx).
🏛️ Why is it important?
FCF per Share reveals how much real cash is available per share – useful for dividends, buybacks, or reducing debt. Unlike net income, free cash flow is harder to manipulate and often seen as a more reliable metric.
🧮 Calculation
🎯 What does this mean for investors?
- High FCF per share signals strong financial flexibility.
- It shows how much capital the company can effectively reinvest or return to shareholders.
- Particularly relevant for dividend payers and capital-efficient businesses.
📘 Short interest
📈 What is it?
Short interest indicates how many shares of a company are currently sold short – that is, borrowed and sold by investors who expect the price to decline.
🧮 How is it calculated?
It reflects the percentage of a company’s shares that are being shorted relative to the total shares available.
🏛️ Why is it important?
Short interest serves as a sentiment indicator: A high value may signal skepticism or bearish expectations – but also increases the potential for a short squeeze if prices rise unexpectedly.
🧮 Calculation
🎯 What does this mean for investors?
- Low short interest usually indicates market confidence in the company.
- High short interest can be a warning sign – or an opportunity if sentiment shifts.
- Especially relevant in volatile markets or ahead of key earnings releases.
📘 Employees
📈 What is it?
The employee count shows how many people a company employs worldwide – offering insights into its size, structure, and business model.
🧮 How is it calculated?
🏛️ Why is it important?
It helps assess operational scale, labor intensity, and cost structure. Combined with revenue and profit, it enables key metrics like revenue per employee or productivity.
🧮 Calculation
🎯 What does this mean for investors?
- A high headcount can signal operational complexity – but also significant growth capacity.
- Revenue per employee is a key indicator of efficiency.
- Especially useful for comparing tech, industrial, or service-heavy companies.
📘 Turnover per employee
📈 What is it?
Revenue per employee indicates how much revenue a company generates on average per employee – a key measure of efficiency and productivity.
🧮 How is it calculated?
The employee count is typically taken from the most recent annual report.
🏛️ Why is it important?
This metric helps compare business models – especially between labor-intensive and technology-driven companies. A high value suggests automation, operational efficiency, or strong value creation per head.
🧮 Calculation
🎯 What does this mean for investors?
- A high revenue per employee indicates a scalable and margin-strong business model.
- A low figure may reflect labor-intensive operations or lower value-add.
- Especially helpful when comparing tech companies to industrial or service sectors.
Elastic NV Stock Analysis
Analyst Opinions
36 Analysts have issued a Elastic NV forecast:
Analyst Opinions
36 Analysts have issued a Elastic NV forecast:
Elastic NV Events
Past Events
|
SEP
22
Special Call - Elastic N.V.
3 days ago
|
|
AUG
27
Q1 2027 Earnings Call
28 days ago
|
|
JUN
10
Rosenblatt 6th Annual Age of AI Technology Summit
4 months ago
|
|
JUN
4
Bank of America 2026 Global Technology Conference
4 months ago
|
|
MAY
28
Q4 2026 Earnings Call
4 months ago
|
|
MAR
2
Morgan Stanley Technology
7 months ago
|
|
FEB
26
Q3 2026 Earnings Call
7 months ago
|
|
JAN
14
28th Annual Needham Growth Conference
8 months ago
|
|
DEC
10
Barclays 23rd Annual Global Technology Conference
10 months ago
|
|
NOV
20
Q2 2026 Earnings Call
10 months ago
|
|
OCT
9
Analyst/Investor Day - Elastic N.V.
12 months ago
|
|
SEP
11
Piper Sandler 4th Annual Growth Frontiers Conference
about one year ago
|
|
SEP
8
Goldman Sachs Communacopia + Technology Conference 2025
about one year ago
|
|
SEP
4
Citi’s 2025 Global Technology
about one year ago
|
|
AUG
28
Q1 2026 Earnings Call
about one year ago
|
StocksGuide Free
Elastic NV — Special Call - Elastic N.V.
1. Management Discussion
Hello, and welcome to the Elastic Observability Update Metrics Call. Today's call is being recorded. [Operator Instructions] I would now like to pass the call to Alex Kurtz, Vice President of Investor Relations. Please proceed.
Good morning, everyone, and welcome. I'm Alex Kurtz, Vice President of Investor Relations here at Elastic. Thank you for joining us today for a deep dive into our new metrics offering. Joining me are Baha Azarmi, General Manager of Observability; and Santosh Krishnan, Senior Vice President of Security and Observability Solutions. For today's agenda, Baha will start with a brief presentation followed by a short customer video, and then we'll open the floor to Q&A. But first, let me quickly run through our legal disclaimer. Our presentation today will include forward-looking statements, which may include predictions and expectations regarding the market and demand for our products and solutions as well as expected capabilities of our products and solutions.
These forward-looking statements are based on factors currently known to us, speak only as of the date of this presentation and are subject to risks and uncertainties that could cause actual results to differ materially. We disclaim any obligation to update or revise these forward-looking statements unless required by law. Please refer to the disclaimer of risks and uncertainties shown here as well as those more fully described in our filings with the Securities and Exchange Commission. With that, I'll hand it over to Baha.
Thank you, Alex. Let me go to the next slide. All right. Hey, everyone. I'm Baha. I'm the General Manager of Observability here at Elastic. I've been at Elastic for 11 years, and it's a pleasure for me today to present you with our new metrics offering. So our new metrics offering has been launched almost at the beginning of our fiscal year in June. And so what we've done with this new metrics offering is entering this market with a solution that is not only meeting our customer requirements, but also surpassing some of the best metrics solution in the market. And so you will see in this presentation how we did it. But in the high-level lines, we rearchitectured Elastic Search for metrics, and we are also meeting our customers where they are. And we also made sure that we are preparing our -- we're building our metrics solution for what our customers are doing today, namely looking at AI workloads.
And so 3 characteristics of our metrics solution. First, it's blazing fast. If you enter the metrics market, you have to be fast, and that's one of the guiding principle for our solution. We looked at benchmark against competition -- competitive solution such as Prometheus and Mimir. I'll get into the numbers more in detail later in this presentation. The other thing we've done is we don't want our customers to go from one solution to another when they have their logs, their traces and their metrics with us. They need to stay in the same platform, the data store, should be the same. It's completely transparent for them to store all those signals with us when they do observability as well as when they query the data in Elastic or they go through the different experiences we have for observability.
Everything leaves in the same platform. And lastly, we built it for AI. When the workload shape has changed with AI, having now agents more than traditional application, it brings much more signals, much more data and much more metrics than before. So we thought about our metric solution to be as efficient as possible to cope with the new type of workloads. But before I get into more details about what we've done, just level setting with everyone, if you're not familiar with what the metrics are, metrics is the main signal in Observability. That is literally what wakes up engineers at 3:00 a.m. in the morning when there is an incident, page people when there is something to look at. And so when you use an Observability solution, you create rules. Those rules are triggering alerts and 99% of the time, those rules are based on metrics.
And so a couple of examples here on the screen. You can create -- say you have an application, a web application and you're looking at the traffic on this application, you will look, for example, at the number of HTTP requests. This application relies on an infrastructure, on an application stack. There are different technology involved and resources that are allocated to this app. And so you will look at the resource utilization such as the CPU or you can also look at things like the latency of the request going into the APIs you're exposing through this application. So a lot of those characteristics of your application are emitting metrics, your application, your infrastructure are emitting metrics. Those metrics are capturing Observability solution and then you create rules that triggers alerts that then page people.
The thing that has changed is when you look at a traditional application, say, a banking application and you go yourself as a user in your bank account and you look at your statement, you scroll through the statement, you click on an item. All of those are predefined path and transaction into those applications that are quite traditional. You have front end, the back end and data store, database, microservices, cloud deployments, all of that, I put this into the bucket of a traditional application. And so not only those transactions are well known. And in addition to this, like I said, this emits traces, logs and metrics. And so there is a predictable volume you could expect for it. But for agents, it's very different.
AI is really causing an explosion in metrics. And when I say AI, you can think about the different type of workload or things you need to observe such as LLM calls, GPU cycles, write queries, agents and harnesses. All of that is creating a new set of Observability signals that needs to be captured. But then the challenge is, as you all know, when you interact with an LLM, there is reasoning steps and those reasoning steps depend on what you're asking for. It goes into tool calls. Those tools are not necessarily known in advanced. And so now you have agents calling your traditional application probably exposed through MCP, and it's really unpredictable amount of turns you won't get with agents. So that goes now a new paradox for customers.
First, customers have to think about how am I going to cope with all that data. And we know that there are solutions out there that are penalizing customers and they are not able to keep all the data. The problem with this is then they will -- they start to have blind spots. They have to compromise on the number of data they can chip. And then when there is an incident, they don't get the full fidelity on what happened and then -- and it becomes difficult for them to understand what the root cause is. So new challenges with AI. And so when we started to think about how we will go to market with this new metrics offering, we set a couple of guiding principles, and I will explain those more in detail in later slides. But first, we introduced a new way to store metrics and not only to store them, but also to manage them.
So it comes with functionalities that will automatically roll up, down sample or compress the data. Second, we wanted to make sure that users of Metrics solution will feel familiar when they land with Elastic and use our metrics offering. And so we put a particular attention to support standard in the market such as PromQL, and we will see that. And lastly, again, we build it for the AI scale. So you saw that AI is bringing more data and new things to observe, and we build it for that with the efficiency that is required to cope with that workload. And so you know that -- you know Elastic probably for logs. Our customers are trusting us for their messy logs. We're more than happy to receive all that unstructured data. We're -- at the core, we are a search engine, so very good for structured and unstructured data. Logs are flowing in. They get into a document store. We extract those fields. and then we make them available for aggregation.
We can full text search on it. So that's our story on logs and how we do it. We use a document store. For metrics, the game is very different because metrics have a different shape than logs. There are numbers. They come with labels. So for example, you have something like a number that represents the CPU usage. You have a time stamp, you have dimensions. It belongs to this host that is deployed on this Kubernetes pod that is deployed on this region of the world that is deployed on this cloud provider, et cetera, et cetera. So many different dimensions. And so for this to cope with metrics, we completely rearchitectured Elastic Search for it, and we build a column store within Elasticsearch because metrics are coming with their own challenges.
I just talked about the dimensions. First, the dimensions is something that is very hard to manage for existing metric solution in the market. And we wanted to make sure that we were not limiting our customers in terms of the cardinality. Those are the words you will hear a lot with metric solution out there. Cardinality is something we don't want to limit, so you can have as many dimensions as you want. But then we say that and then our users are like, okay, but what does that do in query? Because when you have a lot of dimensions, it starts to be difficult to manage all that data in memory. And so column store are really well architecture or really -- it's a great fit for metrics. Let's say you have 30 dimensions, going through 30 dimensions when you query has its own challenge. When you go to 2 dimension out of the 30, you need to just take those 2 dimensions and not parse the data for the 28 left.
And so that creates some challenges in memory that we actually solved with techniques like dim filter. We also solved how we can manage the data on storage and make sure that it's efficient by tuning our codecs. So we use a lot of techniques, as many techniques as we can to make sure that our columnar data store is efficient for querying and for storage. And the numbers are telling. We have documented our benchmarks. They are available online. You have them in detail, but open source code, so you can run it and verify those numbers. So what we've done for logs, we've done it also for metrics, and we're very proud of it. We're benchmarking regularly against the noted competitors here to be 30x faster than Prometheus and Mimir, 8x faster than ClickHouse and get storage efficiency for our customers. So when they think about consolidating their metrics alongside the logs they have with us, they see immediately performance gain and immediately storage efficiency.
So like I said, we have logs that goes into DocumentStore. We have metrics, logs and traces to DocumentStore. We have metrics that goes to columnar store. We have vectors that goes into vector store. But what does that mean for Observability? We have this platform with integrated stores that benefits our users for Observability. And how we do that, imagine that question on the right-hand side, why is checkout slow? And imagine a user will ask it through our AI agent or directly an AI agent through investigation will ask this type of question in natural language through the reasoning. Those are going through many data layers, metrics. It goes then to traces, looks at the signals in traces and services and then drill down into logs. And maybe the customer will bring their knowledge base and this knowledge base is vectorized.
And so you can see that bringing all those data store in an integrated way and an efficient way allows us to be ready for this type of reasoning that is done with AI through agent leak, directly with our users through chat. And so we are enabling our users to RCA this way with those different data store integrated together. And so like I said, we build it for AI scale, but we also build it for a product that we've been cooking for quite some time. And you probably have seen that recently, we made the acquisition of a company called Deductive AI that is specialized in RCA investigation with agents. And so if you're there in New York on the 8th of October, you will hear from us one of our big announcements in Observability we've done. We worked quite a lot on our AI story solution. So we're very excited to share this with you. Stay tuned and come and attend our Elastic on the 8th of October in New York to hear more. So we launched our metrics offering. I've talked a little bit about our storage efficiency and performances, but our metrics offering is also coming with a ton of functionality which I tried to categorize for this webinar into those 3 categories with functionalities that are -- that relates to meeting our customers where they are with PromQL, giving our customers with rich content, so they don't have to rebuild anything when they use our metrics offering and integrating this with different consumption surface than our UI for our customers' harness and agents and making sure that our AI agent is also ready to serve with Metrics insights within our solution.
I'll go through some of it now. So the first thing we wanted to make sure we had is PromQL native support with our Elastic Metrics offering. which means that a user can take their PromQL queries, copy and paste it into Kibana, and it will just work. And to do this, we are using the most popular dashboards out there that are using PromQL and making sure that we're bringing 100% compatibility. We reached the 90%, and we are on track to get to 100%. So now our users feel familiar with our metrics offering by acquiring with PromQL and also can use our AI agent to generate those queries directly into the solution. The other thing that our customers are asking us and specifically the logs customers we have that want to bring their metrics alongside the logs with us is to help them migrate.
And of course, we have a professional services team that does that, but we felt that we needed also to have tools in the solution that will help customers to migrate from their solution to us. So we're delivering this as part of the solution today. The experiences we've built, we actually think about the existing experience we have and adapted for metrics. We actually rebuilt them for metrics. And so when I say rebuild and experience, that means delivering content out of the box and content is dashboards, visualization, alerts, SLO, skills, machine learning jobs, workflow -- all of that comes into an experience. They're fully loaded. We started with Kubernetes, which is -- which has the highest demand. We have AWS. We're working on other integration today. We even went above and beyond in terms of how we think an experience should be with, for example, integration with technology partner like Temporal, Supabase and Vercel, where we have not only experiences as shown on the screen, but we also have managed endpoints.
What does that mean? It means that a user that use, for example, Vercel can point to our metrics endpoint, send their metrics, and we will manage that ingest for them. It will scale as the data comes through. They will lend into our solution and immediately have the experience they need for Vercel. So this is the type of end-to-end experience that we're building for our customers. So not only we have specific technology endpoints to manage that intake of data, but we also have OTel and PromQL, Prometheus endpoints to bring the data into our metrics offering. The other thing we want to do is to democratize metrics for any users. So if you're not a PromQL user and you don't have necessarily that expertise and you want to be able to query the data, you can do that in natural language directly into our agents. More importantly, our users start to tell us that they -- on day 0, the way they consume Observability is not necessarily into our UI. They're directly going into their agent and calling the tools and skills that we expose for them to consume the insight they have into our Observability solution.
And so we are fully embracing this. Like I said, we're delivering MCP server, tools, skills, but also MCP app. What you see on the screen is our Observability MCP app. You can interact with it. It will give you insight on the anomalies that exist in your system, the blast radius of an incident. And so all of this can be done outside of our UI in cloud, for example, in cursor, you name it, the harness that our users are using is where we're going to meet them. Lastly, in terms of go-to-market, we have 3 plays. First, we want to make sure that we are going and seeing our logs customers and attaching metrics to it because this is one of the demand that our customers have. They want to be able to investigate through their Observability signals all into the same place versus going into different solutions. So that alone is a huge opportunity for us.
Second, we also have the PromQL shop. So users of Prometheus and PromQL who wants to see immediately efficiency in terms of the query, efficiency in terms of the storage, but also scalability and not limited cardinality. This is also a place where we go and help our customers to consolidate in Elastic. And then the last play is for the customers that are being penalized to either keep metrics for a longer time or bring their own -- bring customer metrics or just use metric solution. Some of the solutions out there are really penalizing in terms of the pricing that then creates the consequences that I've said at the beginning, blind spots, which is not ideal when you have incidents. And so we want to win on the economics and go after that portion of the market as well. All right. With that, I'm finished. I will hand it over to Alex.
Yes. Thanks, Baha. And now we're going to present a quick Elastic customer video from Norion Bank discussing their Observability strategy and their use of our new metrics offering. And then after that, we'll proceed to Q&A.
My name is Tim, and I'm an Observability platform engineer at Norion Bank. My role is to make sure our engineer teams have the visibility they need to understand and operate their services reliably. And we support multiple development teams across the organization, helping them troubleshoot faster, improve reliability and get better insights into how the application behave in the production environments and test and CI and so on.
So I'm [Johan Andersson], Observability platform engineer at Norion Bank. I've been part of the Norion family now for almost 4 years, first as a consultant, now full time. Our team runs the Observability platform that the rest of the bank builds on. So ingest the Elastic infrastructure itself and tooling around it and helping teams have with any problems they may have.
Yes. One of the biggest challenges today is simply the amount of data. Modern environments generate huge volumes of logs, metrics and traces. And the challenge isn't to collect data anymore. It's turning the data into actionable insights.
A few challenges we have. I would say one of the obvious for us being a bank is the compliance versus velocity. So DORA and GDPR, which are regulatory systems mean that every change and pretty much every log line is auditable, that pulls against the delivery speed that the business wants. Then there's the telemetry volume. Our data grows faster than the value we get out of it. So we're constantly making calls on what to keep and for how long. This without going blind the moment something breaks or when we're reviewing a past incident. But I would say that our main concern -- my main concern is that the question often becomes how do we get -- make this cheaper instead of how does this get us out of incidents faster.
We at Norion Bank have been using Elastic for 8 years, I think, give or take. And our usage has grown significantly over the time. Initially, we focused primarily on centralized logging. As our Observability maturity increased, we expanded into metrics, APM, distributed tracing and OpenTelemetry and so on. So today, Elastic plays a much broader role in our Observability strategy instead of looking at individual signals in isolation, we can correlate logs, metrics and traces in the same platform.
Two things that's very positive about Elasticsearch to me is Elastic common schema. So instead of correlating logs across system, it's becoming a query instead of an integration project, which it has been for us. And then there's the range of Elasticsearch. I mean the same building block goes to a small single node hobby project closer to what we have that is a multi-cluster production setup.
We really appreciate having a unified platform as Elastic is. Our engineers don't need to jump between multiple tools and understand what's happening in our production environment or when they're testing new applications. They can move seamlessly between logs, metrics and traces and so on doing investigation on a potential incident as well.
We have tested some of Elastic new metrics features. Specifically, I'm quite impressed with time series data streams. So we built a small collector for our Azure DevOps pool cues and ingested it into a time series data stream. And the storage savings we saw just after a month was substantial. So metrics is really the only signal cheap enough to collect from everything continuously. So that gives us a very good baseline on what to alert on. So I mean, logs and traces explain why something breaks, but metrics tells us that it's starting to break and how bad it's getting. So for us, many of the failure modes we look at is things like heap, disk watermarks, ingest lags and that sort of thing. And those are mostly gradual and show up in metrics long before any user notices anything is wrong.
We pay a lot of money for this and being able to have the data, it's very important for us to be able to quickly identify when something is breaking because, I mean, even though Observability costs a lot, it does so due to the fact that we will have a very good tool to see that things are breaking before and being able to sort of circumvent them. Time series data works by declaring the dimensions, let's -- it lets Elastic search co-locate sort series together, so compression gets much better without really costing any query performance. In our new nonproduction environment that is eventually going to be our entirely new setup, we have integrated Kubernetes using Elastic Agent to monitor and collect logs from pods and so forth. So yes, the experience is that it works really well. Nothing more to say. It just works.
[Operator Instructions] Our first question today comes from Rob Owens at Piper Sandler.
2. Question Answer
Maybe you can, at a high level, just talk about how long it took you to rearchitect this solution in terms of either dollars, man hours? And what type of competitive moat this provides you relative to the competition and for how long?
Thanks for that question. I can definitely address that. So this has been in R&D for a good, I want to say, 12 to 18 months at least. So we launched this in June, and it was probably in development for a good 18 months prior to that. In terms of the competitive moat, Baha touched upon this a little bit. But we always get an asymmetric advantage whenever we add innovation to the platform.
So as you are all aware, we have had a very strong platform when it comes to dealing with unstructured messy logs. And what we have done over here is we have extended that kind of a benefit to a brand-new use case where some of our customers had been using us in some capacity in the past, but this is the first time we have introduced a purpose-built solution right in the platform for the proliferation of metrics, which is happening. So that's where we expect our sustainable advantage to be.
Our next question today comes from Howard Ma at Guggenheim Securities.
Great. Can you help us bridge customer adoption of Elastic for metrics today to a future steady state? I believe about 2/3 of the business today is tied to logs, either operational logs or SIEM. So how are you aggressively marketing metrics of that entire base? And on a related note too, how do you think Elastic will be used alongside other metrics platforms? Will it be incremental to usage of other metrics platforms? Or more importantly, how do you ensure Elastic becomes a primary metrics engine versus the competition out there?
Definitely. It's a great question, Howard. So the way to think about our proliferation today in customers, so you did mention adoption in logs as well as on the SIEM side in security. Where this offering plays is really on the first part, of course. So it's more towards SRE teams who have been using us as a centralized logging platform. If we look at that customer base today, most of them use a second and third tool for doing things like infrastructure monitoring, et cetera. And the -- let us call it, the economic value of that may even far exceed the value that we are providing when it comes to log analytics. So that is what presents the opportunity for us to go after a part of what you mentioned, so the log analytics platform for SREs and then go to that customer base and attach metrics to it.
So that's really the -- let us call it, the shortest-term opportunity. Now to your second question on do we anticipate other tools as well? Practically speaking, these kind of adoptions are gradual. So in some sense, this is a newer product for us in terms of our purpose-built solution over here, which we launched only at the end of June. So practically speaking, we will see a gradual kind of adoption over there. And we do expect some coexistence with other tools in the short term. Our goal, of course, is to provide a consolidated solution for all of our customers' logs, metrics and traces.
Our next question comes from George McGreehan of Bank of America Securities.
This is George McGreehan on for Koji. Kind of following up on that last question there, do you think there are any sort of product unlocks that are required to take maybe a customer's existing metrics use cases, all of them and consolidate all of them onto Elastic? And then maybe a second part to the question, kind of ultimately, what is kind of the uplift opportunity on the average logs customer that you have if you can consolidate all their metrics?
Yes. So definitely, I mean, the product unlocks are a lot of the things that Baha presented. So I think as I alluded to in one of my prior answers, since we have an open platform, our customers have been using us for all signals in some sense in an incidental fashion. So a lot of our customer base do enjoy us for log analytics. So majority of them use us for log analytics. And some of them, they were using our platform for other use cases as well. The specific unlock that was required over here was an efficient blazing fast store. So the one thing to remember is we are definitely piggybacking on an inflection point that is happening with AI. And that inflection point comes in 2 ways. It comes with the larger amounts of infrastructure, which are getting deployed that need to be monitored as well as a whole bunch of agent activity and so on, which needs to be monitored as well.
And that has what has created the need for a more economic metrics platform at the data store level. So we are using that inflection point to enter the market in a serious way right now. And that, I would say, is a big part of the unlock sort of giving us a license to participate. The other part of the unlock is support for things like Prometheus -- sorry, the PromQL query language because that's how a lot of the metrics business gets done on the SRE side of the house as well as the ability for customers to just bring the dashboards that they were using in other tools and just migrate them over to Elastic as well. So that is the other part of the unlock. So think of it perhaps as equal parts, the data store efficiency that AI demands and on the capability side, support for query languages, dashboards, visualizations and last, but not the least, the ability to be able to chat with your data as well.
So those are the unlocks that we actually just released in June. And that does put us in a good spot to gradually take over those metrics workloads from our existing customers as well as go after new customers. In terms of putting like a number on it, it's early days. So stay tuned. The best way to think about it is we have been on one side of Observability when it comes to SRE team spend. We can now participate in the other side seriously as well.
Okay. We're just going to transition to some questions that we got over the chat. So on AI pacing, if Model Labs decided to spend more on R&D to ensure safety, how does that impact spend for the category -- Observability as a category?
Yes, definitely. I mean -- and we hinted at this in at least a couple of places in the presentation as well as in this discussion. So AI does provide an inflection point, and I'm going to speak only on the Observability side of the house since we are talking about our metrics offering over here. So 2 very specific ways. One is, of course, as you all know, infrastructure spend is going through the roof and a lot of that is really in support of all of the agents and the models which are getting deployed. And that comes with its burdens of monitoring at first, the infrastructure level, just to understand uptime, understand how many agents are getting deployed, the proliferation of them and so on.
So that needs proper Observability and monitoring goes without saying. The other part of it is what are those agents themselves doing. And this is where some of the agent Observability side of the house comes in as well, and there is a tie-in over there to properly monitoring agents, both from an uptime health point of view as well as a safety point of view to understand what those agents are doing. So there is definitely a time when it comes to how agents are getting deployed, the infrastructure on which they are getting deployed as well as what the agents are doing.
Okay. Great. Last question I have here is, what does the adoption curve look like for a stand-alone metrics offering like the one we just went through today. That's kind of the high-level question. I would say just from our view of that we just launched this product a few months ago. It has to now go through a traditional enterprise selling motion, right? And that's a little bit different between the new customer and existing customer. So our sales teams are just getting their hands into this and talking to customers. But maybe, Santosh, you want to spend a little bit of time talking about how you expect to see this product pushed into the market, existing customers, new customers and how that may look?
No, it's exactly right. I mean we are a couple of months since launch. And the early design partners as well as the early engagement has been extremely positive. At the same time, I think as Alex mentioned, these are longer sales cycles. So we do expect adoption to see more of a ramp style as opposed to like a hockey stick immediately.
We've got one more question here from Tom. Operator, can you let Tom in here?
Sure. Thomas Blakeley from Cantor Fitzgerald.
Thank you, Alex, and thank you, everyone, at Elastic for hosting this. Very helpful. I think maybe a different way of asking some of the prior questions is could you compare metrics data consumption to logs in general, especially for these high cardinality type of AI workloads that you're describing here? Maybe as a second follow-up to that question, we're talking about agentic here and these types of use cases. Is there any other area, maybe security specifically that you're kind of targeting with these metrics products?
So in terms of the metrics volume, the best way to think about that is in terms of the data that is coming in, you can almost expect the metrics volume to be in the comparable order of magnitude as logs. There may be one distinction in that people typically like to keep logs around, so on the retention side. So think of it as data coming in, getting processed, people actioning them and data that is kept around for long periods of time for retroactive analysis and such. So in terms of volume of data coming in, you should assume that it is in the same order of magnitude, and you can do the math from there as we see in logs. But in terms of data getting retained, we do see logs getting retained for a longer period of time. To address the second question, now I don't know whether that was a fully satisfactory answer, but that's the way...
It was. It was.
In terms of the security side of the house, I want to -- see, I mean, our focus over here is really on the SRE workload. So I do want to clarify that part. So this is mainly for the Observability business on the SRE side of the house. On security, there may be incidental use, but I don't want to project that there is going to be massive use of the metrics that are showing yet. So that is something that we are continuing to monitor.
That's helpful. And maybe, Alex, if I could squeeze one more in. I think you mentioned to the prior question about the timing here. So it might be premature. But should we think about this as a spend consolidation trend from taking -- like you mentioned Prometheus, like taking spend that's already happening on a workload from another? Or is this about net new workloads, right? And then that would make maybe semi easier motion to consolidate the logs and metrics just on Elastic that way.
Yes. I can address a little bit of this, Alex, which is this -- there is definitely a spend consolidation aspect to it. So in some sense, platforms are consolidating around all of these use cases, which is no secret. So we do see that spend consolidation. Where I want to say there is a little bit more of sort of the gravy on top over here is the AI part of it. So a lot of our customers are reevaluating their needs based on the additional volumes of infrastructure that they need to monitor and so on. So there is a little bit of a reevaluation of existing tools for the new world of AI. So certainly a spend consolidation aspect to it, but with a new lens of higher amounts of, let us call it, infrastructure and metrics to be used for monitoring. Alex, you wanted to add anything over there?
No, I think you nailed it.
That concludes the allotted time for today's Q&A session. So I will now hand the call back to Alex Kurtz for closing remarks. Thank you.
Yes. Thanks for joining our call today. If you have any follow-up questions, please reach out to us at [email protected]. Thank you.
This concludes today's conference call. You may now disconnect.
Elastic NV — Special Call - Elastic N.V.
Elastic unveiled a purpose‑built, AI‑scale metrics product (launched June) that rearchitects Elasticsearch for fast, storage‑efficient time series and PromQL compatibility.
📣 Key Message
- Launch: New metrics offering launched in June with a rearchitected Elasticsearch that includes a columnar/time‑series store aimed at high‑cardinality, AI (large language model) workloads.
- Consolidation: Product is positioned to let existing logging customers and Prometheus users consolidate metrics, traces and logs in one platform and query via natural language or agents.
🎯 Strategic Highlights
- Architecture: Columnar time‑series data streams and tuned codecs to reduce storage and speed queries; built to avoid cardinality limits common in other metric stores.
- Compatibility: PromQL (Prometheus Query Language) native support (~90% today, on track to 100%) and migration tools to import dashboards and queries.
- Go‑to‑Market: Three plays—attach metrics to Elastic log customers, win PromQL users on performance/economics, and target customers penalized by high metrics pricing.
🔭 New Information
- Benchmarks: Company-published numbers claim ~30x query speed vs Prometheus/Mimir and ~8x vs ClickHouse plus material storage efficiency; benchmarks are open source for verification.
- Integrations: Managed ingestion endpoints for partners (e.g., Vercel), time series data streams, natural‑language agent access, and integration with Deductive AI (RCA/agent investigations) with a public announcement planned Oct 8.
❓ Analyst Q&A
- R&D & moat: Management said ~12–18 months of R&D before the June launch and expects a platform advantage by extending Elastic’s log strengths to metrics.
- Adoption path: Early customer feedback positive but enterprise sales cycles are long; expect a gradual ramp as sellers target existing log customers first.
- Scope & sizing: Management noted metrics ingestion can be comparable in volume to logs, clarified the primary focus is Site Reliability Engineering (SRE) workloads (not a large immediate security push), and declined to quantify revenue uplift yet.
⚡ Bottom Line
- Implication: The product materially expands Elastic’s addressable Observability opportunity by offering consolidation and potential cost/performance advantages, but adoption will hinge on enterprise migration wins, verification of benchmark claims, and a measured sales ramp.
Elastic NV — Q1 2027 Earnings Call
1. Management Discussion
Good afternoon, and welcome to the Elastic First Quarter Fiscal 2027 Earnings Results Conference Call. [Operator Instructions] Please note, this event is being recorded.
I would now like to turn the conference over to Ash Kulkarni, Vice President of Investor Relations. Please go ahead.
Good afternoon, and thank you for joining us on today's conference call to discuss Elastic's first quarter fiscal 2027 financial results. On the call, we have Ash Kulkarni, Chief Executive Officer; and Navam Welihinda, Chief Financial Officer. Following the prepared remarks, we will take questions. Our press release was issued today after the close of the market is posted on our website. Slides, which are supplemental to the call can also be found on Elastic Investor Relations website at ir.elastic.co.
Our discussion will include forward-looking statements. which may include predictions, estimates or expectations regarding the demand for our products and solutions and our future revenue and other information. These forward-looking statements are based on factors currently known to us, speak only as of the date of this call and are subject to risks and uncertainties that could cause actual results to differ materially. We disclaim any obligation to update or revise these forward-looking statements unless required by law.
Please refer to the risks and uncertainties included in the press release that we issued earlier today. Included in the slides posted on the Investor Relations website and those more fully described in our filings with the Securities and Exchange Commission. We will also discuss certain non-GAAP financial measures. Disclosures regarding non-GAAP measures, including reconciliations with the most comparable GAAP measures can be found in the press release and the slides. Unless specifically noted otherwise, all results and comparisons are on a fiscal year-over-year basis. Webcast replay of this call will be available on our company website under the Investor Relations link.
Our second quarter fiscal 2027 quiet period begins at the close of business on Friday, October 16, 2026. We'll be hosting a virtual public webinar highlighting our improved metrics capability on September 22 at 8 a.m. Pacific Coast Time, which will be made available on our IR website for viewing. See the Elastic Investor Relations website for more details.
With that, I'll turn it over to Ash.
Thank you, Alex. Good afternoon, everyone. Thank you for joining us to discuss our first quarter fiscal 2027 results. We are pleased to report a strong start to the year with continued strength in sales execution. We beat across all guided metrics and demonstrated the constant currency growth acceleration in revenue and sales-led subscription revenue that we called out last quarter.
Q1 total revenue was $478 million, growing 15%. Sales led subscription revenue grew 18% to $399 million and we delivered a non-GAAP operating margin of 16.2%. As we previously noted, we entered fiscal 2027 with a plan to accelerate our sales-led subscription revenue growth on a constant currency basis over the course of the year, and our Q1 results demonstrate that we are off to a good start.
Customer demand was strong across all solution areas, especially in search and AI and security. We ended Q1 with more than 1,800 customers spending $100,000 or more in ACV. This is the highest quarter-over-quarter net additions to this $100,000 metric that we have ever seen. Our 21% CRPO growth and 27% RPO growth signal that customers are continuing to make multiyear commitments to our platform as long-term AI transformations are taking hold.
AI is reshaping the stack that developers build upon. The focus is no longer on token Maxi. It is on building agentic applications that leverage the reasoning and influencing power of LLM on a business's proprietary data. This requires the highest possible retrieval accuracy at the lowest possible cost. That shift plays directly to elastic strength, and we have invested accordingly in critical areas. First, we have invested in a highly optimized data store and retrieve for AI. Our goal is for Elastic search to be the best store for all data that our customers care about, enabling text, vector and hybrid search across structured and unstructured data, spanning text, vectors, images, audio, video and more.
We released Vector DB index mode and auto calibration this quarter giving developers a high-quality vector search experience out of the box with no manual tuning required, 1 platform with support for every data type AI demands. Second, in precisely accurate context, we continue to be 1 of the world's most powerful contact platforms for AI. This quarter, we brought Gena's multimodal and multilingual semantic search capabilities, including first-party embedding and reranker models to on-premises and air gap environments. This extends the power of our first-party models to the world's most sensitive, regulated and security-conscious deployments.
Our agent builder harness continues to mature as well. enabling developers to build agents directly on top of data in Elasticsearch. Agent Builder now offers advanced agent observability, monitoring and enhanced human-in-the-loop approval workflows, giving enterprises the control and visibility they need to deploy AI agents with confidence at scale. Our investments are translating directly into competitive wins, a global 2,000 semiconductor company selected Elastic search services in a 7-figure new logo win to power a personalized AI-driven knowledge search experience for its customers.
Elastic Search will serve as a context layer transforming the company's vast product catalog into real-time grounded AI context. When a customer queries a chip specification, compatibility requirement or part number agent builder returns an accurate answer with per user document level security, ensuring each customer sees only what's relevant to them. In a competitive RFP against pure-play vector databases and other platform players our hybrid Symantec retrieve and natively integrated agent capabilities were the decisive differentiator.
AI is also changing the arena of observability as organizations build and deploy more agents, it requires more scalable monitoring of the entire application stack at a lower cost. And the speed and scale of AI deployments is requiring more automation for SRE teams to streamline the process of detecting, investigating and remediating issues. We are pushing the frontier in these areas through targeted investments. This quarter, we relaunched our metrics offering. We released column Nour mode in Elastic Search 9.5, now in technical preview.
Column nor mode is an entirely new index mode, purpose-built for time series data. It delivers extremely efficient compression, storage and querying of time series in a columnar data structure, pushing storage costs down 20% to approximately 3 bites per metric sample while still using the same ESQL query language. With these innovations, we are now an optimized engine for multiple types of data, including documents, vectors, logs, metrics and more. Column nor mode makes the Elastic platform a highly competitive solution for metrics and infrastructure monitoring, an area where we historically have not had a major presence.
Additionally, we now support native Prometeus ingestion with PROMQL support, simplifying the migration from Prometius into Elastic. No new tooling or retraining is needed. We are giving teams full visibility across metrics, logs and traces at 1 unified platform, all at a very compelling price compared to incumbent competitors. We also acquired deductive AI, a leader in the emerging space of AIR Deductive has built a reinforcement learning or RL harness that automates the task of complex investigations. It bears upstream data like code repositories and elastic alerts with downstream signals from Snack, PagerDuty and ServiceNow to dynamically construct decision trees as it learns from past and ongoing investigations.
It then uses these to drive automated investigations for new incidents based on past learnings. This allows SRE teams to significantly reduce the time to investigate and remediate problems to achieve the goal of an AI-led Sari organization. By integrating deductive reasoning capabilities into our ObserveIT platform, we are building a true agenticasari, 1 that can autonomously detect, investigate and guide remediation across the full signal stack.
This quarter, Gartner recognized Elastic as a leader for the third consecutive year in the Gartner Magic Quadrant for Absobility platforms, reflecting the strength of where we already stand. Illustrating the power of this unified platform approach, a leading global insurance company added elastic observity to its existing security deployment in a 7-figure expansion win. The customer had been running a fragmented environment with application logs in Elastic and metrics and traces in another incumbent solution, preventing effective root cause analysis across tens of thousands of annual incidents half attributable to application issues.
The deciding factor was Elastic's newly released native Prometheus ingestion and from QL support, which met their heavily metrics-driven environment where it was. And combined with our migration tooling, enabled full consolidation onto a single open telemetry first platform without any costly rip and replace. Looking ahead, the ability to apply elastic AI agents across all signal types to intelligently identify root cause was a key driver of the expansion.
In a post metros world, organizations are facing an increasingly challenging landscape, where vulnerabilities are being discovered at an alarming rate and weaponized at machine speed. This requires cyber defenders to detect, investigate and mitigate at speeds well beyond human capacity alone. To bridge this gap, AI-driven automation has become an absolute necessity for cyber defenders Accordingly, we have invested in several areas to help our customers achieve their end goal of an AI-driven song.
Attack discovery reached a new milestone this quarter. It now investigates and validates threats autonomously allowing SOC teams to move at machine speed. Attack discovery turns a wall of alerts into a prioritized list of real attacks and moving security teams closer to Alert Zero. Alert Zero is the SOX version of inbox, a Q worked down to the attacks that actually matter with agents and analysts operating together. This quarter, we were named a leader in the IDC Marketscape for worldwide SIM and a strong performer in the Forrester Wave for extended detection and response. Forrester specifically recognized that Elastic's strategy envisions an open agenetic stock that will automate operations.
Elastic XDR integrates seamlessly with our SIM and attack discovery capabilities, enabling protection and remediation unaffected systems to counter AI scale threats. And on endpoint protection, Elastic Security is the only vendor to achieve 14 consecutive months of 100% detection rates in AV comparatives independent testing. Our strength in security is also allowing us to rapidly grow our footprint in the U.S. public sector through the CISA SIM as a service offering. This relationship continues to serve as a powerful channel across the U.S. government opening new opportunities.
A large U.S. public sector agency shows elastic security and observability to begin unifying its fragmented data estate onto a single platform, replacing disparate SIM data. Elastic newly achieved FedRAMP high authorization, unlocked the opportunity and our ability to monitor both on-premises and multi-cloud environments from 1 managed deployment made us the strongest candidate. Where the agency's previous vendor had stalled on innovation, elastic space of Development and LLM agnostic AI integration gave them a clear path forward for modern threat detection and response.
Our efficiency and AI features were key drivers of this win. What is exciting about this customer is that we were able to migrate their very complex data platform from their incumbent solution onto Elastic in under 1 month taking advantage of all of the automated migration tooling that we have built for this purpose. We see the same momentum in the private sector. A global semiconductor manufacturer chose Elastic Security Services as its security analytics platform to protect against insider that and secure its intellectual property using our AI capabilities. The customer intends to move hundreds of dashboards from an incumbent solution into Elastic to leverage our natural language search and analytics capabilities.
Now moving away from manual workflows, the customer is adopting our agent capabilities across their full data estate. When competitors offered AI as an add-on, Elastic's fully integrated platform gave the customer exactly what they needed, 1 product built for the age of AI. All of these innovations, combined with the consistent sales execution are driving rapid growth in AI usage within our customer base. Over 37% in of our 100,000-plus ACV customers are now using Elastic for AI, up from approximately 21% a year ago. That is more than 670 high-value customers now using Elastic for AI use cases with 70 net additions quarter-over-quarter in Q1.
Our ability to deliver all of this with an open platform across both cloud and self-managed deployments is proving to be an enduring advantage as AI adoption grows across natives, enterprises, regulated industries and government agencies around the world. This includes our support for both proprietary models and open models like GLM from Z AI, our adherence to standards like open telemetry, our ability to support sovereign deployments through our self-managed offering and our partnerships with NVIDIA and Dell around their AI factory and with Google distributed cloud.
We entered this fiscal year with 7 successive quarters of strong sales execution and continuing momentum for our platform. Our pace of growth in search and AI and security has continued. And with our most recent innovations in the areas of metrics and AIS, we are excited about the prospects of our absorbability business. As AR adoption grows across the enterprise, we expect to continue driving acceleration of our business toward our midterm revenue and profitability targets. I also want to take a moment to recognize a board transition. I want to thank Karen Moroney, who will be stepping off our Board after a long tenure.
We are grateful for her partnership and she will continue to be a friend to Elastic. I am pleased to announce that Julia Lusin has been nominated to join our Board. Julia has seen Elastic Grow as a leader in the areas of search, AI, absorbability and security. In her prior role as President of developer tools at Microsoft. She brings a unique perspective around AI and at scale infrastructure development that will be invaluable as we continue to execute on our strategy.
I want to thank our customers and partners for their trust, our shareholders for their continued partnership and our employees for their focus and execution. With that, I will turn the call over to Nava.
Thank you, Ash. On our last earnings call in May, we expressed confidence that our commitments we secured in fiscal '26, combined with our continued sales execution, will drive revenue acceleration over the course of fiscal '27 on a constant currency basis. While it's still early in the fiscal year, our Q1 results put us on track to achieve this goal. Our total revenue in the first quarter was $478 million. We grew approximately 15% as reported and on a constant currency basis. On a constant currency basis, Q1 growth accelerated quarter-over-quarter, up from 14% in Q4. Sales with subscription revenue in the first quarter was $399 million. We grew 18% as reported and 17% on a constant currency basis.
Similar to total revenue, sales-led subscription revenue accelerated quarter-over-quarter in constant currency, up from 16% in Q4. Our CRPO in the first quarter was $1.2 billion, representing 21% growth as reported and 20% on a constant currency basis. Our constant currency CRPO growth sustained 20% growth for the second consecutive quarter. Our RPO for the first quarter was $1.9 billion, representing 27% growth, both as reported and on a constant currency basis.
As Ash mentioned, the continued strength in RPO reflects customers deepening their long-term commitments to Elastic as a core part of their AI infrastructure. Our Q1 revenue acceleration on a constant currency basis, both for total and for sales-led subscription revenue as well as our second straight quarter of 20% constant currency CRPO growth provides validation for our acceleration trajectory. 3 core dynamics are powering our fiscal 2017 sales-led subscription revenue growth.
First, our strategic investments in sales capacity over the past year are driving the pipeline improvements we expected. Building on 7 quarters of go-to-market improvement, we continue to see year-over-year gains in both ramp sales head count and productivity this quarter. Additionally, the strength in our second quarter pipeline and buildup of out quarter pipeline reinforce our confidence in securing new and expanded commitments as well as achieving our planned renewals. Second, as we discussed last quarter, a portion of our fiscal '27 revenue is made up of commitments from fiscal '26.
Now being consumed and converted into revenue. We are pleased with the healthy consumption activity we saw this quarter. The net expansion rate or NER remained strong, though it moved from 112% to 111% this quarter. As a reminder, our NER is a 4-quarter trailing metric impacted by historical growth. The NER we reported in Q1 reflects the lower constant currency growth rate in the trailing 4 quarters as compared to the 4 quarters preceding. We expect NER to improve within 4 quarters as constant currency revenue acceleration builds through fiscal '27.
Third, we saw continued improvements in our new and expansion commitments as seen in our greater than $100,000 customer count, that segment now contributing 90% of sales-led subscription revenue, up from 87% a year ago. This quarter, we added more than 80 net new customers to this tier, our largest increase to date. This reflects the effectiveness of our sales team in both winning new logos and expanding within our existing base.
Now turning to Q1 margins and profitability. I will discuss all measures on a non-GAAP basis. We delivered subscription gross margins of 81%, total gross margins of 77% and an operating margin of 16.2%, exceeding our guidance from last quarter. The improvement in margins reflect the operating leverage in our model as revenue scales. We achieved an adjusted free cash flow margin of 30% despite onetime charges related to organizational changes we announced in June. These amounted to $13 million of cash paid for restructuring and other charges. As a reminder, adjusted free cash flow fluctuates quarter-to-quarter due to booking seasonality, and we manage free cash flow on a full year basis.
During the first quarter, we returned approximately $40 million to shareholders, representing purchases of approximately 800,000 shares. Since the $500 million share repurchase program launched in October 2025, we used $380 million and repurchased 5.2 million shares cumulatively as of the end of last quarter.
Now turning to our outlook for the second quarter and for the fiscal 2027. Building from the momentum we experienced in Q1, we are raising our previous guidance for the full year. For the second quarter of fiscal '27, we expect total revenue in the range of $486 million to $487 million representing 14.9% growth at the midpoint or 15% constant currency growth at the midpoint. We expect sales-led subscription revenue in the range of $407.5 million to $408.5 million representing 16.9% growth at the midpoint or 17.1% in constant currency growth at the midpoint.
We expect non-GAAP operating margin for the second quarter to be approximately 19%. We expect non-GAAP diluted earnings per share in the range of $0.80 to $0.82, using between $108 million and $109 million diluted weighted average ordinary shares outstanding. For fiscal '27, given our strong Q1 results, we are raising our outlook for the year. We expect total revenue in the range of $1.998 billion to $2.010 billion, representing approximately 15.2% growth at the midpoint or 15.3% constant currency growth at the midpoint.
We expect sales-led subscription revenue in the range of $1.682 billion to $1.694 billion representing 17.4% growth at the midpoint or 17.5% in constant currency growth at the midpoint. We expect non-GAAP operating margin to be approximately 19.4%. We expect non-GAAP diluted earnings per share in the range of $3.29 to $3.37, using between $108.5 million and $109.5 million diluted weighted average ordinary shares outstanding.
We continue to expect our fiscal 2027 adjusted free cash flow margin to be 21.5%. We are growing revenue efficiently while maintaining disciplined investments and are making progress towards rural [indiscernible]
Before I close, a few more financial items worth highlighting related to this year. We incurred approximately $20 million of restructuring-related charges during the first quarter, and we expect to incur an additional $2 million to $5 million of restructuring charges for the remainder of the fiscal year. We expect our GAAP operating margin to be positive in the second quarter and for the full year. We also expect to maintain GAAP operating margin profitability going forward. And last, as we said last quarter, we expect total revenue and sales-led subscription revenue growth to accelerate in the second half with Q4 having the highest year-over-year growth for the year.
To summarize, we are executing well across our fiscal year priorities and are firmly on track to meet our medium-term financial targets of both accelerating our sales-led subscription revenue growth to 20% plus and improving our rule of 40 as measured as a sum of revenue growth and adjusted free cash flow. The sustained progress we see in CRPO, sales productivity pipeline and operating leverage reinforce our confidence in our revenue growth and margin expansion plans.
Elastic continues to be the essential platform for enterprises looking to derive value from their data, and we look forward to the opportunities ahead. Thank you for your continued support thanks for joining us today. With that, I'll open it up for Q&A.
[Operator Instructions] Our first question today comes from Matt Hedberg with RBC Capital Markets.
2. Question Answer
First of all, congrats on the quarter. The acceleration especially after a 4Q was impressive. ASH, there's a lot of things that stood out to me the strength in 100,000 customers. I think you said the largest sequential add you've ever seen was impressive I guess, you talked about a lot of things on the call about execution and product traction and just better sales capacity. But I'm wondering if you can put a finer point on the success there. Why now? And just kind of the sustainability of that large customer growth would be great.
Matt, thank you very much for the question. And like you said, it was a great quarter in terms of the net adds. We added 80 customers to that cohort, the highest ever number of additions that we've had. Fundamentally, the way I think about it is that our new and expand motion, especially in our enterprise and mid-market high-propensity customers is working really well.
If you remember, about 2 years ago, a little over 2 years ago, we made a change to the way we did segmentation within the organization, within the sales organization. And since then, you have seen us continue to improve in this area. And what you're seeing is customers are making bigger commitments customers are making longer-term commitments. And that's resulting in this cohort really growing very nicely. By the way, this 100-gig cohort now represents 90% of our sales-led subscription revenue.
So it just gives you a sense both of how important this cohort is, but also how well they are doing. And the thing that excites me the most is the AI penetration in this cohort. So 37% of this 100,000 cohort is now using our AI features. That number was about 21% in the past. And like we explained even at our Financial Analyst Day, the more this high-value customer cohort uses our AI capabilities, the more they use more and more solutions within our platform, that really becomes the enduring growth driver for us. So very excited about it, and it just shows that the go-to-market motion is working and the platform strength and differentiation is holding very well.
Well, if I could, as a follow-up, the 37% of those customers using the , it was another thing that stood out to me. Is there any way to think about what that means from an NRR perspective? I have to imagine it's obviously additive and maybe it's part of the NRR reacceleration. But just any way to think about what that means from like a customer ACV or NRR perspective? .
That question. So net the NRR is obviously a strong metric across the board for all our 100,000 customers. But when you think about the cohort of customers that are that are using AI, the dynamics that we talked about during the financial Analyst Day still stand, which is they have a higher growth propensity compared to customers not using AI, so that dynamic exists today among that AI cohort group the same way it existed when we talked about in the Financial Analyst Day.
The next question comes from Tyler Radke with Citi.
Sorry about that. I was on mute there. Can you just talk a little bit, obviously, really strong cloud performance. And I know you alluded to the strength in the cloud bookings last quarter. But any one-off dynamics we should be mindful of? And can you just comment on sort of the bookings mix this quarter, how that cloud sort of looked relative to historicals? And just any color on how we should be thinking about the growth of cloud from here? .
Yes. Thanks, Tyler. It's Nava here. So look, we're very pleased with the way cloud has been performing in the quarter, both in terms of the commitment volume. And also, more importantly, the consumption against the annual commitments we have, the aggregate annual commitments we have. And as a reminder, cloud is not a guided metric and there's always going to be quarter-over-quarter variability because it's consumption. But our annual cloud growth improved to 27% this quarter, up from 26% last quarter. On the monthly cloud side, that number, we expected it to remain flat and it remained roughly flat for the quarter.
So the dynamics are roughly the same in terms of the growth on the sales-led cloud side and the SMB smaller customers remaining flat. At the end of the day, though, we win because we have flexibility in our deployment model, right? And we meet the customers where they are and where they want to deploy our software, and we are 1 of the very few players that can actually do that. And that's the reason we continue to focus on sales led subscription revenue.
In terms of bookings dynamics, we expect to, like I said, meet customers where they are. There isn't much to call out this quarter in terms of one-offs. We talked about the mix in Q4 being a good cloud quarter. Q1 remained a solid quarter with no unusual activity 1 way or the other.
And by the way, Tyler, just to put a finer point on what Navan said. The fact that we can deliver all the capabilities that we provide through the platform, whether it's for AI, whether it's for security, whether it's for observability in environments ranging from commercial cloud to people running it in their own data centers to air gap environments, we have -- we mentioned last quarter that Google Distributed Cloud has OEMed our capability as well. So that flexibility, that range is a significant enduring moat. Because if you think about the markets that we play in, there are very few vendors that have that ability to deliver across all of those form factors, and that is a big advantage for us. And that's the reason why now I'm said, sales-led subscription revenue is a very important metric. And by the way, cloud self-managed, all of those are things that we look at, and we are very happy about the performance overall.
Great. And Ash, maybe just get a follow-up for you. Obviously, some pretty remarkable events going on in security as it relates to some of the new attack vectors and agents going rogue. Like can you just talk to us about the Elastic Security business, how do you see it participating in some of these new Agentic security fronts?
Yes. Our security business is something that we are very, very excited about. Even in my prepared remarks, Tyler, I talked about several customers, right, that are using us in security. I talked about the semiconductor company. I talked about the government did the very large government agency. We've talked to you in the past about a SIM as a service. I just mentioned Google disconnected Cloud. All of these are already driving our SIM business and our XDR business.
And what's great about this is we are able to help our customers because it's never been harder to be a CISO. Threats are -- vulnerabilities are being discovered faster. Threats are being activated faster. So sort of working at human speed is just not sufficient. You have to figure out how to use AI on the Defender side, to be able to detect, investigate and remediate machine speed and you know how early we invested in sort of the AI-led capabilities like attack discovery and so on. And all of that, the maturity, the continuous innovation that we are driving there we are already seeing all of this turn into strong commitments, and you're seeing now the consumption against those commitments. So I expect the momentum to continue for us in security.
The next question is from Miller Jump with Truth Securities.
And congrats on the strong results here. You mentioned customers choosing you for flexibility and highlighted some of the enhancements to Gena on-prem capabilities this quarter. I'm wondering if you can give any more color on how you're seeing the distribution of customer AI deployments developing specifically across cloud, on-prem and hybrid and if there's any difference versus your other use cases?
Yes. It's -- so what we are seeing is that there is still the majority of customer deployments tend to be first and foremost in cloud, that's where they typically start because that's the fastest way for customers to get started but enterprise customers and government agencies. And I say enterprise customers I'm specifically referring to customers in regulated industries, whether it's banking, whether it's telco, especially in international markets for us outside of the Americas, what we are seeing there is a greater desire to not just have data sovereignty but also to have operational sovereignty.
And in those environments, they want solutions where they can run these capabilities within their own enclaves, within their own control. And again, like that's where we have such a great strength because there aren't too many companies that are able to provide that kind of functionality. And in the past, our genome models, you had availability of those of the commercial genome models through our inference service, which was cloud only, but there was no way if you're an air gap customer or a customer running things within your own enclave to take advantage of the genome models, we didn't have a pricing model in place for sort of the commercial capabilities there. So that's what we launched.
And there's a lot of interest. We launched it because we're seeing a lot of interest. So going forward, what I would expect is AI deployments are going to be based on factors like the criticality of the data, the sensitivity of the data, the kind of customer in their geo location, so those will be bigger factors, but you're going to see AR adoption both in cloud and in self-managed?
Really exciting. If I could just squeeze in a follow-up for Nova. You all highlighted the strength in the SSA deal but just given that we're coming off on the anniversary, I'm wondering if you can give any more color on how the Fed vertical is being treated in the Q2 guide and if there's any headwinds or tailwinds we should consider this year?
Nothing specific at this point in terms of guidance for the Fed vertical Miller the global public sector remains an important sector for us. When we think about our guidance, we obviously look at a prudent risk-adjusted view as to forward numbers. Very pleased with how the CSA contract is performing and the continued activity there. So we expect that to continue to gain momentum as more agencies come on board. But nothing specific to call out in terms of a big tailwind coming in or a big headwind coming in from the Federal segment. .
The next question is from Brian Essex with JPMorgan.
And congrats from me as well on the results. It's great to see that acceleration. Maybe ask for me, I'd love to get your view on how you see your customers deploying AI and coding around AI, specifically around leveraging your platform to build their own harness in context windows to get more control around the ability to protect that context and proprietary data as opposed to using OEM harnesses and coding platforms? And how that -- how you're positioned for or your view on how that portion of the market is going to evolve over the next few years?
Yes. And yes, the first thing to appreciate is, at the end of the day, when you're building any kind of a genetic solution the most important element in that is going to always be the large language model, the model that does reasoning, that does inferencing and so on and so forth. But that model, unless what the agent that you're trying to build only depends on external data only depends on like publicly available information, is going to need to somehow be coupled with your proprietary information.
Now if you think about any enterprise, you think about any large agency, the biggest challenge is, now you're talking about many, many perabytes, if not exabytes of information, information that's constantly being created, information that's constantly changing and so this really ends up being a situation where you have to bring the model to the data. The data is just too much to take to the model. And more importantly, that data is your secret sauce. So you never want to have it completely exit your organization anyways.
And so that's really why as you think about what people are building with harnesses and so on, the most important element in that is sort of the data retrieval or the context layer and when you are trying to get that context for your LLM, for your agent, you have to worry about accuracy. You have to worry about speed and you have to worry about cost. And what that means is you really want to try and precompute as much of that context ahead of time as possible so your model isn't just constantly trying to sift through all of the data every single time, which is a very expensive, very inefficient, very slow approach.
And that's what we do. That's where we fit in. That's the reason why customers turn to us because we're able to make their agents perform better. We are able to make their agents more secure in how they operate. We are able to provide just the right context to their agents, and we are able to reduce cost and give them that balance of both using proprietary models where it makes sense using open models where that's the best approach so that flexibility, that deployment choice, all of this is how people are using us today. And that's why we believe that this is something that's an enduring motion for us. It's an enduring area for us to grow on.
Got it. Maybe that's super helpful color. And maybe just for a follow-up. Security as a percentage of total revenue and in a post Mythos world, how do we think about contribution from that business relative to the rest of the Elastic platform? .
As a percentage of revenue, we don't disclose that, Brian. But in terms of growth, security remains a very strong growth vector for us. And we've highlighted this in the press earnings call as well as to the contracts and the customers that we have on the security side. So very pleased with how that's performing, and it remains to be a high-performing, high-growth segment for us.
Even this quarter, if I may just add to what Noam said, we had -- security was -- grew incredibly well. The order roughly was security, AI, search, AI and then observability and with observity with what we're doing around metrics, the deductive acquisition, like that's the third pillar of the stool, if you will. That's what gives us a lot of optimism in the future. So really, like we feel really good about the way our platform story is evolving here. .
The next question is from Rob Owens with Piper Sandler.
Thanks for the question, Alex. In your prepared remarks early on, you talked about success in the quarter. You talked about search and AI and security. And I know you've got new capabilities in observability, Ash, and you just mentioned some them, but maybe you can drill down relative to the metrics opportunities, some of the new pricing dynamics that you offer and just what customer feedback or acceptance has been at this point?
Yes. Thanks for the question. And Rob, the way we have built our absorbability business over the years is starting with logs. As you know, log analytics was where we started because the messier the logs, the more capable our solution has been in giving you the ability to do full tech search through those logs, to do analytics on those logs. And so our strength in log analytics continues. It's in a huge area for us.
And over the years, we've continually made our platform more efficient for log analytics, which is another reason why we continue to do well in that area. But sort of expanding from there has been an area where, as we've looked at the market, what we realized was metrics because of AI and what's been going on in terms of people building these agents, that's an area where we didn't have that same kind of strength. We didn't have that same kind of performance.
And so about 1.5 years ago or so, we started working on a completely novel back-end to Elastic Search that allowed us to have not just the regular document store model that we had in Elastic search but also a column or store back end and all accessible through the same API because again, we want to make it easy for people to adopt this column in our back end. And this column or back end has been really tuned for basically all kinds of time series data. So metrics and even simple logs, and this column or approach makes it possible for us to store the data in a much more efficient way. So the storage efficiency is massively higher.
The ingest performance is better. The query performance is better. So we get a ton of benefits and it's going to show up most in metrics. And in the past, it used to take us double-digit bites to store metrics. We are now able to store a single metric in around 3 bites, which is a huge difference. And now we are incredibly competitive in the market. This is going to allow us to really take on this area head on. And we are early, like I have to say, but the early feedback that we've gotten from customers because we are going to our existing log analytics customers and upselling there, has been very good. So we are excited about the feedback that we are getting. But the way I see it is if we do this right over the next year, multiple years, this is going to be a pretty significant and meaningful area of growth for us.
Great. And speaking of early, you mentioned a number of autonomous innovations this quarter across both security and observability. So curious, just early feedback from customers. Obviously, the security landscape is changing rapidly. So for those on the bleeding edge, how are they consuming what does overall consumption look like? Or what's that relative state of change for those that are moving to some of these autonomous capabilities?
Our AI SoC capabilities on the security end have been a big reason for our success in security. So you've been seeing us do very well in security for the last many quarters. And I attribute a lot of that to the investments that we made and the differentiation that we have in our agentic capabilities when it comes to security. And the biggest differentiation that I still hear from our customers is not only do we have a very, very complete set of capabilities out of the box. But unlike others who have a black box approach to AI we have more of an approach where we allow you to see what's under the covers. You can see the skills. You can see the tools inside the harness inside the security harness that we built.
So you can complement it, you can enhance it, you can do more with it. That is a big differentiator because at the end of the day, we believe that models are going to keep getting better and for different tasks, some tasks, you're going to prefer to use cloud, others you're going to prefer to use Gemini for something else you might use an open source model. Also skills will continue to evolve. Harnesses will continue to get better and we believe that giving that openness and choice to our customers will be an enduring differentiator. And that's what we are seeing so far.
And just as a reminder about our metrics webinar on September 22, that information is going to be posted on the IR website. And with that, let's go to the next question.
The next question is from Raimo Lenschow with Barclays.
Congrats from me as well, a great quarter. A couple of weeks ago, you launched Kubernetes capability on the observability side. Can you speak to the importance of that because that seems to be closing a really important gap in the offering and maybe just speak to what's possible now?
Yes. A lot of it has to do, Raimo, with our focus on having a great end-to-end experience and the areas that we want to make sure customers adopt us increasingly for is using us for metrics, using us for infrastructure monitoring, and as you know, a lot of agents are being deployed on Kubernetes, environments and getting that right with a great end-to-end experience with dashboards that light up out of the box with sort of native sport, not just for open telemetry-based ingestion and analytics but also support for PROMETHEUS data and PROMQL, like these are areas where we've invested a lot.
Even in the prepared remarks, the customer that I talked about that chose us for metrics, that customer moved to us because we made it so easy for them to bring their PROMETHEUS data directly into Elastic without having to transform things without having to change things. And that's a big differentiator. So you're absolutely right to look at that and see that, that is a key element. It is 1 of many investments that we've been making on the observability side. And that's what is quite -- we find that to be quite exciting for the days ahead.
Perfect. Yes. No, thank you. Yes, same view here. And another 1 for you, like it's like you only had your Q1, but you raised the full year by more than the beat in Q1 nowadays and software, everyone is very conservative, et cetera. What gives you the confidence there? What are you seeing in terms of pipeline, et cetera? .
Yes. Thanks, Raimo. I don't think the guidance philosophy has changed much compared to what we've done in the past. We've always taken a prudent and risk-adjusted view to guidance. But like you said, it is only Q1, but it was a good start to fiscal '27. And we got some strong data points from that quarter. Our CRPO, obviously, which was a good number in the RPO number as well as the $100,000 adds. Apart from that, there were 3 specific drivers that we saw internally as well.
First is the strong pipeline build, both for the second quarter and the full year, the out quarter pipeline build is looking good. Second is the consumption against the CRPO committed CRPO number performed well. And then third, we expected a certain productivity and capacity increase given the hiring that we did, and we we're seeing that, and that's allowing us to have the confidence on the go-get number that we need to do for the net new revenue side for the rest of the year.
So that's the reason we guided the way we did and we're encouraged about the revenue trajectory for the year. So it hasn't changed -- the philosophy hasn't changed, but we feel good about what we need to go achieve for the rest of the year.
Next question is from Howard Ma with Guggenheim.
I want to add my congratulations, too, on a strong quarter. My question is, is the acceleration that you're seeing, would you say that that's directly attributable to higher multiproduct adoption driven by the realization that Elastic is an attractive solution for both content engineering and managing the anti-driven proliferation in telemetry data as opposed to point solutions. And does your guidance factor in material acceleration in cross-sell among various use cases?
Yes. Maybe let me touch upon that and then Nova might -- let Navan talk about all things related to guidance but -- just if you think about our motion, it's always how it's been very similar, right? So we have a platform that allows customers to do multiple things. And what we focus on is making sure that our platform is incredibly good in each of those areas. So each of our solutions, our focus is on making sure that those solutions are able to be differentiated and stand on their own and win on their own. .
And that becomes the tip of the spear for us. It's our land and then expand strategy because once we land with 1 solution, then the goal becomes, how do we get the other solution in there and the third solution in there and obviously, like we had talked even at our Analyst Day or last Analyst Day, the customers that grow the fastest are the ones that adopt us for all 3 solutions. So that land and expand motion has continued, and it's not that necessarily that has inflected in any way. But this is what you're seeing here is just the right kind of progression.
This is a motion that we've been driving -- probably the biggest thing that has happened is as our focus on our enterprise selling motion, the segmentation change that we did 2 years ago, as that has matured, we are seeing the benefits of that play out very, very nicely. So our land and expand is working in all 3 solution areas we are seeing the right kind of movement. And look, it comes down to making sure that you are positioning your platform, your product in the right way. And then our sales teams know how to position the multiple platform -- the multiple product strategy within that platform. And that's why we feel so good about what this is going to mean for the future.
In terms of the guidance, Howard, there's nothing different implied in how our land expand motion works. Obviously, there's a lot of -- a lot of our revenue comes from expand more than land. Land is the entry point and then expansion is where the dollars come in over time. And that dynamic comes from both expansion of the existing product that you bought and also cross-sell. So there isn't anything in the guidance that we've taken into account a different behavior from our customers from what we currently see. .
[Operator Instructions] The next question is from Rod Soltan with UBS.
Ash, in your prepared remarks, you called out a SIM migration, which I believe you said got done under a month with some of your automated migration tooling. I just wanted to ask, how much of a benefit are you seeing to cloud consumption from AI accelerating migrations on the SIM side, but also maybe just more broadly?
Yes. So the consumption that we saw was -- the strength in consumption that we saw this quarter was broad-based. It was not related to any 1 customer. But what I talked about there, which is really important to understand is, at the end of the day, SIM has never been sort of greenfield, right? SIM as a space has been around for a long time. And our motion has been to displace the incumbents who are not innovating at the same rate. What's really changing there, to be honest, is the environment, people are really worried about what it means to protect your environment, protect your agencies and so on in a post metas world.
And it's not just metros. There are so many very, very capable models out there, not just commercial models, but open source models that give you the ability to really discover vulnerabilities and then act upon them. So you have to assume that people who are trying to do harm now have the ability to access these models. So defenders are having to move faster and so on. So that is driving the momentum for our business and the ability with our tooling with our automated tooling to migrate these customers from their incumbent solution to our product, our platform, we have gotten really, really good at it.
This was a very significant sized agency, and we were able to move their massive real estate over in 1 month -- in under 1 month. And that is just the thing that gives our field a lot of confidence. It is what gives our customers a lot of confidence because as they see these things happening over and over again, it gives them confidence that they can safely move to Elastic and that we will be able to make them successful quickly.
The next question is from Shrenik Gutari with Robert Baird.
All right. I think we need to go to the next question.
The next question is from Mike Cikos with Needham.
This is Matt Glitre on for Mike Cikos over at Needham. And you gave some great color on that 100,000 cohort and some of the AI adoption, which we appreciate. Are there any other clear underlying expansion trends you can share regarding older cohorts versus newer ones or smaller customers versus larger ones? Or is it more so just expansion across the board and you're waiting for that trailing 12 months net expansion number to catch up, as you mentioned in the prepared remarks?
Yes. Thanks, Matt. So the trailing 12-month number on the ER, the NER side is impacted by the trailing 12-month constant currency growth. So that's a separate factor. And as constant currency growth improves alongside guidance that we've provided, it's going to take a lagged effect for the NER to catch up. So that's the comment on the NER side that I was making. But on the cohort behavior, the cohort behavior that we talk about is basically a durable land-expand motion, so we get our customers in. And there is a long period of durable expansion that we expect from every 1 of those cohorts and that's continuing.
And we also expect to see and we see the AI cohort show a differential in our growth, meaning the customers who are using our AI features effectively expanding at a slightly higher rate than the ones that aren't. So those are the 2 dynamics that we see in our expansion rates and those trends are continuing. And as I mentioned, NERs, which is trailing picks up alongside the revenue growth rate that we expect to post for the year.
The next question is from Sanjit Singh with Morgan Stanley.
Ash, I see a lot of the passion on the SIM side and obviously throughout the other core parts of the business as well. I wanted to come back to the AI search part of the business. We have a lot of data platform players trying to solve that context, Symantec problem. I think Peppard it in a proprietary way. So from the elastic perspective, in terms of getting that agent performance and building that map for that agent. Why is Elastic able to do that better than some of the other data platform peers that are trying to solve that similar problem?
At the simple answer, Sanjeet, is because we've always been optimized for dealing with messy data, for dealing with unstructured data. Most of the data platforms that you're talking about that you might be thinking about were all designed to work with structured information. And fundamentally, although they might have had a sort of no SQL view of the world, it was still sort of designed with strict schemes structure in mind. Elastic has always been different in that sense.
If you think about Elastic, we started as a document store with an inverted index that allows you to put any and all kind of information in it, which is why we were always used for search, which is why we then moved into log analytics because all of these things end up being very unstructured. The schema keeps evolving. And if you think about the kind of information that is being used primarily, a lot of it in AI is this kind of unstructured data. So our strength in terms of being able to bring in this data, being able to then analyze it, search across it the capabilities that we've built, not just with vector search but also around hybrid search, the harnesses that we've built on top of it, all of this Vigia models, our ability to do reranking and so on.
We are way ahead of the competition, especially when you look at things from this unstructured lens. And frankly, Sanjay, we feel that we are still very early in this overall phase of AI adoption. Most organizations are only now starting to really deploy things in a meaningful way. So as that grows, as we have more penetration within our customer base, I think that's going to be what really helps us continue this momentum for a very long time.
The next question is from Ryan MacWilliams with Wells Fargo.
One for Nava. How should we think about the gross margins in the quarter? It looks like they were just slightly lower versus previous quarter. I mean perhaps some impact from the mix shift from cloud here. But anything else worth calling out? And maybe how should we think about gross margins for the rest of the year?
Yes. Look, we're very pleased with how our subscription gross margins are performing. It's remained above 80%. And really, there's nothing specific in terms of a trend that emerged this quarter. But over the longer term, what we expect is that these gross margins are expected to improve as we see benefits from things like serverless as it gets to scale, so there's going to be fluctuations quarter-over-quarter, but nothing specific this quarter from a trend perspective on margins. .
This concludes our question-and-answer session. I would like to turn the conference back over to Asco Harney for any closing remarks.
Thank you very much for joining our call today. We are pleased to report a strong start to the year. We are extremely proud of our results and very excited about the opportunity ahead. Lastly, please join us on September 22 for our public webinar on metrics. Have a great day. .
The conference has now concluded. Thank you for attending today's presentation. You may now disconnect.
Elastic NV — Q1 2027 Earnings Call
Elastic NV — Q1 2027 Earnings Call
Strong Q1 FY27: revenue up 15%, sales‑led subscription growth accelerating, AI and observability investments driving wins and raised full‑year guidance.
📊 Quarter at a Glance
- Revenue: $478M (+15% YoY)
- Sales‑led rev: $399M (+18% YoY; sales‑led subscription revenue)
- Op margin: Non‑GAAP operating margin 16.2% (beats prior guide)
- CRPO: $1.2B (+21% YoY) (Committed Remaining Performance Obligation: future contracted revenue)
- RPO: $1.9B (+27% YoY) (Remaining Performance Obligation)
🎯 What Management Says
- AI/context layer: Elastic positions Elasticsearch as the retrieval/context store for agentic AI—supporting text, vectors, images, audio and hybrid search to improve accuracy and lower cost.
- Product moves: Released Vector DB index mode with auto‑calibration, Gena models for on‑prem/air‑gapped use, Agent Builder enhancements (observability and human‑in‑loop controls).
- Observability & metrics: Launched a columnar index mode (columnar time‑series storage) and native Prometheus ingestion to target metrics/infra monitoring; acquired Deductive AI for automated incident investigations.
🔭 Outlook & Guidance
- Q2 guide: Revenue $486–487M (≈15% YoY midpoint); sales‑led $407.5–408.5M; non‑GAAP op margin ≈19%; EPS $0.80–0.82.
- FY27 guide: Revenue $1.998–2.010B (≈15.3% constant‑currency midpoint); sales‑led $1.682–1.694B; non‑GAAP op margin ≈19.4%; EPS $3.29–3.37; adjusted FCF margin ~21.5%.
- Risks/one‑offs: $20M restructuring charges in Q1 with $2–5M expected remainder; cloud consumption can fluctuate (cloud not a guided metric); GAAP operating margin expected positive Q2 and FY.
❓ Analyst Q&A
- 100K+ cohort: Added 80 customers spending ≥$100K ACV (largest sequential add); cohort now ~90% of sales‑led revenue and 37% using AI (higher expansion propensity).
- Cloud mix: Annual cloud growth ~27%; cloud consumption variable quarter‑to‑quarter and not explicitly guided—management emphasizes deployment flexibility (cloud, self‑managed, air‑gapped).
- Security & metrics: Security momentum highlighted (attack discovery, XDR, Fed wins); management declined to disclose security % of revenue but called it a high‑growth vector. Early customer feedback on columnar metrics and Prometheus ingestion is positive.
⚡ Bottom Line
Elastic delivered an accelerating start to FY27, beat guidance across key metrics and raised its full‑year targets. Investments in retrieval for AI, vector/search tooling, metrics (columnar) and autonomous security are translating into large account wins and higher contracted backlog, though cloud consumption variability and modest restructuring costs are near‑term factors to watch.
Elastic NV — Rosenblatt 6th Annual Age of AI Technology Summit
1. Question Answer
Good afternoon, everyone. It's Blair Abernethy, software analyst with Rosenblatt. Thanks for joining us. Today, we're happy to have Eric Prengel with us, who's the Global Vice President, Finance for Elastic. And we're going to spend the next 45 minutes walking through Elastic's current business and how they're positioning themselves for this AI -- rapidly changing AI features that we have entered into in the last couple of years. Welcome, Eric.
Thanks for having me, Blair. Really appreciate you having me and everybody who's joining. Looking forward to the conversation.
Yes. So listen, maybe before I ask the first question, I just want to suggest to anyone who might have a question for me to -- actually, if you could just e-mail it to me at [email protected], and I will pull up and filter that into our conversation that would be appreciated.
So Eric, why don't we just start with -- at a high level, some context for people that may not have looked at Elastic in the recent, recent past, just give an overview of sort of where the business is at today, the market or the problems that you guys are addressing and then a little bit about your background as well.
Yes. So why don't I start with the business, and I'll end with my background. And if I forget to anything, just double-click on anything, please ask me. So Elastic is the world's leading data platform, which is specifically designed to index, store and analyze massive volumes of messy unstructured data.
That's what it was Shay Banon originally created it for. And what has happened over time is it's been evolved to be used in three core use cases. So the first one is search. And historically, Elastic was something that you could build search applications on top of. Search has turned into AI pretty quickly. AI has kind of been used as a search problem.
So now Elastic is increasingly a platform that people are building AI applications on top of. We offer vector databases. We have inference services where you can bring large language models into Elastic. We have multiple models through GenAI through a reranker model, an embedding model. There's hybrid search capabilities that we have that allow people to build AI applications on top of Elastic.
And that's been a big driver of growth for our business, expanding the TAM in search where people are using Elastic to build applications. That's one of the core pillars of Elastic. The next pillar, I'd say, is probably observability, where the ability to index, store and analyze these massive volumes of data has been applied to first logging, where you can index all log data and parse through it and use it really for observability. And that's where we've got a ton of strength in logging.
And we also have metrics and traces, which is APM capabilities at Elastic. But logging is kind of the core functionality. And I'm sure we'll talk about it later, but there's a lot going on with Metrics Elastic that we're super excited about that the new place that we're headed. And then the third capability is security. And it started with SIEM security -- the SIEM capabilities. And that has evolved. We also have endpoint functionality and some other stuff. And that's effectively a logging use case where people are ingesting log data and finding security issues with in and off of log data and parsing through it.
And that's a place where AI has been tremendously valuable to Elastic. And where we're able to -- we created a bunch of things in the security business where we were first to market. We were first to have an AI assistant in our business. We were first to have an Agentic SOC, which is this attack discovery capability that we have, which sort of automates the parsing through of data and alerts and triages it down that the SOC analyst doesn't have to do that manually. And so that's been a tremendous benefit that we've seen in security.
Our security business is just doing really, really well. And so taking a step back and AI has changed our business in the last three years, it's been pretty massive. So for search, AI has expanded the TAM where we used to have a narrower TAM with AI we're now being used to build applications. That's been huge. And then with observability and security, I think what's happened is it -- AI hasn't necessarily expanded the TAM.
But because we have AI capabilities built natively into our platform, we've been able to be first to market with a lot of AI functionality. And we've got a road map, which is really appealing to our customer base around AI. And so that's helped us become more differentiated. That's a high-level big picture Elastic story. I don't know, Blair, do you want me to go into a little bit kind of the update on the quarter? Would that be helpful or...
Sure. Actually, given your role as Global Vice President in Finance, absolutely give a snapshot of your last quarter, which was great.
And maybe just -- I'll give you a little context on what I do. So here at Elastic, I run FP&A. I have strategic finance. I run IR, I have procurement, I have enterprise data. So all the business-facing finance functions are kind of where I spend my time, and I partner with Navam on a lot of that part of the business.
And so I do have a pretty good sense of how the business has been performing. We had a really strong Q4 to end the year. We ended the year with CRPO growing 20%, RPO growing 28%. We just had a tremendous amount of long-term commitment that we saw coming from our customers. And when I saw that data, I said, well, this is remarkable.
Let's double-click into it. Is it that are we doing more discounting and that's what happened. And I looked into it, and we're not doing more discounting than we have historically. Was it more 5-year deals or some outlier 7-year deals that we got signed that [ juiced ] the RPO? And no, it's not the case. It's all 1-year deals and 3-year deals, which is the same tenure -- same duration that our deals have historically been structured to have.
So our business was just performing really tremendously well from a commitment perspective, and we're very happy to see the way that the business was performing as we exited the year. So that was really positive and a lot of excitement here at Elastic around how our business is doing.
Yes. And Eric, you also -- just for some of those who may not be familiar, last fall, October time frame, you sort of gave a longer-term or medium-term view on where you guys are going. Maybe if you want to just recap that and sort of your progress towards those goals.
Yes. And we've actually -- we've updated those goals. We've taken those goals even higher than they were before. But we had an Analyst Day in October of 2025. And at that Analyst Day, we walked through what we're seeing in the business around AI, the traction that we're seeing with AI.
And as we take a step back and look at our business, the growth that we think that's going to drive. And so we were comfortable to tell people that we think that we're going to get to 20% plus on our sales that subscription business. And sales-led subscription is the total subscription revenue, excluding the monthly cloud, which is more of a month-to-month business.
And so we feel very comfortable that we're going to get to that 20% sales-led subscription growth. And we also talked about a Rule of 40 type metric, whereby our Rule of 40 is going to be 40 plus, and we talked about operating margin being in excess of 20% non-GAAP operating margin being in excess of 20% in the intermediate term.
And the intermediate term for us is FY '29. And we updated that a little bit at the Q4 earnings where Navam said that we actually now just saying over 25% for the non-GAAP operating margin. We now expect that we're going to be in the 25% range for non-GAAP operating margin in that time frame. So a lot of positivity and excitement around where the business is going.
Yes. And a significant amount of your growth in the next few years seems to be coming or you believe will be coming from AI. And maybe we can shift back to that for a minute. On your core search business where you guys came from, where you have literally millions of downloads of the open source version, but also thousands of customers.
How is -- how are you approaching AI in your installed base in the search side? What are you providing for them? What's the value that Elastic can deliver and keep yourselves relevant or sticky within that search installed base?
Yes. So we've got a lot of functionality. We've got a vector database that they use to build their applications on top of. We've got reranker models. We've got embedding models through GenAI. We've also got inference as a service where people can bring LLM usage and inference usage from different LLMs into our platform and so they can use all of that as well as through hybrid search to build applications on top of. And there's a couple of reasons as to why we really think that we're doing so well.
So one of the issues is data gravity. People aren't going to put all that data into LLM. They need to bring the LLM to the data instead of the reverse. And so Elastic allows them to do that. Elastic has retrieval capabilities that bring the data that's relevant to a question to the LLM. And we got a blog post recently where an application without Elastic -- sorry, an application with Elastic was 70% more efficient in terms of token usage than one that wasn't using Elastic because Elastic is using that retrieval augmented generation, bringing the data that's relevant to the query to the LLM and kind of -- or bringing the specific details to the LLM and making the LLM much more efficient. So...
Certainly using traditional search capabilities and your highly indexed -- your rapid scalable, highly scalable indexing to find the information, the relevant information instead of wasting -- not wasting, but token expensive.
It makes it faster. It makes it more efficient. It makes it more accurate all at a lower cost. So if you're building an application with Elastic, it's tremendously impactful and can reduce the cost, can increase the efficiency, can increase the velocity of the application that you're building. And so that's the kind of thing that Elastic can do for people who are building applications. The other thing, just to give you a little bit more context, and this is an example that we've used historically, but if inside of your -- inside of Rosenblatt, there was some sort of search thing and you want -- you went to -- you had an internal LLM to answer questions, like an internal like chat-driven interface.
And you said, "Hey, I just broke my arm." I hope you haven't broke your Arm [indiscernible] -- but "Hey, I just broke my arm." I need to go to the doctor, what can I do? They're going to -- through Elastic can provide the underlying capabilities that say, "Hey, this is Blair Abernethy. He lives in this location. He has this medical coverage and they can say, Blair, you should call this person, you should do this person because they're in network. It can give you all of that because it has context around Blair, Elastic brings that Blair context to the bigger picture LLM. And so you're able to build applications like that with Elastic.
Yes. Then you guys were talking about that a lot last year, context engineering was starting to become -- the word was coming up. And I guess, I mean, part of the challenge here is that unstructured data is 80-plus percent of the -- 85% of the data out there, right? And it's -- a lot of it is unindexed. So are your customers recognizing this context engineering capability that you guys are bringing?
Absolutely. And that's why we're weighing these use cases, and that's why we're helping them to be more efficient. We're just -- we're seeing a ton of customers who need this context. Like there's a lot of stuff we do. We've got an AI solution, which help -- we've got customers in a big document company. And what they do, we allow them to query across their data. We bring the context to them. So it's not just that LLM has to read every single document. Elastic finds a document and then the LLM can read the document. Think of -- if you said, "Hey, I'm looking for contracts that have been signed with big automakers and I want to know x about them." If you used to ask an LLM that they have to look at every single contract in the database, think how expensive and time-consuming that is. With Elastic, Elastic brings the 3 contracts that are with automakers. It points them to what they need and then the LLM can analyze that data and use all the intelligence that LLMs are great. They're super powerful. They've changed the way that we work but they don't have the ability to parse out which one they should be looking for and Elastic can bring that to the table, make them much more efficient, much faster. You're getting better results at a lower cost. That's kind of how -- and so customers are wildly excited for that.
Eric, from a go-to-market standpoint, how are you guys taking this to your search installed base? And how are you -- I mean there's a lot of -- as we were talking before the call, there's so much innovation happening, so many changes happening so rapidly. How does Elastic kind of break above the noise a bit and say, "Hey, we have, we can solve some of these issues for you"?
Yes. We go to our customers. We understand what issues they're having. We work with them to tell them where we can help them. We put a lot more capacity into our go-to-market recently. I know that in Q1 of '25, there were some issues with our go-to-market. We resegmented the go-to-market, and we kind of narrowed the scope of reps who are covering higher-value customers and rework the go-to-market there.
There were some issues with that for that first quarter. But since then, the go-to-market has really been humming where we've seen tremendous success. We've seen a big uptick in productivity. And because of that uptick in productivity -- or strong uptick in productivity that we talked about at the Financial Analyst Day, because of that strength that we've seen in productivity, we put more capacity into the model to really go out and chase the business.
So we've been super excited for that. And the way we're doing it is we've got some specialists who are search focused who can give people expertise around AI and bring that to bear. And we're going and talking to customers and seeing what they need.
And it's I'd say that because of the strength that we have in AI, we've been able to up level the kinds of conversations that we're having where we're coming in because -- I mean, AI is really a board level initiative. And so the most senior levels at the company are engaging with Elastic because of that.
And even if they're not necessarily purchasing AI capabilities today, we're seeing customers who are making commitments and longer-term commitments with Elastic because of the AI road map that we have and because of our ability to partner with them over the long term to really be the AI road map that they're excited for.
Is -- maybe we can shift a little over to observability because it's been one of your -- the observability solutions and security solutions has been important drivers for you in the last five years. Where are you at on observability today? There are some -- a number of competitors in the market. And then maybe talk a little bit about sort of AI within your products or what you're doing to stay relevant in that space?
Yes. And so the biggest thing for us with observability is there are kind of 3 pillars to observability. There's logging, there's APM or traces and there's metrics or infrastructure monitoring. Historically, Elastic has been super strong in logging. We've had -- if you have a big logging use case or a complex logging use case, Elastic and maybe one other vendor you call.
We are the leader in that space, and we feel super confident about our ability to get into most of the logging opportunities and to win most of the logging opportunities. We've got an incredibly attractive price to value ratio where price to technology ratio, price to innovation ratio, where we kind of are best-in-class there, and we can bring best-in-class to bear at a reasonable price.
With that being said, metrics is probably -- or infrastructure monitoring, same thing. It's just -- it's probably been the fastest-growing part of the observability market. And it's been growing so fast because a lot of this cloud infrastructure that's been coming online, becoming a bigger and bigger part of the technology ecosystem. And we probably haven't had a best-in-class solution in metrics historically.
We've got a competitive solution, but it's not best-in-class, but it hasn't been. And we spent a lot of time in FY '26 reworking that solution, making it more compelling, more competitive. We've made it meaningfully more efficient by putting a columnar data store on the back end, where we've reduced the footprint of storage for metrics significantly by using a different storage ecosystem than we use for logging.
And because of that, when you benchmark us against our competitors, we're now meaningfully more efficient for them, have a much better price-to-value ratio. And so we think the big opportunity for us in observability and potentially one of the big opportunities for us [indiscernible] solutions is this metrics opportunity, where we now think that we can compete and win against the leaders in that space in a way that we couldn't previously.
And it's probably going to manifest itself with us, but initially rolling out as an add-on play where we try and sell metrics to customers who are already using us for logging. But ultimately, we think that we can lead with metrics and go out and win big. And it's something, Blair, that a lot of the leaders in the field have been asking for and we're excited for.
And so when our team got on stage at our sales kickoff at the beginning of May and told everybody in the field that we were going to have this best-in-class metrics offering and walk through some of the benefits, there was so much excitement. It's been something that our field team has been dying to sell. And it was funny, somebody said, "Oh, are you going to have any incentives for the field team to sell metrics."
And I almost laughed out loud because they've been wanting metrics so badly. It's like you gave them exactly what they wanted. They don't need incentives. It's something that they've been wanting to sell forever, and they've been selling against it. But now with this reworked architecture at the back end with the efficiencies, it's something that they can sell so much better than they've been able to sell before. So yes, there's AI capability. We have an AI assistant.
We have other capabilities that we have that are AI-centric in observability. But I think what's really going to move the needle is the metrics capabilities that we're bringing to bear. And like that's going to be just a complete game changer for our business and for the metrics business overall.
So that's GA now. .
That's being sold, it's in production. I think it's -- if it's not GA, it will be GA very soon. I think just in terms of -- we also -- just because I don't want to shortchange those because we're super excited about metrics, but we also have an AI SRE where we're going to bring a lot of AI to SRE and like we're instead of relying on engineers to manually do all this work, it's something where you're going to have AI that can automatically organize these unstructured logs, discover patterns, figure out root causes, and this is going to make things so much more effective, similar to what we do with attack discovery in security, which has been just a game -- the security business, I can't talk about that, but we've seen so much happening positive with the security business. I think that, that's the AI capabilities that we're bringing in for the SRE are going to really change the game for us. But metrics is probably the bigger opportunity even than that AI opportunity, to be honest with you.
Yes. So I mean, you've had a lot of traction with logs in the last couple of years. So I guess a lot of those customers are probably coming up for renewal over the next 24 months. So that's a perfect opportunity for you to sell metrics.
Yes. The field could not be more excited about metrics.
So we -- hopefully, we'll see some impact from that in coming quarters. This is not 5 years out -- is this some...
Well, here's the thing. So we just bought it to -- we're just taking it to market in Q1. People have to get enabled on it, and then they have to go out and sell it. they do -- they get the deal signed and then it takes time to turn to revenue. So if you think about the revenue outlook that we have for FY '27, we're not assuming a massive revenue impact from metrics. I think it's hopefully going to help us win commitments, get deals signed in the business, but I don't think that it's going to be something where we're going to say, "Oh, look, a meaningful portion of revenue is specifically attributable to metrics." I think it's FY '28 that the revenue component really starts to have a bigger impact. I think right now, it's going to be bookings it's probably going to be the bigger deal.
Got it. Got it. Before we go to security, just what metrics -- help us to understand how your pricing works for observability for logs and so forth?
Yes. Right now, the way that we price the solution is definitely based on ingest and compute. And so that's going to continue to be how we think about things. There might be some tweaks around the edges, but that's typically how we price things as Elastic. And there's going to be -- for the serverless offering, it's slightly different, how we price things versus ECH, and it's a little bit more based on outcomes versus -- outcomes.
It's not just based on storage and compute, there's other complexities in there, but it's typically storage and compute is the best way to think about how we price and it's consumption units. So we have consumption-based pricing, and that's going to continue to be how the [ cloud ] is priced. And it's going to consume less storage because we're now storing it much more efficiently with metrics. So it's going to compress the pricing that people see and make us much more able to compete with other vendors.
Right, right. And the -- just on your observability installed base, is it -- maybe help us understand how much of that is sort of Elastic Cloud versus on-prem or self-hosted? Is it mostly cloud?
Well, I think first and foremost, it's important to realize that the self-managed is not necessarily on-prem. A lot of people are taking that self-managed business and deploying licenses in their cloud ecosystems. And so they're not -- if you think about self-managed versus -- if you think about self-managed versus cloud, it's not legacy is self-managed, modern is cloud.
We're seeing some hyper modern use cases happening in self-managed environments where customers are taking our licenses and deploying them in their AWS, GCP or Azure instances and running very modern AI use cases, but where they're buying from us in a self-managed way. To your other question, how do we think of -- I'd say that there's not a big distinction where one solution skews more towards the cloud than others.
I'd say U.S. public sector tends to be where we see more self-managed business and large -- where I'm looking for highly regulated industries tend to have more self-managed, but I don't think that necessarily aligns with a specific solution where I'd say like, "Oh, observability is very self-managed and search is very cloud-centric."
I don't think that's the case. And even as you think about search and the motion we've seen towards more and more AI, I don't think even that has been more cloud, for example. We're seeing a lot of customers who are buying self-managed licenses and then using those self-managed licenses to deploy AI solutions in their own cloud environments or in their own on-premise instances.
Right, right. And that's part of your value prop is that you have the flexibility to allow customers to do it any way they -- to run it any way they want. Let's just shift to security. Maybe go back and just sort of high level. So here's what our security offering, where we came from. And then maybe talk about some of this new stuff like the AI site live the engineering and AI assistant and what progress you've made there on the product side?
Yes, I'm very excited to. And so logging turned into SIEM because that's based on log data and using that engine to parse the log data from a security perspective and to identify threats and anomalies. That's what the SIEM solution does. We've also added XDR into the business, and that came through the Endgame acquisition where we have endpoints. And we've actually -- one of the two $20 million-plus deals that we signed in Q2 of FY '26, one of those deals was very XDR focused, which is a tremendous win for us that we're very excited about.
And we've also got Agent Builder on top of the security solution. Agent Builder is our solution that allows you to take the data that's inside of our ecosystem and engage with it in the same way that you would an AI chat interface, you can just ask questions directly of the data, build different outputs with that data and do a lot of automation with the data that's in our ecosystem already. So you can create agents that are utilizing the data directly with Elastic in a way that we're pretty excited about.
And so those are two things where we were first to market on. And then also Attack Discovery is something that's been huge for us from a security perspective. And what Attack Discovery does is it allows you to -- without needing a ton of manual work to parse through the different alerts that you're receiving and figure out which ones we should be spending more time on, which ones are less serious and just sort of automating that triage to prioritize the alerts to spend time with is what Attack Discovery does.
And it allows people to reduce the amount of time that SOC analysts spend doing that manually. And it's been a tremendously positive thing. We've seen a lot of traction around it in our business and a lot of excitement. So a lot of people are using it, but there's also a lot of people who are excited about even if they're not ready to use it is yet, I think it's part of their road map.
And so when you're making their purchasing decision, it's something that comes to bear. And I think that security overall we've just seen tremendous momentum in it. And as we think about FY '26 as a whole and how we exited '26, a lot of the momentum that we're seeing in our business was from security. And I think the reason that -- it used to be that our reps were saying like, "Oh, when we're in a deal, we do well, but it's hard for us to get in deals." I think that Elastic name and security is getting stronger and stronger. We're getting in more and more deals. And when we're in deals, we're really winning them.
I ran to one of our 3 geo leaders at our sales kickoff, I was talking to him for a while. And he was just -- I was talking about the whole business, and he was so excited about what's going on for our security business. It's just the capabilities that we're bringing, our ability to win when we get in deals because of our technological differentiation.
He's like, look, my job is to get us in deals. The product team's job is to give me a product that I can sell once I get in deals and the product team is 100% delivered. We're ahead of our competitors on AI. We're excited about our ability to win when we're head-to-head with competitors. Maybe people can -- there's -- they can discount their product to a point that it's untenable. But generally, we're really excited about our ability to get in deals and then to win those deals once we're in the deals. Just it was really palpable to hear his excitement when I was with them at our sales kickoff.
Are you -- is Elastics -- if you think about your marketing and your profiles, you've been around for a long time, and you've had extremely well known on the search side of things. How are you raising your profile? Where are you investing to raise your profile on the security side?
Yes. I think there's stuff that we're doing for branding. I think there's stuff that we're doing in terms of going to conferences, raising our visibility. We've got search specialists, AEs is kind of a field goal and [ SA ] is an overlay where they bring to bear specific domain knowledge and are able to engage in those security conversations and have relationships with the appropriate security buyers in a way that we might not have had a year or two ago before we had that functionality.
And so just from a security perspective, we've made a lot of investment. I think a lot of it also is word of mouth and the fact that our solutions are winning and that they're being trusted by some of the biggest companies in the world. The CISA deal, we haven't talked about it yet, but that was a huge deal for us.
I mean we signed a $26 million deal with the U.S. Federal government through the CISA agency, where they're providing SIEM as a service to the civilian agencies in the U.S. public sector. And that just shows a massive trust in Elastic. And these are big, chunky deployments that are really important to agencies that are critical to the U.S. government, and they're trusting Elastic to deploy SIEM as a Service. And so stuff like that is just -- it's a great -- that kind of commitment from the U.S. government is phenomenal and speaks to the capabilities that our security offering has.
Yes. And that's -- you also just in the recent months, got FedRAMP high authorization, which is great. Is this...
I think [ long ] ago, right? Then we got FedRAMP high. Yes, very exciting.
So that, combined with this CISA deal is pretty important. How about other non-U.S. Federal state level and maybe talk a little more about internationally, how is your profile? How is business trending over there?
It's doing great. I mean the system just start to stand out that I mentioned it, and I'm so excited by it. The traction we saw there was game-changing. But internationally, the business continues to do really well with the public sector internationally at the state level, at -- with the Department of War and the different aspects of the non-civilian U.S. public sector, we've seen a ton of strength.
I think that from a public sector perspective, we're very happy with the way the business is performing. CISA is the bellwether and it's actually put a pretty big uptick in terms of the cloud component of the public sector business, which isn't typically as much cloud and CISA has like change that a little bit. But across the board, we're seeing strength in the public sector. There's a lot of excitement there.
Eric, how -- maybe if you can comment from Elastic's perspective on Agentic AI adoption within your customer bases. What -- how would you sort of characterize what are they doing? What have you seen that's working effectively? Were they leveraging your platform? And maybe just give us some sense of where we are on this -- on the customer journey in enterprise.
Yes. So we talked a little bit about the document search that we're seeing, but there's also an AI-native customer who we have on the music generation side. And what they're doing is they're using Elastic Search for vector search and beddings, a lot of detailed model stuff.
And what that allows them to do is they can index over 1 billion songs and then kind of create this retrieval and matching and generate lyrics to create -- I think we see a lot of as these AI-generated songs. They use Elastic for that, and that's really a great use for us. You're also seeing customers using us for Agentic. There's a global supply chain.
They're leveraging us for vector search features and they're embedding -- to embed AI into their products. And they've got a new Agentic product that didn't release yet, but it's on the way up. I'd say Agentic is very top of mind. It's still in the phase of becoming more prevalent. I think we're going to see more and more that gets deployed in the real world that's Agentic over the next 12, 24 months, but it's still earlier days for Agentic than it is for some of the other AI use cases is my sense.
But we're definitely seeing more and more of us with the Agentic stock with some of the stuff that I just talked about on this music company and then some of the stuff that we're doing in observability where people can use Agent Builder to engage with their data in a way and then ultimately, the goal is to be able to create agents that can act in -- can automate some of the things that needed to be done manually in an Agentic capacity.
I think that's the direction that we're going in that we're seeing more and more customers start to -- if they're not deploying it, some are deploying it. But even if they're not deploying it, they're starting to work with it. They're starting to think through how they can get value from this Agentic approach to AI.
Yes. Interesting. And -- your products have traditionally -- have been pretty technical and for customers. And so it's always hard to -- very difficult to have the staff that the teams available within an organization to really understand how to get the most out of the platform or the components of your platform. Is AI helping customers -- helping to make Elastic easier to use?
Absolutely. It makes a huge difference. I mean migrations off of other solutions on to Elastic are much easier with AI tooling. The AI assistant enables people to do things on Elastic that used to be very manual and can be totally automated or simplified now. AI is definitely a big tool in terms of how much more efficient it is for people to get up and running on Elastic and to reduce some of the complexity unquestionably.
Yes. Yes. And then what about internally? Maybe just bring us up to speed on what -- how Elastic has been leveraging AI within your operations?
Yes. In terms of our operations, I mean, there's a lot that we're doing in terms of engineering. So in R&D, we're heavily utilizing AI coding tools, all the ones you think about from OpenAI, Anthropic, from Google, and that's definitely accelerating the amount of code that we're deploying that we're writing.
We're creating much more efficient ways in terms of go-to-market the field is using some AI modules to automate seller onboarding and to make things a little faster. We're using it for feature testing in engineering. And in terms of -- in my function, there's a lot that we're doing in AI in the finance function, where there are things that used to be very manual, and we're experimenting with ways to automate them.
I'm not going to get too much detail with that because some of them are still figuring out. But the kind of stuff in the last 3 months, I'm not going to say 6 months in the last 3 months that we started to work on building in my organization are going to create meaningful efficiencies for the business over time, and we're already starting to see a little bit of it.
But there's things that we -- I mean, how much easier it is to build some of these things, there's something that we had an idea for. And 6 months ago, we were talking about buying a solution, and we actually built our own pretty efficiently for something that we're going to be using that we need to get our auditors comfortable, but we're pretty excited about it.
Good. And on the R&D side, we're in your finance hat, can you talk a little bit about the cost of token cost, which is everyone sort of grappling with versus the productivity or the value you're getting out of these things.
I track our token spend on a daily basis.
You are not worried about it, right?
I have it daily right? I'm very -- I'm not worried about it because I know it, but I know it because it's important. So I don't know what you say in that cyclical statement there is, but it's something that we think about that we track very actively. We want to make sure that engineers are using AI because it's going to give them -- you can't be a tax engineer without AI.
And we want to make sure that they're using it efficiently, that they're using the right models, that spend isn't getting out of control, but also that we are getting real spend into our AI usage. So I track it on a daily basis. I know how it's being used. We want to make sure that it's being used efficiently and that it's creating value in our organization, but it's very much a cost that we are aware of, cognizant of and planning around.
We're excited about it because I don't want to -- I don't -- the last thing I want to do, you have to balance it, like this is going to change the way that people work. This is -- I don't want people thinking about, oh my God, "I can't spend this $10 on AI when they can be so much more efficient with AI than without it." It's an engineer who's really strong with AI, if they were told, "Hey, you can only use this many dollars of AI." They would effectively stop working once they ran up to that limit because it's like if we were driving from San Francisco to L.A. and we ran out of gas halfway through, we wouldn't get out and walk.
We figure out a way to get more gas in the car. And I think that that's what AI can be in terms of force multiplier is the same way a car can move you from here in LA [indiscernible] 500 miles, so much faster than a horse can. I think that AI versus manual coding is the same way that no one's going to -- in short amount of time, it's going to be pretty rare that you see people manually coding things in my belief. And that's not an elastic belief, that's an belief based on conversations I've had with our team here and some of the things that I've seen that some of the engineers are able to do that is pretty remarkable.
I've been hearing similar comments this week from several different people at the conferences I'm attending. So yes, there's -- we're heading towards a point of where coders may not be coding all that much at all.
They understand code. I mean it's critical for them to -- but they're also going to have to understand how to get agents to work for them and how to have these Agentic factories that are developing software where they're giving directions, but they're not -- I think one of our developers here said something to me that really resonated.
If we were in a car factory, and you said, "Oh, this isn't working fast enough", like you have all these machines and putting the cars together. You wouldn't go down there with a hammer and nails and like work alongside the machines.
That would be really inefficient. And his belief is that at some point, pretty soon, we're going to get to a world where that's what coding looks like where you're setting up the factory for the agents to develop code, but you're not there writing code next to them.
Right, right. You're setting the strategy in the direction and the feature descriptions, if you will, and the processes, but then let it run and let it run.
The Q&A and the testing and the code review, you're having all of those be done by different agents who have a set of parameters that they're working under and are able to utilize in order to really drive the best results.
Has Elastic looked -- sorry, have these coding tools changed your hiring practices or views at all within the engineering group?
I think that across Elastic, we need to be thoughtful around what our organization is going to look like going forward. I think in FY '27, you'll still see us add headcount on a net basis, but it might be in different organizations than we would have without the benefit of some of these AI innovations. And it might -- the shape of the organization, the places where it grows is going to be different than it would have otherwise because there will be some new efficiencies that will be introduced because of AI.
We're going to use AI as many places as we can. But for example, the selling function, you still need people talking to people in order to sell software. And I don't think that's going to change in the immediate term. So we'll see headcount continue to flow into the field work, obviously. But there will be change in terms of how Elastic growth looks in this fiscal year.
I guess in your SMB side of your business and your monthly business, are you utilizing or applying AI there to help drive up consumption?
I think it's something that there are more opportunities for us to do more with AI in that part of the -- in the low-touch part of the business, and that's something that we're looking into and exploring and there are different ways that we can get benefit from AI for sure, in that sort of the self-service business.
Okay. Great. Maybe just as we're getting close to the end of our time here, just to step back a bit and just sort of remind us in terms of M&A technologies. How are you looking at the M&A world right now, just given the fact that things are changing so rapidly? Is it -- are you more focused on internal development? Or are you still looking for -- because you bought a couple of interesting pieces in the last year. So maybe just to frame that up for us.
Yes. I don't think there's going to be a stepwise change in our M&A strategy in the midterm. I think that we've had this perspective that if things can pull forward our road map, if they can bring innovation to the business then we wouldn't have otherwise or that would take us much longer. We're open to doing something with M&A. And that doesn't preclude us from doing at a certain size or scale or what have you, if it's accretive to the business in terms of the growth and the trajectory of our business and the direction we're moving, which is getting more and more AI-centric, more and more Agentic. Like if there's something in the AI space -- in that space that's going to support that, I think we're very open to adding that technology to our business. And I kept that short because I know we're short on time. So.
Yes. I appreciate it, Eric. And it's great to see the business performing so well in the last couple of quarters, and it seems like the opportunity window has been getting bigger and continues to get bigger for Elastic. So thanks for sharing your thoughts and your time with us today.
Thanks for having me, Blair and I really appreciate the conversation.
Okay. Great.
Elastic NV — Rosenblatt 6th Annual Age of AI Technology Summit
Elastic is positioning its search, observability and security platform as an AI-native stack — metrics and security momentum underpin medium-term targets.
📊 Key Message
- Central thesis: AI is expanding Elastic’s addressable market (search → AI apps) and improving stickiness across observability and security by bringing the model to the data and reducing LLM token cost.
- Momentum: Management reports strong bookings trends (CRPO and RPO growth) and improved go-to-market productivity that support higher medium‑term growth and margin targets.
🎯 Strategic Highlights
- AI stack: Vector database, embedding/reranker models and inference-as-a-service plus hybrid search and retrieval-augmented generation (management cites ~70% token efficiency in one benchmark).
- Observability: Reworked metrics product (columnar backend) reduces storage footprint, is being sold now and is expected to aid bookings in FY27 and revenue more meaningfully in FY28.
- Security & GTM: SIEM, XDR (Endgame), Agent Builder and Attack Discovery showing strong traction; GTM resegmentation improved rep productivity and field capacity.
🔭 New Information
- Targets updated: Management reiterated its medium-term targets: sales‑led subscription growth >20%, Rule of 40 >40 and non‑GAAP operating margin ~25%+ by FY2029.
- Notable wins: $26M CISA deal and FedRAMP High authorization highlighted as proofs of trust and catalysts in public sector cloud adoption.
❓ Analyst Q&A
- Metrics timing: Management expects initial bookings benefit in FY27 but meaningful revenue contribution shifts toward FY28; product is in-market and field-enabled.
- Pricing & deployment: Cloud is consumption-based (ingest/compute); serverless/outcome options exist; self‑managed licenses are often deployed in customers' clouds rather than strictly on‑prem.
- AI costs & hiring: Token spend is tracked daily; leadership isn’t alarmed but is managing model selection and efficiency; they expect headcount mix to shift as AI changes workflows.
⚡ Bottom Line
- Conclusion: Elastic appears to be converting AI product leadership into bookings momentum, with security and a revamped metrics offering as key growth levers; near-term revenue upside from metrics is limited but medium‑term targets and margin guidance were raised and look credible if GTM execution holds.
Elastic NV — Bank of America 2026 Global Technology Conference
1. Question Answer
Let's get this started. My name is Koji Ikeda. I am one of the software analysts here at Bank of America. I'm thrilled to be hosting a fireside chat with Elastic. We got Ken Exner, Chief Product Officer; and Eric Prengel, Global Vice President of Finance. So thanks so much for being here, guys.
Before getting into product, and I do want to get technical with you, Ken. I'm thrilled to have you here because I want to talk about the technical side of Elastic. Eric, maybe first question is over to you. You guys reported results last week. It was a busy day on reported earnings that day. Lots of companies reporting. So maybe just give us a high-level overview of what happened in that quarter. And I think most importantly, the guidance methodology as you're thinking about the next fiscal year.
Yes. So we were really excited about the quarter. We saw cRPO grew 20% and RPO grew 28%. On a constant currency basis, cRPO increased 5 points growth from the prior quarter. So tremendous momentum. It was really a testament to the bookings that we're seeing and the strength in the product that Ken and his team put together, where we're able to really win in the field.
I think there have been a lot of people asking, "Oh, well, is any of this inflated? Is there some sort of thing that's going on where you have more discounting or something like that?" And the answer is no. This is truly the business performing. And so we are really happy about that. That was tremendously positive.
One thing that did happen in our quarter is that there was a shift in the mix a little bit more towards cloud. And because there's an upfront rev rec component to self-managed, that took a little bit out of revenue. So think about there being a 1-point headwind to revenue based on that, coupled with a little bit of FX. But overall, a very positive quarter in terms of the commitments, a record quarter over the last couple of years in terms of the growth and commitments. So we're really happy around that.
We also gave guidance for FY '27. We initiated our FY '27 guidance. And the way to think about our FY '27 guidance, a couple of things. So we guided to a full year of 14.5% growth, which is actually acceleration from the Q1 guide. So we think that we're going to see the trajectory of the business accelerate nicely on a quarter-to-quarter basis, which is very exciting. And we're comfortable with the guide based on what our cRPO is and what that means in terms of how much we have to go get that's not already committed. So we feel really comfortable about that.
And in terms of the guidance philosophy, I would just say that it continues to be -- we want to put forward a guide that we feel comfortable that we can hit, that we feel confident that the business has plenty to execute against to get to that guidance. So we feel good about everything on the guide side.
On that point in the shift mix to cloud, 1-point headwind, can we dive into that a little bit more? Is that really around, hey, when you gave that fourth quarter guide, the first time you thought this amount is going to go to cloud, this amount to self-managed and it turned out a little bit differently? Or was it bigger customers that decided to change their allocation between cloud and self-managed?
I'd say it was the former, but it was a little mix of the latter. So the biggest thing for us was we won the CISA SIEM-as-a-Service deal, where we're providing security and SIEM to the U.S. public sector, the civilian agencies there through CISA. And so we've actually seen a much better uptake of that than we'd even expected. And so there were certain government customers who historically had been consuming us through self-managed and some of them shifted over to the cloud when they did deals with us in Q4. And so that CISA SIEM-as-a-Service deal really drove an increase in the cloud portion of our business, which we were really happy to see. It's all going to come to us as revenue. It's just that the timing of the revenue recognition moved around a little bit.
Eric, I hate to put you on the spot. But FedRAMP, do you know exactly where you are, FedRAMP certification on the cloud side?
I believe that we got...
Certified.
Yes, we're fully certified.
Fully certified and it's up as of last month.
Okay. Okay. Yes. Okay. So I guess the key message here...
FedRAMP high.
Yes. We were FedRAMP moderate, and now we got FedRAMP high.
Got you. So I think the key message here on the guide is look at cRPO as an indication of what's giving you that confidence in the cRPO.
Yes. I think that's the right way to think about it.
Okay. Okay.
And one other thing besides cRPO, I think it's worth noting because it's something that we've put a lot of effort into across fiscal '26 is field capacity. And so call it, 2 years ago, in Q1 '25, there were some execution issues. Since then, Mark Dodds has done a tremendous job of really getting the go-to-market motion on track. And because of the success that we're seeing in the go-to-market and the productivity that we've seen in our field force, we've actually started to invest a lot more in capacity. And so over the last 12 months, we've been putting more AEs into the field. And in Q4, we saw -- that was part of the reason we saw success in Q4, and that gives us a lot of confidence going into FY '27, just given the capacity and productivity that we need to drive the business, we feel very good about that.
Maybe on the question on kind of go-to-market with Mr. Dodds and really considering you just finished your fourth quarter. And so good time to make any sort of strategy shifts for the next fiscal year. Anything we should be thinking about on any sort of account reallocation or any sort of geographic reallocation or anything on the go-to-market side?
No, nothing in terms of account reallocation, geographic reallocation, nothing in terms of sales compensation. We feel very happy with how our go-to-market functioned across fiscal '27. You can particularly see that in Q4. And based on the way the team is executing, we don't need to change the go-to-market. We just need more of it, and that's why we're adding capacity to the business.
Got it. Ken, let's talk Elastic technically. But I do want to start high level first. And so it is a very technical product. Customers buy you for the technical benefits and the differentiation in there. But maybe just taking a huge step back, what is Elastic and why do customers buy you?
What is Elastic? That's a big question. The company started as an open source search engine, Elasticsearch, which is one of the most popular open source projects of all time. So I think it's the most popular Java open source project. So it's used by millions of developers. Initially, people used it as a search engine to power search within their applications. People started realizing that you could use it as a development platform. So people started using it to build matchmaking sites and ridesharing sites and using it to build signal intelligence systems, things like that.
A couple of the most common use cases where people using it for log analytics and observability to search through logs, to search through metrics. And also people started using it for threat hunting, also searching through logs and security event data to do security threat hunting.
So over the years, we evolved into sort of 3 businesses, one around the search business, which these days is really about powering AI-based search. The observability business, which was taking a lot of what people were doing, using us as a log analytics platform and searching through metrics and traces and other things and making a more out-of-the-box experience there. And then finally, on the search side, this is probably the newest, but growing incredibly fast. People were using us as a SIEM or as a security analytics platform. And then we've been expanding beyond that to sort of the adjacent spaces and in the security space. So those are the 3 core businesses, the search, which is these days, AI -- powering AI search or powering AI applications, not just human usages of search, but also observability and security.
Let's tackle each one of those opportunities one by one. AI search or search, AI, we'll combine those 2. Observability and security. And so when customers are coming to you -- let's start with security. So when customers are coming to you and saying, "Hey, Elastic, help me with my security problem." What is that problem? How do you help solve it?
Well, the core of this is we became very popular for threat hunting. People would use us to search through logs and security event information, looking for that needle in haystack, trying to figure out if there was an intrusion, trying to figure out what happened and trying to correlate across different signals across their business. We packaged that up as a SIEM product, and this was -- happened a few years ago. And this is the core land motion for us, which is we are the SIEM for most of the SOCs, security operation centers, that they use for that core threat hunting. But we also do some of the adjacencies. So we expanded into endpoint protection. We expanded into cloud security. We expanded into entity analytics and SOAR for some of the adjacent spaces. But the core of the product is the SIEM application, which is security events information system that people use for threat hunting.
I will also say that these days, everyone in the security space talks about sort of an agentic SOC, which is taking a lot of the activities that these security analysts do and turning it into sort of agentic workflows that allow them to respond more quickly. We've been a leader there in sort of turning the security operations center, which is built around the SIEM into a fully agentic security operations center. So these days, people talk about it as sort of using AI to automate the tasks of a security professional. You have to -- people are creating attacks using AI, so you have to kind of respond with the speed of AI as well.
And then same question on the observability side. What are they coming to you for?
The core of the business was always in logs, which is -- people were using us as the ELK stack as people used to refer to it as, became the most common solution for logs. That continues to be a big part of our business. But we expanded into the adjacencies as well. We expanded into metrics, expanded into tracing, expanded into synthetic monitoring and RUM, a bunch of the different areas. So today, we're a complete observability solution.
I will say that we've spent a lot of time over the last year trying to become a really great metric solution. And I view this more as an opportunity for us to expand. Even without investing a lot in metrics and infrastructure monitoring, we've had decent pickup in adoption, but logs has always been the core of our business. I'm very confident about our ability to win and go on the attack in terms of metrics because we've done a bunch of performance and efficiency work. We're now 3x faster than Prometheus-based systems. We're 2.5x faster than Prometheus-based systems, 2x faster than ClickHouse or more efficient than ClickHouse. So we've done a lot of work to be really performing high -- highly performant and highly efficient metric store in addition to being a highly performant and efficient log store as well.
Can I add something there? So I think it's just good to note for everyone that logs is the primary portion of observability in which we play. And I think that -- if you look at the market growth, metrics and infrastructure monitoring has probably been the fastest-growing part of that market. And so for us to be able to be much stronger in that market and more competitive, which we relaunched our product in fiscal '27 at SKO.
We got on stage and talked about the tremendous strength in the change that we've made in the product. I think that presents us with a huge opportunity for observability -- for our observability business to really be reinvigorated and go to the next level with those metrics capabilities. So it's something that the field is super excited about. It's something that the team is super excited about. And I think it's a really big opportunity for Elastic in FY '27.
Yes. We also now natively support Prometheus data in PROMQL. So if you're using a system like Grafana that is Prometheus-based, you don't have to change anything. You just swap out the back end and suddenly it's cheaper and faster, which is really -- you don't have to change in your dashboard. It's just -- it's immediately cheaper, immediately faster.
So maybe a good question for you, Ken, thinking you're the Chief Product Officer. And so the strategic move to invest more into metrics, infrastructure monitoring, was that a recognition of, hey, there's a pretty good opportunity here, we should go for it? Or were there customers saying, we need more because we want to use you guys for this?
It was both. One, as Eric mentioned, metrics or infrastructure monitoring has been the fastest-growing part of the observability space. And it's not one that we had focused a lot on. Even despite not focusing a lot on this space, we still had customers starting to use us for metrics workloads. And this is because we're seeing a bit of consolidation happening. People are wanting to use the same tools for metrics and tracing and logs. So some customers were pushing us because they were wanting to consolidate tools, but we also saw it as a big opportunity for us to grow the business. I would say it's both of those.
Ken, when you're out there talking with customers, I think one of the things we often debate with observability and security is that there are 2 different buyers. Are you seeing -- when you're out there talking with customers, are you still talking with 2 different buyers for your products? Or are you beginning to sit at the same table as either one person talking about both or having both parties in the room at the same time?
The most common is it's different. But if it's a business that is trying to save money through consolidation, it tends to go up to the CIO. So oftentimes, for consolidation plays, it's going to be at a more executive level, and that's usually the same buyer. Oftentimes, CISOs or the SRE team and the InfoSec team report up to a CIO eventually. But they tend to be different buyers, but we're still able to use the accounts to move laterally.
Like one of our most common plays right now is talking to our existing search users and getting them to consider us for security or for observability. And they just make the introductions to their CISO and their CISO often already knows us because their security analysts are already using us in an open source form, and we're able to turn them into a security customer in addition to search.
How does the conversation go with customers that choose you for observability and security traditionally. But the natural progression is how do we use agentic capabilities within observability and security and you guys can power that. What does that conversation look like with customers?
So in the security space, everyone is kind of talking about the agentic SOC So there's a lot of curiosity about what it means. And we're able to actually show it in the product on top of real data, and it's not just sort of this theoretical thing or not just a good demo. So usually, in the security space, what we do is we show it, and we actually let them use it. And there's kind of this -- it's gone from this theoretical or this marketing hype to something actually very real.
I remember when we introduced Attack Discovery, which was -- this is one of the very first uses of agentic AI and security. We introduced this at RSA like 1.5 years ago. It kind of blew people's minds because what we were doing is we were processing all the alerts that come in and automatically figuring out which ones were false positives, which ones were real, which ones were correlated. And we're able to map this to the MITRE ATT&CK chain and basically show customers the entire attack path.
Now for security analysts that sifts through hundreds of these alerts a day trying to figure out which ones to pay attention to or not, we've just taken that work and just done it in like in a minute and showed them, this is what you need to care about. And when we have these conversations, like these analysts would start to cry or like they would tear up. They're like, you've taken all the drudgery away from my work and like gotten me to a point where I can actually fight the issues. I can actually act on these things. So when you show them this -- we show them how real this is, it's quite empowering.
We're always worried that people might react to it as taking away their work, but it was actually quite the opposite. It's the drudgery. It allows them to actually feel more effective because they're kind of buried in what they're doing right now. They're buried in drudgery. And the same thing on the SRE side. They're buried in drudgery. They're getting woken up in the middle of the night. They spend the first half hour trying to figure out what the hell is going on, why are they getting paged in the middle of the night. And if we can immediately show them, this is what the issue is, this is what you need to investigate, these are the potential ways to remediate this. Again, they beam because you've taken that drudgery away from them.
I think what's really interesting and attractive for Elastic for the end customers is having a cloud solution and a self-managed solution. And so help me understand why having that both options is important. And then also how you guys think about driving innovation between those 2 products? Is it parity for the 2 products? Is one more important than the other? Or like is one catching up to the other? How do you guys think about innovation between the 2?
So this is a huge differentiator for us. We are open source. We have a core product that's open source. We have self-managed, meaning you can run it yourself on-prem or on your own AWS or GCP accounts wherever you want. We have customers that run us on battleships, run us on Humvees, like you can run it wherever you want.
We also have 2 different versions of our cloud offering. We have a hosted, which is sort of a single-tenant version of our self-managed that we manage for you on all 3 cloud providers. And then we have the serverless offering, which is kind of a pure SaaS version, which is on a modern serverless architecture. So we offer it multiple ways across all 3 major CSPs, across more than 60 regions, across GovCloud, FedRAMP moderate, FedRAMP high. We're working on IL5 right now. So lots of different ways to consume the software.
I think the other thing that makes us a little bit different is that these are not forks. Like we don't -- we try to maintain for the core system together, which allows us to always lead with serverless, but eventually make things back into the other ways we offer the software, too. So the promise we make our customers is that we will always launch things first in serverless, but we try to always make sure that we make them available for on-prem as well. And it's important, especially for our public sector customers, where they may be completely air-gapped. They may be on battleships as I said. They need to know that they're going to have a great security product. They're going to have a great observability product, and they're not crippled because of their environment.
Speaking of forks...
Sorry, I will say one other thing. The other thing -- the other reason I think this is important is that it allows us to be where the data is. And this is important because think about observability, like each of the cloud providers has their own observability solution. Despite that, we have a very vibrant observability industry that works across these different cloud vendors because it allows them to create a common interface to those different systems, but it can also be where the data is.
So in terms of our search business. We don't have to -- you don't have to move your data into the AWS because that's where your vector database is. You can have your vector database be wherever your data is. So there's 2 advantages to being wherever a customer is. One is you can provide a single interface across all the different -- wherever their data is. And you can be wherever -- if they are in GCP or on-prem, you can have your Elastic cluster or your Elastic deployment there.
So fork, there is a hyperscaler out there with a forked version of you guys. I don't hear about it that much when I'm talking to customers and partners out there. I'm curious from your seat and when you're out there talking with customers, does that forked version come up at all anymore?
It does if you're an AWS customer. So if you're an AWS customer, they bring it up because for an AWS customer, it's there. It's easy for them to use it. And they try to attack us and try to say -- their pitch is essentially, it's the same thing. It's the same product. And we often have to sort of combat that and explain that it's not. It's a fork and it's one that's not been maintained very well, and we have to talk about how we are significantly more performant, more efficient. And then they run the benchmarks and they actually see that we actually are quite a bit cheaper in terms of the total cost because of the investments we continue to make in efficiency, the investments we continue to make in performance. But we have to combat that. But it's usually only with AWS customers.
So Elasticsearch has been around for a long time. And when we peel back Elasticsearch, it is based off Apache Lucene. And I've always wanted to ask you, Ken, how do you guys make it easy or maybe it's not easy to switch between different versions of databases, vector databases, solutions, search solutions that at the very, very core are Lucene based?
Switch between different vector databases...
If someone wanted to come to you and they're using some other...
It's not easy. They're not -- the interfaces are completely different. So Lucene is the core search engine. We are the primary maintainers and contributors to Lucene. So people often view it as one and the same thing. With us, like we're 90-plus percent, 95% of Lucene using contributors and contributions. We chair Lucene open source projects. Others can use that as a core engine in whatever other implementation they have, but the interfaces are different. The implementation is different. So you can't very easily change. So if you have a system like MongoDB that also uses, it doesn't mean you can change.
Okay. Okay. So I wanted to ask kind of the bull debate on you guys and AI as a demand accelerator. And so Ken, maybe a question -- or Eric, a question for both of you. What are you seeing out there that's giving you the confidence that AI is going to be a long-term driver for you guys and an accelerator of growth for you guys?
I'll start. I'd like to look at it 2 ways. One is we're a foundational part of the Gen AI and agentic AI tech stack. And this is people using us as a retrieval system as part of their context engineering environment. And then we're also using all of these same tools ourselves to power our observability and security solutions. Both of those are important growth drivers for us.
On the search side, as I mentioned, people -- search has become something that doesn't power human interfaces anymore. It's powering agentic experiences. So people are using search as a retrieval system for passing data to an LLM or an agent. And this begins with us as a vector database, but includes a bunch of different retrievable techniques around that and a bunch of the supporting ways to pass data to an LLM or an agent. It's no longer just RAG or prompt engineering. It's helping people build MCP tools, building skills, different ways of exposing data to an agent or an LLM. And we provide sort of a complete context engineering platform that supports various different techniques. And everything from embedding models to different retrieval techniques very efficiently, figuring out how to get data to an agent or an LLM. That is a huge growth driver for us, how do we continue to invest in that and be a core part of the modern agentic AI stack.
The other part is we use these things ourselves, and we get to use our own toys. And it's allowed us to move very fast in observability and security and to be leaders there in applying these to those use cases. So I mentioned before, Attack Discovery, like we were actually the very first observability and security company to introduce AI assistance and copilots. This was more than 3 years ago. And we've continued sort of providing that leadership, constantly providing the leading capabilities for using agentic workflows within observability and security. And it's because we can use our own technologies and we can use our own tools. And that's actually enabled us to move faster than anyone else.
This provides growth because suddenly now it's not just selling the platform, it's now we can monetize this through token usage. We can monetize this through workflow executions that we charge for. We can monetize this through conversation turns, different meters that spend based on these -- us using these tools for those agentic and AI experiences.
One thing I'd add is I think that we're seeing tremendous momentum on the Gen AI front -- on the AI front in terms of the metrics that we have. So we reported 600 of our 100,000-plus customers are now using us for AI capabilities. That's a pretty big step up from the prior quarter. We talked at the Analyst Day in October around some of the expansion metrics associated with AI and some of the metrics around the traction that we're seeing there. And so it's not just something that's part of the talk track, it's actually genuinely supporting the business. And so across the board, we're really happy with what AI is doing for our business.
I wanted to ask a question on embedding models. I spent -- this one is going to be Ken. I spent a lot of time over the last week...
You've been researching...
I've been trying to figure out what exactly is an embedding model and what does it mean for certain companies? What is it and why?
Embedding model is how you vectorize data. So you take data, whether it's text or image or whatever, and you want to put it into a vector database, you need an embedding model. It's a way to turn text or whatever into vector coordinates that you put into a vector database that allows you to do similarity search. So it's a way to turn it into a couple of plots of data that you can put into the vector database. And it needs to create those coordinates based on an understanding of similarity. So it needs to process the underlying data, understand what is similar and then create these coordinates to plot into vector space.
When people introduced vector databases, initially, it was about text, taking text and trying to create coordinates for a vector database that allows you to say that a cup and a glass are similar concepts, and you can plot those in proximate space in a vector database. People also use it for images and text and stuff. Actually, one of the things people pushed this for very early on, even before generative AI is people wanted to do like image search using Elasticsearch. And companies like Adobe were using us to do image search even before generative AI. So we've been doing this for a while.
The thing that's been happening more recently is sort of a race to multimodal embedding models where you can take a PDF document, which might contain tables of data and text and images and stuff and be able to vectorize that entire thing or take a video or take audio. We recently introduced our omni series of Jina AI models, which are multimodal, which allows us to handle any type of data. And -- we're very proud of this because it truly is multimodal. It handles audio, video, images, text and everything using sort of vision model techniques. And it's sort of state-of-the-art in terms of multimodal.
The other thing I'm very proud of is -- this one often people overlook, but it's really important if you're actually using these is that we have some of the most efficient embedding models. So we introduced a new small and nano class of our embedding models, which rank right now in the top 10 of all embedding models, but they're super small. Compared to the rest of the top 10 of embedding models, it is -- I think it was 14 to 50x smaller than any of the other models, which directly translates into cost. So if you're using this, like people are picking these because they're still highly performing in the top 10, but they're like a fraction of the cost to run. So I like -- I geek out over efficiency. And that to me is almost as cool as multimodal.
Interesting. It sounds like something I need to dig in a little bit more on here. So we are all out of time. Ken, Eric, thank you so much for doing this. This has been a fun conversation.
Thanks for having us.
Thank you.
Elastic NV — Bank of America 2026 Global Technology Conference
Fireside chat: Elastic frames bookings momentum and product-led AI/observability/security as the drivers behind a confident FY27 guide despite a short-term cloud mix timing headwind.
📌 Key Message
- Thesis: Elastic says contracted Remaining Performance Obligation (cRPO) grew ~20% and RPO ~28%, supporting an initiated FY27 revenue guide of 14.5% growth; management credits improved field capacity and bookings for confidence while noting a small revenue timing headwind from a shift to cloud.
🎯 Strategic Highlights
- AI & Search: Elastic positions itself as a retrieval/context platform for agentic and generative AI, offering vector search, embeddings, and tools to pass data to large language models (LLMs).
- Observability: Heavy investment into metrics/infrastructure monitoring — product relaunch and claims of materially better performance and cost efficiency versus Prometheus and ClickHouse to win consolidation deals.
- Security: Focus on SIEM and agentic Security Operations Center (SOC) workflows (Attack Discovery) to automate triage and reduce analyst drudgery, enabling monetization via token/workflow meters.
🔭 New Information
- FedRAMP: Elastic confirmed FedRAMP High certification (upgraded from Moderate) and availability across GovCloud regions.
- CISA deal: A CISA SIEM-as-a-Service public-sector win materially increased cloud consumption in Q4 and partly explains the cloud mix/timing shift.
- Embeddings: Launched an “omni” multimodal embedding series and new small/nano embedding models that claim top-10 quality at substantially lower compute/cost.
❓ Analyst Q&A
- Guidance: Management points investors to cRPO as the basis for the FY27 14.5% growth guide and says the guide is conservative relative to committed backlog.
- Cloud mix: The ~1-point revenue headwind came from deals shifting from self-managed (upfront revenue) to cloud (different recognition timing); management says cloud uptake is durable.
- Go-to-market: No territory or comp overhaul planned — Elastic has added account executives and increased field capacity to capture demand.
⚡ Bottom Line
- Conclusion: Elastic combines clear bookings momentum and differentiated product advances in AI, metrics, and security with tangible public-sector traction (FedRAMP High, CISA). The FY27 guide looks attainable given cRPO and added sales capacity, but investors should watch cloud/self-managed revenue timing and execution on embedding/AI monetization.
Elastic NV — Q4 2026 Earnings Call
1. Management Discussion
Good afternoon, and welcome to the Elastic Fourth Quarter Fiscal 2026 Earnings Results Conference Call. [Operator Instructions] After today's presentation, there will be an opportunity to ask questions. [Operator Instructions] Please note, this event is being recorded. I would now like to turn the conference over to Eric Prengel, Global Vice President of Finance. Please go ahead.
Good afternoon, and thank you for joining us on today's conference call to discuss Elastic's Fourth Quarter Fiscal 2026 Financial Results. On the call, we have Ash Kulkarni, Chief Executive Officer; and Navam Welihinda, Chief Financial Officer. Following their prepared remarks, we will take questions.
Our press release was issued today after the close of market and is posted on our website. Slides, which are supplemental to the call, can also be found on the Elastic Investor Relations website at ir.elastic.co.
Our discussion will include forward-looking statements, which may include predictions, estimates, our expectations regarding the demand for our products and solutions and our future revenue and other information. These forward-looking statements are based on factors currently known to us, speak only as of the date of this call and are subject to risks and uncertainties that could cause actual results to differ materially. We disclaim any obligation to update or revise these forward-looking statements unless required by law.
Please refer to the risks and uncertainties included in the press release that we issued earlier today, included in the slides posted on the Investor Relations website and those more fully described in our filings with the Securities and Exchange Commission.
We will also discuss certain non-GAAP financial measures. Disclosures regarding non-GAAP measures, including reconciliations with the most comparable GAAP measures can be found in the press release and slides. Unless specifically noted otherwise, all results and comparisons are on a fiscal year-over-year basis.
The webcast replay of this call will be available on our company website under the Investor Relations link. Our first quarter fiscal 2027 quiet period begins at the close of business on Friday, July 17, 2026. We will be participating in the Bank of America Global Technology Conference on June 4 and the Rosenblatt Technology Summit on June 10.
With that, I'll turn it over to Ash.
Thank you, Eric, and good afternoon, everyone. Thank you for joining us today to discuss our fourth quarter and fiscal 2026 results.
Elastic finished the year strong, beating our guidance across every key metric. This was our seventh consecutive quarter of disciplined field execution, and we saw very strong commitments, resulting in CRPO growth accelerating to 20%. Organizations are increasingly choosing Elastic for their long-term AI transformations and making larger multiyear commitments to standardize on our platform for the future. The acceleration in our Q4 RPO growth, which reached over 28%, validates the growing magnitude and momentum of our customer commitments and sets us up well for the future.
In Q4, we achieved 16% total revenue growth and a non-GAAP operating margin of 14.8%, resulting in a full year revenue growth of 17% and a non-GAAP operating margin of 16.4%. In Q4, our sales-led subscription revenue grew 19% driven by continued demand for our platform for AI, search, observability and security. Our highest value customers are leading the shift towards multiyear deals. It was a record Q4 for $1 million deals. And in FY '26, we added more than 30 net new customers to our $1 million-plus ACV cohort, bringing that total to more than 240. Within that group, our count of customers spending over $5 million with us annually grew 30%. We ended the year with over 1,720 customers spending more than $100,000 in ACV. This is highlighted by several marquee wins in security as we continue displacing legacy vendors.
In the public sector, our partnership with the Cybersecurity and Infrastructure Security Agency, or CISA, around the Elastic SIEM as a Service is growing, with more civilian agencies switching away from competitive security offerings onto the service powered by Elastic Cloud. This led to our commitments mix in Q4 to shift more towards Elastic Cloud than in prior years, which impacted our in-quarter Q4 revenue. The shift to cloud will be a positive for the future as these agencies ramp their usage toward their commitment levels.
The broader AI cycle is actively driving our growth. Customers rely on us not only as a context platform for AI, but to modernize their operations with our AI-driven SOC and SRE for security and observability, respectively. Our customers using our AI solutions continue to grow. We now have over 600 customers with an ACV of over 100,000 or greater using our AI capabilities. This includes more than 40 serverless customers who were previously not captured in discount. Cumulatively, AI use cases have now penetrated more than 1/3 of our $100,000 ACV customer cohort. We see demand ranging from the largest global organizations to AI-native companies.
We believe the adoption of AI will be universal, spanning across organizations of every scale. This represents a fundamental market evolution that provides a consistent tailwind for our growth over the long term. The software stack is being rewritten. Large language models are emerging as the new operating system, and agentic automation is becoming the prerequisite for every mission-critical business process.
We are capitalizing on this AI-driven disruption through 4 foundational strengths. First, data gravity. As AI scales, the LLM must come to the data, not the other way around. Moving petabytes of proprietary information is a nonstarter for enterprises due to cost, security and data gravity. We are ensuring that Elastic Search remains one of the most efficient data stores for all unstructured data and more. Logs, metrics, vectors, text, audio and video. By delivering massive compression and significant ingest speed ups. We provide the price, scalability and speed that make us the data store of choice.
We recently introduced Cross Project Search, which brings cross-cluster search to serverless. In large enterprises where data is scattered across teams and regions, we eliminate the need for costly centralization by allowing users to query disparate projects where they live.
Second, context, and LLM is only as powerful as the context it is given. We have built and are constantly evolving one of the world's best context platforms for AI. We are reducing costs while improving the relevance of AI through hybrid search first-party models like our Jina V5 omni family for multimodal search and our Agent Builder now in general availability. This ensures that enterprise AI is grounded in real-time business reality.
In a recent blog, we compared agent performance using Elastic as a context layer versus an LLM interacting with the data directly. We saw a 70% reduction on tokens used and the ability to answer questions more accurately than with naive rag alone. We are widening our competitive moat with third-party data connectors that allow our search APIs to pull real-time context from systems like Slack and Google Drive without the need for indexing or crawling, enabling 0 friction retriever across the entire enterprise stack.
Third, specialized agents. Traditional absorbability and security practices are evolving into the agentic SRE and agentic SOC. We were one of the first to embed AI and agents into our observability and security products, and we have now automated the entire life cycle from detection to analysis and remediation. These security and observability agents and skills are designed to be embeddable in any AI tool, whether our customers use Anthropic, OpenAI or Gemini with Elastic serving as the data layer behind the automation.
We also launched the industry's first MCP apps for security and observability, embedding interactive domain-specific workflows directly into tools like Claude, VS Code and Github Copilot, enabling users to investigate and triage threats wherever they work.
Fourth, platform consolidation. As the market matures, organizations are consolidating on to platforms that can leverage AI across multiple domains at a lower total cost. We believe that platforms supporting both security and observability on a single data tier will win the consolidation race. We are accelerating the consolidation trend with the relaunch of our metrics offering. Prometheus is one of the most widely used systems for metrics monitoring, especially in cloud-native environments. We now offer native support for Prometheus time series data in Elastic Search. This allows engineers to leverage their existing expertise in AI coding tools without learning a new query language. Most importantly, we are delivering this familiar experience with massive performance gains, providing storage efficiency and query speeds up to 30x faster than Prometheus.
Our customer wins in Q4 reinforce these strengths. Our data gravity advantage is winning consolidation deals in the most data-intensive environments. In a 7-figure new logo win, a global provider of financial business information is leveraging Elastic Search for its massive repository of over 2 billion documents. We successfully displaced a legacy dual vendor setup by proving that Elastic's hybrid search delivers superior relevancy for their most demanding high-volume workloads.
Our recent acquisition of Jina AI proved essential during the evaluation, providing high-quality, multilingual support across 30-plus languages. By combining these models with this BBQ to manage massive scale efficiently, the customer is reimagining the search experience for their millions of subscribers, while preparing for the next wave of AI-native products.
Our context engineering leadership is making us the essential retrieval layer for ISVs launching AI experiences for their customers. In a 7-figure expansion, a leading workplace AI software firm has established Elastic Search as the foundational retrieval engine at the heart of its enterprise offerings. By serving as the essential context layer for their agenetic pipeline, Elastic enables the delivery of grounded permission-aware insights across massive complex data sets. This partnership ensures that their AI services remain performant and secure, providing a scalable foundation for their next generation of AI-driven products.
Our specialized agents are driving the largest platform consolidations we've ever seen. We secured a key 8-figure win this quarter where we are redefining the modern SOC experience. A Fortune 50 global financial services firm is modernizing their security operations by consolidating their disparate cyber data silos into a unified AI-driven SIEM. By migrating mission-critical workloads from an incumbent to Elastic, the firm is leveraging our platform to dramatically improve data retention and accessibility while optimizing their long-term infrastructure costs. Additionally, their cyber incident response teams will be deploying our AI-driven capabilities, including attack discovery and AI assistant to proactively mitigate threats and realize significant productivity savings.
By leaning into our 4 foundational strengths, we are setting ourselves up to be an enduring part of the infrastructure for the AI-driven future.
Finally, as a company, we've always focused on building a strong and durable business while continuing to innovate for our customers. As AI transforms how work gets done across every function, we are evolving how we operate internally to accelerate innovation, increase capacity through automation and move faster as a company. As we evolve the organization to better align our teams with working in an age of AI automation, we expect to simplify how we operate, reduce operational complexity and scale even more effectively as our business grows. As such, we expect to expand our operating margin meaningfully in FY '27. Navam will address this topic in more detail. Importantly, these changes do not slow down the growth in our sales capacity and our ability to capture the opportunity for growth acceleration ahead of us. While the structure of our organization will evolve, we will expect to grow our total head count on a net basis this fiscal year.
These organizational changes support our continued top line growth momentum and ability to scale effectively as we grow, and we remain on track to deliver our midterm growth targets. Strong sales performance throughout FY '26 with accelerating CRPO has set us up to accelerate our quarterly revenue growth trajectory in FY '27. The continuous innovation across Elastic and the increasing adoption of AI reinforced my confidence in our future. We entered the new fiscal year energized and are ready to drive our momentum forward.
I want to thank our customers and partners for their trust, our shareholders for their partnership and our employees for their dedication. With that, I will turn the call over to Navam to review our financial results in more detail.
Thank you, Ash. I am also incredibly proud of the team's FY '26 performance. Not only did we beat our guidance throughout the entire year, but importantly, we laid the foundation for revenue acceleration in FY '27 by growing customer commitments in FY '26 as evidenced by our growth in both CRPO and RPO over the course of the year. Our sales-led subscription revenue continues to be durable, and we've consistently delivered strong growth, including a 20% growth rate in FY '26.
Our total revenue for the fourth quarter was $451 million, growing approximately 16% as reported and 14% on a constant currency basis. Sales-led subscription revenue in the fourth quarter was $375 million, representing growth of 19% as reported and 16% on a constant currency basis. We saw another quarter of strong customer commitments alongside stable consumption patterns, a direct outcome of our sales strategy focusing on high potential mid-market and strategic enterprise customers.
Our sales team continues to meet customers where they are in terms of deployment preferences, be it self-managed or cloud. Each quarter will show some variability in cloud customer preferences between self-managed and cloud and those variances impact in-quarter revenue. This quarter, our sales team delivered a significantly larger mix of cloud commitments compared to historical patterns, partially driven by the U.S. public sector agencies increasingly adopting CISA SIEM as a Service. We anticipate U.S. public sector cloud momentum will continue in FY '27.
The variability in cloud commitment mix is important to keep in mind in the context of our revenues reported here in Q4. As you may recall, revenue from cloud commitments ramp over the course of the year, whereas self-managed commitments have a portion of revenue recognized upfront when the license is delivered with the remainder recognized ratably over the subscription term.
The sustained strength in customer commitments is now visible in our accelerating constant currency CRPO. In Q4, we grew CRPO to $1.2 billion which was 20% growth, both as reported and on a constant currency basis as compared to 15% on a constant currency basis in Q3 FY '26. The acceleration in our CRPO is a direct result of customers increasing their commitments of search, security and observability solutions. The acceleration of CRPO is also what gives us confidence in our expected revenue acceleration over the next 12 months as increasing commitment volumes accelerates constant currency CRPO and constant currency revenue in that order.
While there continues to be noise and questions in the market regarding AI's impact on software, there is clarity among our customers with respect to Elastic being an essential long-term component in their AI infrastructure. This sentiment is reflected in their multiyear commitments. These multiyear commitments are visible in our Q4 remaining performance obligations, or RPO. In Q4, our RPO accelerated to $1.98 billion, growing 28% as reported and 27.4% in constant currency. This was an exceptional quarter for multiyear commitments, driving our highest year-over-year growth in total RPO over the last 4 years.
If you look at RPO beyond the 12-month horizon, the strength of our long-term positioning becomes even clearer. Our noncurrent RPO, which represents RPO less our current RPO, or the portion of RPO that will be recognized beyond 12 months, grew 43% year-over-year in Q4. The noncurrent RPO has been progressively improving over the last year. This increase underscores a deepening of customer relationships as they increasingly execute contracts with multiyear commitments. We secured these multiyear commitments without any material change in our discount practices, underscoring the genuine customer commitment to our products and its associated value.
We also saw continued deal momentum with higher-value customers. Customers with more than $1 million of ACV grew approximately 14%, where we added more than 30 net new customers this year. We are particularly pleased with the growth of our greater than $5 million in ACV customers, which grew 30% as we continue to see strong expansion among our customer base.
Turning to margins and profitability, I will discuss all measures on a non-GAAP basis. We successfully expanded our sales capacity to capture the AI opportunity while simultaneously improving margins across the board. We continue to demonstrate the efficiency of our underlying model by balancing these strategic investments with discipline.
During the quarter, we exceeded our guidance and delivered an operating margin of 14.8%. For the full year, we delivered over 120 basis points of operating margin expansion, finishing at 16.4%. Note that this quarter, our GAAP net income was impacted by a valuation allowance release against the Netherlands, U.K. and certain U.S. state-deferred tax assets. The release created a onetime benefit of $435 million to our GAAP net income. This did not impact any of our operating results, non-GAAP diluted earnings per share, adjusted free cash flow or cash and cash equivalents. We maintained a strong adjusted free cash flow margin of approximately 20% in FY '26. Together, our FY '26 adjusted free cash flow margin and total revenue growth is 37% and well on the way to reaching our midterm target of Rule of 40, an important milestone that validates our strategy of driving durable growth and compounding value for our shareholders.
We also continue to make significant progress on the $500 million share repurchase program that we announced in October. During the fourth quarter, we returned approximately $40 million to shareholders, representing purchases of approximately 650,000 shares. As of the end of the fiscal year, we have used approximately 68% of our $500 million authorized amount, putting us ahead of our goal of using half of the authorized amount in FY '26. Since the beginning of our repurchase program in October, we have repurchased approximately 4.4 million shares. As I discussed at our Financial Analyst Day in October, our current capital allocation strategy is to return 50% of our free cash flow through share repurchases, unless we have attractive acquisition opportunities that require us to use cash.
Looking ahead to FY '27. We closed FY '26 with a foundation that positions us to accelerate revenue growth while expanding profitability throughout FY '27. Our Q4 CRPO reflects the significant buildup of committed backlog that will fuel our next phase of revenue growth. We expect both revenue and sales-led subscription revenue to build momentum throughout the year with Q1 showing the lowest quarterly growth and Q4 showing the highest quarterly growth. This growth comes from 2 specific drivers, namely CRPO, which turns into recognized revenue through the year, as well as increasing ramp sales capacity, which drives new commitments. The high-value commitments that we secured in FY '26 will drive acceleration throughout FY '27 as reflected in our constant currency revenue and sales-led subscription revenue guidance.
With these assumptions in mind, for the first quarter of FY '27, we expect total revenue in the range of $469 million to $470 million, representing 13.1% year-over-year growth at the midpoint or 12.8% year-over-year constant currency growth at the midpoint. We expect sales-led subscription revenue in the range of $392 million to $393 million, representing 15.9% growth at the midpoint or 15.6% in constant currency growth at the midpoint. We expect non-GAAP operating margin for the first quarter of fiscal '27 to be approximately 14%. We expect non-GAAP diluted earnings per share in the range of $0.57 to $0.59, using between 106 million and 107 million diluted weighted average ordinary shares outstanding. For FY '27, we expect total revenue in the range of $1.985 billion to $2 billion, representing 14.6% year-over-year growth at the midpoint or 14.5% year-over-year constant currency growth at the midpoint. We expect sales-led subscription revenue in the range of $1.673 billion to $1.688 billion, representing 16.9% year-over-year growth at the midpoint or 16.8% year-over-year constant currency growth at the midpoint. We expect non-GAAP operating margin for fiscal '27 to be approximately 19%. We expect non-GAAP diluted earnings per share in the range of $3.21 to $3.29, using between 107.5 million and 108.5 million diluted weighted average ordinary shares outstanding.
Regarding cash flow, we expect to increase our adjusted free cash flow margins to 21.5% in fiscal '27 excluding any acquisitions or any other onetime charges. Our level of cash generation, combined with our planned revenue acceleration, keeps us firmly on track to exceed Rule of 40 by FY '29.
As Ash mentioned, just as we drive AI innovation for our customers, we are using AI to transform how we work across all functions. We are beginning to see productivity gains from AI, which will evolve the structure of our organization and allow us to expand our operating margins. In FY '27, we are expanding our operating margins approximately 2.5 percentage points. Furthermore, we are raising our medium-term FY '29 non-GAAP operating margin target from more than 20% to approximately 25% with associated improvement in our Rule of 40. These targets are now well ahead of our prior financial Analyst Day targets. We still expect to grow our head count on a net basis this year, continuing to invest in our growth. We remain on track to achieve our medium-term sales-led subscription revenue growth target of 20% plus in FY '29.
In summary, we have seen markedly improved sales execution in FY '26, and we're seeing more sales capacity come online, driving improving commitments and accelerating CRPO. The dynamic of commitments and CRPO improving gives us confidence in our ability to accelerate revenue growth and drive further margin expansion in the future. Thank you for your continued support and for joining us today. And with that, I'll open it up for Q&A.
We will now begin the question-answer session. [Operator Instructions] Our first question today comes from Rob Owens with Piper Sandler.
2. Question Answer
Great. With the success you guys are seeing from a booking standpoint when we look at CRPO and RPS specifically, what do you think is the unlock with customers? Is it just maturation relative to where people are in their AI journey? Do you think that there's something from a product standpoint that's really driven this unlock?
And then as a second question, you mentioned the CISA SIEM as a Service, just to over acronym it a little bit. But where you're seeing success in the federal government, have you been able to affect that in the commercial markets as well?
Rob, thank you very much for the question. Yes. So let me answer each in turn. So if you think about our platform, the way our customers are leveraging it is in a few different ways. So first is a data store just to build applications, the new AI applications that are being built, we are increasingly being used as a data store. And really what matters there is just the fact that we have an incredibly efficient platform, that's driving a lot of momentum for everything that we're doing around AI. We are seeing more and more customers choose us for that reason.
The second reason is clearly because we are really strong at context. Whenever you're building AI applications, you need the right kind of context in real time, all the investments that we've made in our vector database, in our Jina models, in Agent Builder, which is now generally available. That is also driving a lot of momentum for us as AI is becoming more and more widely adopted within organizations.
And lastly, it's in the agents that we have built. The specialized agents for AI SRE, for observability and AI SoC, for security, the skills that we have built that can be in worked from Claude Code or Github Copilot or wherever you work from, and that is really driving a lot of automation for our customers, and that's driving more and more of these observability and security wins for us. That's allowing us to consolidate more workloads onto our platform and get bigger commitments, more longer-term commitments because it's making us more entrenched into the overall AI infrastructure stack within our customer base.
The second part of your question about CISA and the SIEM as a Service. To the point that you made, we are seeing tremendous success there. Matter of fact, if you remember a couple of quarters ago, we had announced that, that deal was basically a $26 million deal commitment over a 12-month period. They've already exceeded that as more and more civilian agencies are coming on to our platform, and that's all on Elastic Cloud, which is great. As those ramp, that's going to translate into revenue traction, and that's what Navam was mentioning.
And by the way, we are seeing that same kind of unlock in commercial organizations as well. Even in my prepared remarks, I talked about the Fortune 50 global bank that has chosen us as their SecOps platform. They did that not only because we have the most efficient platform and cost and price efficiency becomes really, really important as you're bringing on more and more data, but also because of the AI capabilities that I mentioned. Their incident response team really liked the capabilities like attack discovery and all these AI SOC skills that we have built. So we are seeing that unlock. We are displacing incumbents in more and more places. I feel that we're just getting started. So this, to me, is the momentum starting to build and you're seeing it in CRPO. We expect to see that drive our revenue momentum in the next 12 months.
The next question is from Matt Hedberg with RBC Capital Markets.
It was great to see CRPO growth accelerate. I think it was 500 basis points to 20%. I was looking at your fiscal '27 guidance for subscription-led sales growth. It looks like about 16.8% on a constant currency basis. That is a slight deceleration versus, I think, the 18% you reported this past year. So my question is, how should we think about CRPO growing 20% really as a leading indicator? And could that accelerate your path to the 20% sales subscription growth target you had?
Yes, absolutely. I mean, first of all, I think that what you're seeing is that our products are resonating with the customers, and that's driving commitments. And that's the underlying cause of the CRPO and also RPO acceleration and all of that turn into revenue into the next year. And second, we're going into the year with more sales capacity than in '26. So what you're seeing on a sales-led subscription comparison is basically an accelerating trajectory for both revenue and sales-led revenue from the Q1 guide number progressively upward to the Q4 quarterly revenue growth number as you play that out to reach that annual target number that we gave you.
And to your second question of does that put you on track to the 20% growth target, absolutely, we feel good about the midterm targets and continuing to accelerate from the fourth quarter exit growth rate to the 20% number that we've laid out as the long term or the midterm target. Sorry.
Got it. And maybe just a quick follow-up. Are there any significant or meaningful or noteworthy go-to-market changes that you expect for this year? I know you've had those in the past. I just want to kind of understand that dynamic as we go into [ the year. ]
Yes. No, let me be very clear on this. So the changes that we made about 8 quarters ago have settled in very nicely. Like you've seen through this entire past year, really strong sales execution. It's only getting better. You can see it in our CRPO and RPO numbers. We are very happy with the way our go-to-market engine is working and the way it's structured. So we plan to make no changes this year, just add more sales capacity. And that's something that we feel really good about, and that's going to be part of what drives our future growth.
Next question is from Miller Jump with Truist Securities.
Great. I wanted to come back to the internal evolution that you called out in some of the reduced operational complexity. Can you give more detail specifically on what segments are seeing the most productivity gains from AI right now? And where are you going to be leaning in on hiring for that net headcount add?
Yes. So what I'd say is that when we look at different functions, pretty much every function is taking advantage of AI-led automation. And you're seeing this -- you're hearing about this in the industry. We are building a platform that's helping our customers do these kinds of things, and we're doing the same thing internally. Everything from our engineering teams using coding platforms for improving their pace of co-development to our marketing teams using AI capabilities for marketing automation, our sales onboarding and enablement, our employee onboarding, within finance for doing financial analysis, we are leveraging AI across the board.
Now there are various functions such as in sales, enterprise selling is still a task that requires pretty significant interpersonal attractions. And so in areas like sales and our sales capacity in our sellers, we expect to keep adding headcount meaningfully through this year. But then in other functions, there might be -- the way we scale in the past is going to be different from how we scale going forward. And so the number of people that we might need to continue scaling and growing the business might be slightly different than what we might have needed in the past.
So those are the kinds of adjustments. But I want to be very, very clear when it comes to our selling capacity, we do expect that, that's an area that's going to continue to grow. And net, like I mentioned, like Navam mentioned, that we expect to be net employee headcount positive as we go through FY '27.
Yes, that makes a lot of sense. If I could just squeeze in a follow-up for Navam. The enterprise success sounds really encouraging, but it does look like there was a little bit of churn in the monthly cloud business. So can you just talk about the dynamics you're seeing in enterprise versus SMB? And what are your expectations kind of for the year ahead across those segments?
Yes. Sales-led subscription revenue and -- tends to be the area that we're most focused on, and that's where the sales team is focused on. So when you think about the growth and the success and the commitments we're seeing there, you're seeing the results of that in the commitment volume we have built in the CRPO and the RPO numbers.
Monthly Elastic Cloud this past quarter grew 3%, which is in line with what we've been thinking about and in line with what we've been modeling. We've always assumed that this is going to be a flattish business driven by smaller customer and SMB dynamics, and these are self-serve motion SMB customers, which tend to be more -- less of a focus area for us. So we exclude monthly from our core sales-led subscription business, the annual cloud business grew very well at 26%. So that's sort of the dynamics you're seeing of roughly a flat monthly cloud business or slightly above last quarter and a nicely growing sales-led subscription and annual cloud business.
The next question is from Kingsley Crane with Canaccord.
One for me. So I was encouraged by this Omni V5 release. I think big picture, there's been a lot of talk about multimodal model kind of a few quarters ago in some of the frontier labs have pulled back from focusing on multimodal. So I'm curious what kind of demand signals for Omni you're seeing in your customers right now? And then when an existing text customer swaps in Omni start sectorizing video? Audio? How could that affect usage on the platform?
Yes. Thanks for the question. So we are very excited about the omni models. So keep in mind that these are embedding models. And embedding and reranking models, that's where we focus as opposed to language models for generation. But in these models, as you can imagine, there is so much information out there that is multimodal in nature. You have PDFs that have graphs and charts in them. You have audio and video where you might -- in video, there might be specific images that you want to extract from it. There's a lot that effectively is multimodal just by nature.
This effectively opens the aperture for us. It increases the total TAM of the opportunities where we can go after taking that data, vectorizing it and then allowing people to do all kinds of search and analysis against it. So it's not necessarily that it drives -- that it consumes more compute. These are very efficient models, but it just allows us to bring more workloads into the picture for customers to use the Elastic platform for. So that's part of what's driving that excitement for us.
The next question is from Brian Essex with JPMorgan.
This is Alex on for Brian. I wanted to ask about around the FY '29 framework that you laid out and reaffirmed. In terms of exiting FY '27 around -- FY '27, around 17%, how do we think about the bridge from there to the 20% plus growth in '29? And how do we think about where we should be exiting '27 into '28?
Yes. So we've laid out the guidance number on a constant currency basis, which I'd encourage you to take a look at. So when you think about where the Q1 number -- Q1 guidance number is for FY '27, and where the full year guidance is, mathematically, it's a step up. It's an implied step up, which we also talked about during our prepared remarks from Q1 to Q4. So you see an accelerating growth trajectory both for sales-led subscription revenue and total revenue with Q1 being the lowest growth number and Q4 being the highest growth number from a constant currency perspective. So that Q4 number is going to be higher than the average growth or the full year growth that we've guided to. And that's the exit value that you go into FY '28 with. And the confidence we have going into '27 again is around the commitments that we have that turn into revenue, and that's the coverage of revenue that we already have through CRPO. And we're entering the year with, frankly, an adequately large number of ramped reps who have been ramping across 2026, and they are going to continue to add commitments in the same way that they added commitments in FY '26. So both those dynamics are going to continue towards '26 to '27, building the constant currency growth rate from Q1 to Q4, and that dynamic continues into next year as well, right? We are continuing to add sellers, and we will continue to add commitments. And that's the buildup to the 20%-plus sales-led subscription revenue midterm target that we've laid out. And all the activity in '26 is just validating that progression through '26 into '27 and to the midterm. So we feel good about the setup in '27 and look forward to updating you as we go along.
Okay. And then just a quick follow-up on the AI attached side, especially around the 100,000 plus customers, how does the spend profile look on the AI attached customers relative to non-AI customers? And which of the AI products are you seeing the most traction or adoption, especially over the past, let's say, year-to-date as AI models have really accelerated in their ability to act agentively.
Yes. So this is Ash. Maybe let me answer that one. So as I mentioned in our prepared remarks, we now have, in our 100,000 ACV customer cohort, 600 customers that are using us for AI use cases. And that is a really nice acceleration that we've seen there. That also includes about 40 customers from serverless that we are counting now. Our services continues to grow in traction, and we are seeing customers come on to that and use us for AI use cases as well. And we are seeing AI being used across the board. As we get used as a vector database, we are seeing AI getting used as Elastic being used as a context platform for building agents, using Agent Builder and so on as well as our AI SRE and AI SOC capabilities in our observability and security platform.
So we are seeing benefit across all 3 solutions when it comes to AI. And that cohort, the AI users within our 100,000 cohort, like that cohort continues to grow at a faster clip, expanded a faster clip than other cohorts. Like we had mentioned in our financial analyst day, that cohort is growing at roughly 5% -- a little over 5% faster than the rest of the cohorts, and that trend is continuing. So as more of the 100,000 cohort adopts us for AI, we expect that, that's going to be a continuing and increasing tailwind for our business overall.
The next question is from Koji Ikeda with Bank of America Securities.
This is George McGreen on for Koji Ikeda. I wanted to ask -- really great to see the acceleration in constant currency CRPO growth and RPO growth as well. Could you kind of maybe qualitatively kind of give some color on between search, observability and security? What is seeing, like, the most uptick? And then as it relates to RPO growth in conversations with customers, how are they kind of sounding now about viewing Elastic more strategically and in a longer-term road map for their own use cases?
Yes. Thanks for the question. And just in terms of the solution mix, we saw growth across all 3 solutions. Our search and AI continues to be a very strong grower. In Q4, security was outstanding in terms of growth. So both of those are sort of leading the charge, but we are seeing growth across all 3 segments.
When it comes to the pattern that we see with customers, look, we have evolved our security and observability solution over the last several years to a point where we are considered to be a strong leader in the categories that we play in. In observability, we lead with log analytics and then we expand from there. We just recently announced our metrics, our new metrics offering, which I'm very, very excited about. It's one of the most efficient metrics platforms out there.
So in the coming year, I expect that, that will also contribute. But we are, in observability, seeing strength; in security, we are displacing incumbents in so many places. I talked about the SIEM as a Service, which is seeing a lot of success in government. I gave the example of the Fortune 50 bank.
As we are maturing and getting stronger and being seen as one of the best leaders out there, because of the efficiency of our offering, because of our AI functionality that is very differentiated, we are seeing our customers making bigger bets. We are seeing them make longer-term bets, and that is something that basically is a signal to us that they see us as, someday, as a partner that they're going to depend on for many years to come. And that's the foundation of our continued growth. So very excited about that, and it's across the board. It's across all regions, which is also what is very satisfying.
The next question is from Howard Ma with Guggenheim Securities.
This is Joe DiBartolomeo on for Howard. So just in terms of the sales-led fiscal '27 guide, is it fair to assume that within that constant currency number, about 500 basis points is from AI contribution, which would be in line with your long-term guidance? And just how can that number drive upside throughout the year?
Yes. So the 500 basis points of acceleration from customers using our AI features and AI products continues to be the case, both in '26 and '27. So what's happening is more of our customers are using our AI features that's driving that tailwind to be across a broader set of customers. So I wouldn't say that it's just the guidance number, minus 500. It's just a growing proportion of our customers are now consuming at a faster rate because of the AI features that where -- they're using on our platform. So that's the way I would think about it.
We're seeing a very nice steady uptick of 100,000 customers that are using our Gen AI features. We've been disclosing that every quarter, and that's been progressively moving up. So that's going according to how we would expect and driving more acceleration across the entirety of our customer base over time.
Got it. And just a quick follow-up, if I may. Are you guys factoring in any meaningful contribution from new products and features in fiscal '27? And just in particular, how big of an expansion opportunity is your revamped metrics engine among existing customers?
Yes. So I'll talk about the metrics piece and then I'll ask Navam to weigh on how the guide has been constructed. But on the metrics piece, look, the way I think about it is, if I just look at the technology that we have built, the metrics back in store that we've built, it's highly, highly optimized for time-series data for metrics. And as we benchmarked it against the leaders out there, we find that our solution can not only stand up to outperform just about anybody in terms of efficiency, in terms of ingest performance and inquiry performance. So I'm really excited about the opportunity there.
As you know, our go-to-market motion has always been a land-and-expand motion. So it's highly likely that we are going to start by expanding metrics uses in our existing log analytics customers that will probably be the fastest route to market for us. But over time, as you can imagine, we would anticipate that we will start to lead with metrics as well.
So it's a big opportunity. Infrastructure monitoring and metrics is a meaningful and large part of the overall observability market that we haven't had much of a presence in. So it is TAM expensive for us and something that excites me.
On the guidance side, it's the organic growth given the product set that we have to sell to our customers. It's not assuming any new products, it's not assuming any acquisitions. So that's the way I would think about the guide, and it's just looking at what we already have to sell to our customers.
The next question is from Raimo Lenschow with Barclays.
This is on for Raimo. Navam, can you help us understand how much of the back half acceleration is driven by execution of increased ramp sales capacity? And how much of it is driven by CRPO or expected near-term closed deals? Just trying to understand the conservatism embedded in the guide? And then maybe how much might require solid execution from ramp sales reps.
Yes. I'll start with the guidance side first and then go to the next question. Philosophically, what I'm giving you, I'm focused on giving you is a credible projection based on what I'm seeing today with the appropriate risk adjustment added to it. And there's the risk adjustment related to consumption related to FX related to timing of large deals and mix and all of those are embedded in there as we provide the guide.
As I said before, I feel good about the setup for '27 given the commitment improvements we've seen in '26. So how you should think about it is we have a CRPO number, which is going to be recognized over the next 12 months, and that's the coverage of the revenue that you have from existing commitments that are just going to be recognized. The cloud commitments in Q4, for example, will be more tail-end weighted and self-managed will be more ratably -- ratable upfront.
So the back half acceleration, as I said, is a combination of 2 things. It's your existing commitments ramping and consuming against the commitment volume that they've already committed to; and second is increasing number of reps that are becoming ramped and are contributing. So that said -- and the coverage amount on the sales-led subscription side is approximately 70%.
So the sales capacity increase going into the year is one of the highest we've had compared to historical periods from a growth perspective. But sales execution is tail end weighted because the largest quarters are in Q4. So it's a combination of both coming from both the existing commitments that we've had and the commitments we're getting in the next few quarters.
Right. If I could just squeeze in one more. Just thinking about last year's pricing adjustment, are there any anticipated pricing or packaging changes that might be embedded in this year's guide?
Yes. So from a price increase perspective, we've always been adding new features and improving performance of our platform. Given the changes we've made in FY '26, we felt confident to relook at our prices again. So we did a 3% increase for cloud and a 5% increase for self-managed. And we make these decisions based on the new features and capabilities we add and the product is also becoming more efficient that allow customers to reduce cost as well to make Elastic a more efficient place to put in their data.
So that's sort of the puts and takes of pricing for usage-based models like ours. What matters most, and we've said this before, is the net consumption trend over a period of time. In any given quarter, we expect to see the benefit of more consumption pricing, and that's offset by optimization and efficiencies that are customers do on a quarterly basis and because of the new product features that we've added to our platform in the past year. So the price increases that we do don't necessarily change revenue in a perfectly correlated way in the same way that a seat-based pricing model works, for example.
So the underlying usage model -- the underlying usage trend remains strong, and we've guided Q1 appropriately given that usage trend. Since this price rate is smaller than what it was last year, we don't expect it to be meaningful on a year-over-year basis when you think about comparisons.
Next question is from Mike Cikos with Needham & Company.
This is Matt Calitri on for Mike Cikos over at Needham. What assumptions are you baking into the fiscal '27 guide around U.S. federal contribution? And is there any way to think about the expected impact from the CISA contract or the FedRAMP authorization?
Yes, I'll start with the U.S. public sector and the federal business. It remains a strong business, and we continue to expect that business to be strong in '27 as well in the way it was performing in '26. So nothing specifically different about the relative performance of the public sector in '27 was assumed in the business. But we're very pleased with the way the system as a service platform has been adopted through civilian agencies. And as Ash mentioned, against that total commitment number, we're continuing to see more and more agencies added and consuming against those commitments. So we're very pleased about that performance.
Very helpful. And then curious as to what you're seeing regarding cohort expansion rates like are newer customers growing as quickly as customers that you landed say, 6 to 8 years ago, did over the first 2 years and are older cohorts of customers continuing to expand. Anything you can give on the dynamics of just different [ errors ] of customers, so to speak?
Yes. So the base cohorts continue to be expanding very nicely because of -- as Ash mentioned, the normal trajectory is it's a land -- land upsell, cross-sell motion. So that upsell cross-sell continues to run as a machine internally with our sales team, and you're seeing those cohorts expand year-over-year as commitments increase and then more features and products are added and more commitments happen and then you also add your second or third solutions with -- against the initial solution that you adopted. So that machine is driving nicely on the core land expand motion.
What's increasing is obviously the tailwind related to AI. So insofar as a customer is an AI -- is using more of our AI features, you see that additional benefit of faster growth with those customers. And we detailed some of that during our Financial Analyst Day.
The next question is from Sanjit Singh with Morgan Stanley.
This is Jamie on for Sanjit. Could you just comment on how you view the [ Splunk ] displacement opportunity today? And to what extent that could be an upside catalyst for this year relative to the guidance?
Yes. Let me answer that. So the opportunity to displace incumbents, there are several of them that we are seeing our sales teams displaced. There are -- these are big markets. When you look at the overall SecOps SIEM area, these are large markets, and there are lots of interesting things happening because of the base of attacks increasing significantly and the sophistication increasing significantly, customers are looking for modern platforms that leverage AI effectively sitting on a data store that is efficient so all the data that needs to be brought in and analyzed can be done at a reasonable cost. And we are exactly that answer. So we are seeing a lot of success in displacing these incumbents and you're seeing those in our CRPO numbers. And like Navam and I have said, I'll expect to see those show up in our revenue acceleration over the next 12 months. And even beyond that because the market share that these incumbents have is still meaningful. And I believe that this is going to be an opportunity that allows us to continue to accelerate over several years.
The next question is from Matthew Martino with Goldman Sachs.
Ash, maybe just on MCP, you've leaned into making Elastic easy for agents to reach through standards like MCP. You launched MCP apps recently. As more agents pull data that way, like how big of a distribution and growth vector do you think that can become? And does that -- does being that agent accessible or retrieval layer turn into a durable advantage over time? Or do you see this as sort of table stakes moving forward?
I think it's going to be a durable advantage, especially because we are able to not just provide access to data, but we are able to provide smart access to data. And what I mean by that is when you bring data into Elastic, we build very smart indices that allow you to understand exactly what you need and get that information from within our systems very, very quickly. We are adding capabilities that allow you to do that in a distributed and federated manner. So you don't have to move your data into a central location. So there's a lot of smart and sophistication that we are adding. We recently published a blog that showed how you can reduce the token usage cost by 70% by precomputing some of the context that you need for retrieval as opposed to using sort of naive retrieval augmented generation or RAG techniques. And that's exactly why the advantage that we have, I believe, is so durable and is only going to continue to grow because data volumes are growing. As more agents are being built, the need for not just speed, but cost management is going to be incredibly important. And to do this in a way that's predictable, that is cheap, that gives you sort of answers that are accurate is going to be the need. And that's exactly what we do very well.
I really appreciate it. All the color there. Navam, I know in the past, you've disclosed the AI customers are growing several points faster. And I presume a lot of that initial momentum likely came from the search side. But curious whether you're starting to see that AI growth really broaden out with some of the newer AI features you've brought to market on the security and observability side.
Yes. I'd say that a lot of the initial growth specifically that 5% growth momentum that we referred to during Financial Analyst Day, including what's continuing on right now comes from mostly Search. But as you mentioned, there's newer AI products that have been penetrating that have been going across security and also observability. So you're seeing the benefits of that across the board. But I'd say the predominant -- numerically, what we've disclosed was predominantly the search side, but we're beginning to see momentum in security, particularly the selections are because of the AI feature set that we have in the product.
The next question will be from Robert Galvin with Stifel.
I had a follow-up on the go-to-market strategy for FY '27. A key theme we've been hearing from some other infrastructure peers is that AI selling motion skew much more technical as AI use cases and pipelines built at Elastic. Are you seeing a similar need for more technical sales teams? And if so, do you have the right team in place? Or do you need to change your sales or hiring profile in FY '27?
Yes, that's a great question. So AI buyers are reasonably technical. But here's the thing. Elastic, our platform, has always been a technical sale. We sell to development teams that are trying to build all kinds of search applications. We sell to infrastructure engineering teams that are building observability solutions. We sell to security operations and security specialists in the CISO office that are building SecOps solutions. So we have had a DNA ever since the foundation of the company, not just to build a platform that is really optimized for these kinds of use cases for use by technical developers, but also a go-to-market motion and a selling motion that knows how to target these buyers and sell effectively to them. So the AI motion is very natural for our teams. We do have a small specialist team that has been focusing on how to really help our customers get these AI applications off the ground, but it's a relatively small team, and it sort of acts as a set of advisers across our broader field. And we are seeing a lot of success with it, as you can see from the commitments.
This concludes our question-and-answer session. I would like to turn the conference back over to Ash Kulkarni for any closing remarks.
Thank you all for joining us today. We are entering FY '27 energized and ready to drive our momentum forward. The continuous innovation across our platform and the increasing adoption of AI gives us great confidence in our future. Thank you.
The conference has now concluded. Thank you for attending today's presentation. You may now disconnect.
Elastic NV — Q4 2026 Earnings Call
Elastic NV — Q4 2026 Earnings Call
Elastic beat guidance with accelerating multiyear cloud commitments driven by AI adoption, while raising margin targets for FY'27 and FY'29.
📊 Quarter at a Glance
- Total revenue: $451M (+16% YoY reported; +14% constant currency)
- Sales-led subscription: $375M (+19% YoY reported; +16% constant currency)
- CRPO: $1.2B (Committed Remaining Performance Obligations; +20% YoY)
- RPO: $1.98B (Remaining Performance Obligations; +28% YoY; noncurrent RPO +43%)
- Margins & cash: Q4 non-GAAP operating margin 14.8%; FY'26 non-GAAP operating margin 16.4%; adjusted free cash flow margin ~20%
🎯 What Management Says
- AI as core: Elastic frames its search/ingest platform as the context layer for AI and says >600 customers with Annual Contract Value (ACV) >$100k use its AI capabilities, producing larger multiyear deals.
- Four strengths: data gravity (keep data local for large language models (LLMs)), context (vectors, Jina models, Agent Builder), specialized agents (AI SRE/SOC), and platform consolidation (logs, metrics, vectors) to win large deals.
- Operate to scale: management will expand sales capacity (net headcount positive) while using AI internally to simplify operations and materially expand non-GAAP operating margin over FY'27–FY'29.
🔭 Outlook & Guidance
- Q1 FY'27: Revenue $469–470M (~13.1% YoY midpoint); sales-led subscription $392–393M (~15.9%); non-GAAP operating margin ~14%; EPS $0.57–0.59.
- FY'27: Revenue $1.985–2.0B (~14.6% YoY midpoint); sales-led subscription $1.673–1.688B (~16.9%); non-GAAP operating margin ~19%; EPS $3.21–3.29; adjusted free cash flow margin ~21.5% (excludes acquisitions/onetime charges).
- Medium-term: Raised FY'29 non-GAAP operating margin target to ~25% and expects to exceed Rule of 40 (growth + free‑cash‑flow margin) by FY'29.
❓ Analyst Q&A
- Bookings drivers: Management attributes CRPO acceleration to AI demand (context, vectors, models), agent automation and product improvements rather than major price concessions.
- Public sector & displacement: CISA SIEM as a Service is driving cloud commitments in federal agencies; similar displacement of incumbents seen in large commercial deals (examples cited).
- GTM execution: No material go‑to‑market overhaul planned; growth relies on a larger ramping sales force plus CRPO coverage; monthly self‑serve cloud remains relatively flat while annual cloud expands.
⚡ Bottom Line
Elastic delivered beat-and-raise dynamics: strong bookings and multiyear commitments give near-term revenue visibility and justify FY'27 revenue acceleration and margin expansion. Key execution risks are cloud vs self-managed mix volatility and successful ramping of added sales capacity. Share buybacks continue.
Elastic NV — Morgan Stanley Technology
1. Question Answer
All right. We are continuing the afternoon session at the Morgan Stanley TMT Conference day 1. Super thrilled to have the management team from Elastic join us. We have CEO, Ash Kulkarni; and Chief Financial Officer, Navam Welihinda. Ash, Navam, thank you again for joining us at the Morgan Stanley TMT Conference.
Thanks for having us.
For the quick disclosures for important research disclosures, go to www.morganstanley.com/researchdisclosures.
So with that, let's kick off the conversation. Definitely an interesting time in the market, investors debating all sorts of aspects as it relates to AI. I think people are coming back to like a first principle of level thinking when it comes to software companies. And so with that as context, as investors assess what software companies will prove durable in the AI area, can you talk today about the problems you solve and the core value proposition you deliver for customers today, Ash?
Yes. So the best way to think about Elastic and what we do is think of us as a data platform. And in the context of AI, what we are relevant for is providing the right context to large language models to be able to do their job, to be able to do the task that they're working on at the moment.
Fundamentally, the best way to think about it is most organizations, take your organization as an example, you sit on petabytes of data. And every day, you're creating fresh data that's in often petabytes, you can't move that data to a large language model. You have to bring the model to the data because it's physically impossible, it's going to be too expensive to do it otherwise.
So when you bring the model to the data, it really comes down to how do you quickly in real time, tell the model exactly what information from all of this petabytes of information that you might be sitting on is relevant to that particular question, that particular task. That's where we come in. And our core differentiation is in how we provide that specific data relevance, that specific data context, depending on the question that's being asked. And that's how we get used in all the AI use cases today.
That's a great start to the conversation. You guys reported earnings last week. So let's go through some of the highlights from earnings and talk through any of the debates coming out of the quarter. So you put in a strong set of results last week. Sales-led subscription revenue growth accelerated to 19%, I think, from 17% in the prior quarter.
Ash, can you walk us through the highlights and Navam, feel free to chip in. What is the market missing when it comes to last quarter's results?
So like you said, strong sales-led subscription revenue, operating income was again strong. What we also talked about on the call was we had a record number of million dollar deals. So all the go-to-market changes that we made about 7 quarters ago are really paying off. We kind of segmented our sales teams into hunting territories and then forming territories. That segregation is really helping in terms of signing more strategic deals, growing our business.
In terms of AI adoption, that has been, again, very strong for us in the cohort of 100,000 customers, which is responsible for the bulk of our revenue as a company. AI adoption is growing. Now it's almost 1/4 of our 100,000 customers are using us for AI. I'd say the two questions that keep coming up, one is around cloud versus sales-led subscription revenue. I think that's a really important one for me to constantly clarify.
We are seeing more and more interest in using our platform in what we call self-managed environments where a customer takes our software and then runs it either in their own data centers or in their modern cloud environments, but in their own private VPCs. And we are seeing that grow for several reasons. One, in the U.S., in regulated industries, a lot of the AI use cases tend to be on data that's sensitive, that's proprietary. They want to keep that within their own domain, within their own control for all kinds of reasons. We are seeing more usage in government. And again, there, you have secret and top secret environments where there is no notion of a marketplace. So the only way they can deploy software is in self-managed.
And in Europe, we are seeing a growing demand for running technologies in sovereign environments as they like to describe them. And that's the last piece has been more of a trend in the last couple of quarters. And I would expect that structurally, these things will continue. And it's a huge asymmetric advantage for us because you look at our competition in security or observability or even in AI, there aren't many companies out there that can say you can get this entire platform with all of these capabilities, not just in a cloud form factor, but you can also run this in your own environment.
So I think that's an important one that we are constantly reminding our investors that look at the entirety of the business and sales-led subscription revenue, not just cloud.
And then the second thing is AI adoption. How that AI adoption, now we have 1/4 of our customers in the 100,000 cohort as more customers adopt AI and as their usage on AI continues to grow, that naturally becomes a tailwind to our business. So those are the two areas where we get the most questions where I spend my time educating people.
Yes. And to your point, I think if you looked at the other subscription line, which captures the self-managed piece, that accelerated by 3 points during the quarter.
That's right.
So the other question that I've been getting from investors since earnings, and Navam, maybe I'll address this to you. The context, again, as Ash pointed out, 30% growth in $1 million commitments, RPO up to 22%. When we looked at the Q4 guide, which is the next quarter, that implies deceleration on a sales-led subscription basis. You printed 19% constant currency, you're guiding 15%. Total revenue, you're looking for about 13%. You flagged 3 fewer days in the quarter in Q4 as one way to think about this and typical risk adjustment guide versus actual roles. Is there any other factors that investors should be considering in terms of contextualizing that Q4 guide?
No. I mean I think the big message that Ash talked about in the first question about how well our execution is going on the sales-led subscription revenue line remains the case in the third quarter. We've now got a full year number for sales-led subscription revenue as reported at 20% and constant currency at 17%. This means that this is the fourth year running that we're compounding sales-led subscription revenue at or above 20%.
On a constant currency basis, we've been 20% for the past 2 years and 18% now as guided for the full year. So we are remarkably pleased with the underlying strength that we're seeing in the business and the commitments we're driving and how consumption is going, right?
So overall, very positive in how the business is going. On the fourth quarter, we always give you a guidance number that is risk-adjusted that has prudence built into it. You mentioned fourth quarter when you're thinking about it sequentially, yes, there's 3 less days in the quarter. So you got to think about that as you think about the sequential view of how third quarter absolute revenue is compared to the -- fourth quarter absolute revenue is compared to the third quarter.
So outside of those things, we feel good about the business. We've risk-adjusted the number and give you the fourth quarter. As always, you shouldn't over-rotate on a single quarter. It's always about the trend and how the subscription revenue line continues to build and that we're feeling good about for the full year.
Awesome. That's great context. So let's get into the meat of what's the theme probably across all -- every software presentation sort of a software vendor's defensibility to perceive AI risk. When this year started Ash, like a number of investors reaching out to me, I'm glad you cover infrastructure. You don't have -- you don't cover the seat-based models or security analysts in general, like was feeling good. On the last couple of weeks, kind of everything has sort of been questioned. And so I wanted to just dive into some of the debates and get your perspective on some of the AI risk debates.
Now when it comes to Elastic, one angle that I hear is that as the cost of software and software development goes to 0, does it become easier for customers to manage open source deployments using software, using AI and AI agents to just use open source for their data platform needs, for their search use cases or for their observability use cases without having to pay Elastic. What is your argument against that line of thinking? And what would the skeptics be wrong when it comes to, hey, AI is going to make just open source deployments that much easier, we don't have to pay for the commercial proprietary offerings?
Yes. A couple of things there. So the first is our -- the way we've built our software stack, it's not just about the paid version is like we operate it and the features are the same. We have a free version that has a certain amount of capabilities and functionality in it. And then we have paid versions that have incremental functionality that tends to be much more valuable, not just in terms of what you can do with it, but also in terms of driving greater efficiency in your hardware utilization.
So there's a lot of value in those features, and that's what people pay us for. Now all of those are licensed in a certain way. So if you use those capabilities, you have to pay us. Otherwise, you're violating a license, and that's something that's enforceable.
The second thing is you talked about why wouldn't somebody just try and build this themselves and run it. The reality is you can write software using these AI tools. We use a lot of AI tools internally heavily and the usage is growing. So I'm a big fan of what you can do with some of these technologies like Cloud Code and so on. But it's a completely different matter once you've written the software to actually operationalize it, run it at scale, manage it, especially a data system.
So you talked about infrastructure software. You talk about data systems, and it's not just ours, but ours and Snowflake and others out there. Like these -- our systems, we have customers who are running literally hundreds of times thousands of nodes, like just massive deployments that they are managing. To be able to run software at that scale is a very different thing than writing code. Like there's a difference between writing and then operationalizing and managing.
And if you imagine the cost involved, the risk involved, the effort involved in all of those pieces, why would an LLM or even an LLM maker choose to go down that route when it's much easier for them to just use the system that's already in place. The data is already sitting in that system. Why -- I mean the cost equation would not make any sense for an Anthropic or an OpenAI or anybody to try and take that workload over. It would cost them more, it would cost the customer more. It would take more time. It would potentially introduce greater security risks and vulnerabilities. It just makes no sense whatsoever.
Now yes, can you build UIs easily? Absolutely. Can you build simple workflows more easily? Absolutely. But that's why I think that every software vendor is going to have to really think about what is their defensible moat. And our defensible moat is our data store, right? That's really -- and all the work that we've done in terms of relevance and context accuracy, that's really the defensible moat, which we feel very good about. And I don't think Anthropic is going to try and recreate Postgres. They're going to use Postgres. They're not going to try and recreate Elastic. They're going to use Elastic. I think that's what you're going to see more of.
Yes. And I think in my conversation, one of the things I point out is that these are tools, right? These data platforms are they're massive scale distributed oftentimes cloud systems and...
That's right. Sanjit, the way -- the analogy that I'll offer maybe and it might make sense to you or might not, but the operating system for the last 10-plus years was really the Cloud platform, right? That's where you went to -- it had all the compute infrastructure. You went there to write your applications. And even in those environments, you had data systems that you integrated with because data would sit in those systems, they were specialized for it, and you would write all your application logic on the cloud platform.
The new operating system going forward, in my opinion, is going to be these language models, these AI systems. So just as you had the Cloud platforms, you're going to have these LLMs. And these LLMs are really optimized for reasoning. They're optimized for inference. So they can do more than just deterministic development. But they are still going to need data systems to be able to store data, to be able to retrieve context for all of those reasons. So I think you're going to see that same parallel model here, and data systems are going to continue to coexist.
Can I ask you one follow-up on the point you just made. So you made the analogy of the data platforms role in the context when cloud was sort of the heart of the matter and LLMs become like the heart of the operating system. Does the role of the data platform changes in one paradigm versus the other?
I think the way you do some of these queries change, and you already have seen that, right? So we are not talking about vector databases. We're talking about -- who was talking about context engineering 5 years ago. Nobody had any idea what that even meant. Nobody was talking about relevance because all of these systems are probabilistic as opposed to deterministic. So it's not SQL anymore. It's about relevance and it's about vector queries and so on.
So yes, the role does change. It does evolve. That's what we've been working on for the last 5-plus years just on the vector database side. I think the other thing that changes is more and more, you're going to see that people are not going to build with humans only in mind. So for the last 40, 50 years, most of our applications have started with UIs and visualization layers and dashboards and reports and so on. If I have an LLM that's accessing a particular thing, it doesn't care about that being in a visual form.
So you're going to have less consoles, you're going to have more APIs. You're going to have less dashboards, you're going to have more direct access to get the raw data because the LLM knows how to process it. So there is a real shift that's going to happen. That's something that we care about. That's something that we've been working on. I think all software platforms are going to need to evolve in that way, but they are going to coexist.
Yes. No, it's a huge theme. I think we got an agent report Keith and I did about a year ago on just the shift from human to computer interface versus agent computer interface. And that's going to be what we're talking about, I think, for a really long time. So we've talked about the risk associated with AI. Let's talk about why Elastic potentially an AI winner. So looking at the other side of the coin, where does Elastic play in the enterprise AI ecosystem? How is AI impacting growth today? And why will AI serve as a tailwind for the business in the years ahead?
So I'll talk about the first part, and then I'll let Navam talk about the numbers. So just in terms of where we play in the ecosystem, we get used in a few ways. In the core AI stack, we get used as a data retrieval platform for context engineering. So everything from vector search, our Jina models that we introduced recently, embedding models, reranker models. If you look at the MTEB dashboards, the Hugging Face benchmarks, the Jina models are some of the best out there. Like they outperform all the other commercially available models for embedding and reranking.
So we are seeing a lot of demand for Jina. Agent Builder has been -- like we are seeing really good traction. People are building SOC workflows that they're optimizing on their own. They're building SRE workflows on top of Agent Builder. So we are seeing a lot of interest, not just in the core AI stack, but we are seeing the AI stack now being used to give us a competitive advantage in security and in observability. So that we feel is going to be how our AI story plays out. It's not just going to be in search, but it's going to be on multiple vectors. Do you want to talk about the numbers?
Yes. So at the core, Elastic is a consumption model business. So we monetize consumption by our customers and AI workloads inherently are more computationally intensive. So it drives more consumption on our platform. So we had our Financial Analyst Day in October of last year. And there, we actually gave some very good data in how we're seeing the difference in consumption increase of people using AI versus people who are not using AI. And we quantified that difference as approximately 6% between those two cohorts.
Now that 6% is an average number. There's a wide dispersion among those customers. Some have many multitudes of that 6% as the uplift and some are earlier on in that journey, so they're less. But the core is that we are seeing benefits of -- on our revenue side of our customers using generative AI, which is driving a tailwind. And it's -- we're starting to see that in our 100,000 customers, which are where the majority of our sales-led revenue comes from.
So we're seeing more and more penetration of the 100,000 customers as the quarters go on. And the second S-curve behind that is every one of our 100,000 customers are on their AI journey themselves. So some are early, some are progressing. But as that inflects, you're going to see the second leg of growth as well.
Yes. You mentioned the Investor Day at the end of last year. I wanted to revisit some of the midterm growth targets that you laid out. If you can lay out the sales-led growth targets and how you anticipate AI monetization will impact the midterm growth target? Under what time frame should the AI contribution become materially accretive to growth?
Yes. Midterm to us is approximately fiscal 2029. Our current sales-led subscription revenue targets are 20% as reported, then 18% on a constant currency basis. I mentioned that we're seeing strong compounding of that number right now. We're also seeing AI contribution of approximately in the mid-20% of the 100,000 customers. So there we're still generally early in the AI contribution among our customer base, but it is showing up in the total numbers as a tailwind to us.
So we feel very good, given how we've been executing in the third quarter to continue to compound our sales-led subscription revenue number. And the midterm targets are basically to get that 18% constant currency number to above 20% plus in the 2029 time frame. And that structurally is going to be a lift rather than an inflection that you're going to see in any given quarter.
So over time, you're sort of going to see this rising tide of revenue growth, so to speak, to get to that 20% as the first milestone -- 20% plus of that first milestone and midterm target.
Got it. That's very clear. Ash, I wanted to ask you a question around contact centering, but I actually want to pick up on a point that you made earlier about bringing a solution to market, not just individual pieces, whether it's vector search. And so what does that solution look? You mentioned Jina, embedding models, reranking models. We have [indiscernible] and vector search capabilities. What other capabilities constitute a solution in the eyes of customers?
Yes. The way we think about it is what does it take for you to build an agent from soup to nuts within our environment. Now keep in mind that you're going to build a multitude of agents within an organization, and agents will talk to each other through protocols that are now becoming more and more standard like MCP and A2A and so on. But for us, like the way we thought about it is, if I want to build an agent from scratch, I'm going to start with the data, and then I'm going to start chatting with the data and assembling all the skills that, that agent needs to do its job. That needs everything from being able to pull the data in to begin with, to chunk it, to then turn it into vectors, then to be able to do reranking if I'm using multiple search techniques to retrieve the most accurate context.
I might then want to make sure that I can connect to an LLM directly within my environment without having to go outside. I also then want to make sure that I'm observing. I'm providing some amount of observability on token usage and other kinds of SynOps activities, do some basic guardrailing. All of those capabilities to us are what it takes to build a complete agent and then hook it up to whatever task you needed to, including things like workflow because these agents are not just about chatting anymore, they're about actually taking actions, which also increases the importance of the accuracy of the context.
If you look at Elastic's platform today and compare it to where we started even 2 years ago, all we had was a vector database, and we had hybrid search. Since then, we have introduced the Jina models, both embedding and rerankers. We have introduced Agent Builder. We have introduced Workflow. We have introduced LLM observability everything together, and we've introduced the Elastic Inference Service, which currently hosts our ELSER model along with the Jina models, but it also proxies out to other LLMs.
So you can do everything from within our environment without having to go bring your own license key or whatever. And in the future, our goal is to also support open source models like Llama models, Mistral, et cetera, through that same Elastic Inference Service. So soup to nuts, the ability to build everything that you need for building your own SOC agent or building your own SRE agent or building your own workplace agent for customer support or for improving salesforce productivity or for legal or whatever you might need to do. That's the goal, and that's how we look at the fullness of the platform.
So in terms of the answer you just gave in terms of what a platform looks like. Can we just sort of marry that with what context engineering is? It's a new buzzword in the industry. We're hearing yourselves talk about it, other players in the ecosystem sort of talk about the importance of context engineering. So maybe define that -- define context engineering and how Elastic is playing a central in becoming a contextual engine for agentic deployments?
Think of context engineering as the set of processes, the platform, the capabilities needed to provide a thinking engine, an LLM with accurate context at every step of its journey. And that context is everything from memory as in what interactions that you have with it in the past to retrieval, what specific documents from your corpus of exabytes of data, does it need to look at to be able to answer the question to specific known relationships, like not everything needs to be inferred.
Within your organization, you have an organizational hierarchy and there are rules on what access rights you have and so on. Those are deterministic rules. You can just provide that information to the LLM as context for certain activities that it might need to do. So it's the combination of all of these things. And that's what the data retrieval platform needs to be able to do. It needs to be able to provide all of these capabilities so the LLM can do its job appropriately and actually deliver the outcome that you're trying to get out of it.
Awesome. That's a fantastic explanation. When I look at the total revenue growth trends over the last multiple quarters, what I see is pretty durable. Growth has been in a very tight range, but not yet accelerating. And the question is, is that when we do our customer conversations, I think you guys have even spoken to this that the search business has been -- growth has been improving in that area of the business. And that's what seems to be bring most loudly when we do our own field work. Does that imply that the security and the observability business has been slowing down or there's been some headwinds to growth? I know you guys are advancing the observability product pretty aggressively. Is that the right way to think about why it hasn't -- we haven't seen just a breakout in growth even though it's been very durable?
So let me first tell you how the businesses are doing, the various solution areas are doing, and I'll give you a different lens in how to think about the growth trajectory. In terms of our 3 solution areas, every quarter, there are -- just depending upon the deal flow, there are differences in which solution does the best that quarter. Last 2 quarters in Q3, as an example, security was the best, followed very closely by search, followed by observability.
Now the way I think about it is in search, obviously, there's been a big tailwind from AI. That has been something that's really helping us. In terms of security, because we were so early in delivering capabilities like attack discovery, a lot of the AI functionality that we delivered, we have been significantly ahead of the curve, and that is helping us win more and more deals. The CISA deal as an example that we talked about, I mean that's a pretty transformative deal. This is CISA, the organization that's responsible for security for all of the civilian agencies in the U.S. government, basically taking Elastic SIEM as a service to other agencies and trying to bring them on to that service. So it's a very strong endorsement.
Observability is growing at the pace of the log industry overall. The fastest-growing part of the observability business, though, has been metrics. And that has not been a place of great strength for us in the past. So this has been something that has been at the back of our minds -- the challenge for us has historically been that our back-end Elasticsearch is highly optimized for storing dense information like logs. But that same -- the reason why it's optimized for dense information storage is what makes it inefficient at storing sparse data like metrics.
We figured out how to build specialized back-end stores within Elasticsearch when we started work on our vector database. We now have an incredibly optimized vector store within Elasticsearch, arguably one of the best performing in the industry. Now we are taking that same model and building a metrics data store that we expect to launch sometime in the middle of this calendar year. We've talked about it publicly at our Elasticon events. And that we feel is going to give us the competitive differentiation that we need to compete heavily in the observability market and capture more of that market opportunity. So that's how we look at it.
On the overall inflection or the growth rate, the one thing that I'll ask you to keep in mind is every release or 2, we have been consistently delivering capabilities that makes our platform more efficient. If you look at the vector database product 2 years ago, we had HNSW and everything was represented in Float 16 and you look at our vector database today with binary quantization and all the features that we've released, there's almost 2 orders of magnitude improvements that we made in efficiency.
Think about that, 2 orders of magnitude, which means that somebody was paying x a year ago or 2 years ago for a workload, they are paying a fraction of that today. That acts as a natural headwind. Now why are we doing that? We're doing that because, a, that's not going to continue forever. Like I don't know how to quantize more than in a bit. Now we can store a dimension on a single bit. You can't reduce it any more than that. So it kind of -- the optimization is kind of asymptote over a while. But you want to be the best. You want to be the most efficient because this is -- we are so early in this opportunity. We think of this as a land grab. The more workloads we get on to our platform, the more customers we get on to our platform using our vector database, that is going to pay off handsomely in the future.
So the way we look at it is, even though these optimizations might act as a bit of a headwind on revenue now and doesn't result in an inflection, the underlying workload growth has been tremendous. And as we continue to progress, grab more share, I think this is what sets us up very nicely. So I would not expect an inflection. I would expect steady growth that will continue to be up and to the right.
Yes, because you're playing for the longer-term share of wallet, which makes total sense. I want to spend the last couple of minutes on sort of the capital allocation side of the question, Navam. So given the steep declines in share prices across software, including Elastic, do you anticipate having to issue more stock-based comp to retain key employees?
Yes. We've been remarkably disciplined in our stock-based compensation this past year. Keep in mind that this fiscal year is an investment year for us. So we're adding sales and marketing capacity. We're adding R&D compared to last year. So even with that investment, we're maintaining a strong percentage of revenue in terms of SBC. So SBC continues to be on a downward trajectory, modular these investment years that we're making.
So we continue to be very disciplined. We're investing appropriately in headcount, but also being mindful of where the stock-based compensation is going.
And then with respect to like share repurchases, the level of share dilution, investors should expect on an annual basis and maybe the priority in terms of GAAP profitability, what's the latest thinking on those dimensions?
Priority 1 for us is obviously make sure that we're investing organically to capitalize on the market opportunity that we have, particularly to exceed or meet and exceed our midterm targets of 20% plus. In order to do that, you need to have sales capacity in the field at an appropriate level. The current investments that we've made in capacity is not just an increase in capacity, but also combined with productivity increases per rep on a single-digit basis, right?
So what that's telling us is that we're not pushing on a string. These conversations that our sales reps are having are resulting in better pipeline and better ACV for us on a quarterly basis. So we intend to push -- continue to push that as appropriate. And AI is not disrupting human conversations. That's something that you need to continue to invest in.
So first and foremost, it's our midterm targets on the 20% plus line. Second is our focus on Rule of 40 and making sure that we are adequately adding enough on the free cash flow line as well within reason, maintaining enough growth for our top lines. And third, we talked about the $0.5 billion capital allocation that we -- capital allocation strategy that we had during Financial Analyst Day. We're well underway. More than 50% of our total has been deployed to reallocate back to our shareholders through share repurchases.
So we're very happy with how that's going. But that's the order of magnitude priorities of 1, 2, 3, which is top line first, then free cash flow and share buybacks. The net result of all that is GAAP operating margin profitability over time.
Awesome. Well, thank you for laying that out, and thank you for giving us an update on the Elastic Business. Thank you, Ash. Thank you, Navam.
Appreciate it.
Thank you, Sanjit.
Elastic NV — Morgan Stanley Technology
🎯 Key Message
- Core Elastic positions itself as a data platform that brings AI models to the data, enabling real-time relevance at scale. Its moat rests on data store, context, and relevance across both self-managed and cloud deployments. With AI adoption rising—about 25% of its 100,000 customers using Elastic for AI—the path to durable growth is clear.
🧭 Strategic Highlights
- AI tailwind AI adoption lifts consumption; about 25% of Elastic’s 100,000 customers use Elastic for AI, delivering revenue upside beyond traditional search.
- Platform breadth Agent Builder, Workflows, Jina models, and Elastic Inference Service create an end-to-end AI stack, with plans to support open-source models.
- Deployment mix Demand for self-managed and sovereign deployments in the U.S. regulated sectors and Europe reinforces Elastic’s moat.
🆕 New Information
- New Mid-calendar-year launch of a dedicated metrics data store within Elasticsearch to boost observability performance. Elastic also signaled ongoing support for open-source models via the Elastic Inference Service.
❓ Analyst Q&A
- Topic Analysts pressed about open-source risk and the defensible moat. Elastic argued licensing and the complexity of operating at scale protect revenue, citing strength in security and expanding AI-driven use cases.
⚡ Bottom Line
- Conclusion The Morgan Stanley session reinforces Elastic’s durable AI narrative: a data-relevance moat, a broad platform, and ongoing demand for self-managed deployments. Near-term guidance seems prudent, with AI contributing meaningfully long-term and capital returns supporting shareholders.
Elastic NV — Q3 2026 Earnings Call
1. Management Discussion
Good afternoon, and welcome to the Elastic Third Quarter Fiscal 2026 Earnings Results Conference Call. [Operator Instructions]. Please note, this event is being recorded. I would now like to turn the conference over to Eric Prengel, Global Vice President of Finance. Please go ahead.
Thank you. Good afternoon, and thank you for joining us on today's conference call to discuss Elastic's Third Quarter Fiscal 2026 Financial Results. On the call, we have Ash Kulkarni, Chief Executive Officer; and Navam Welihinda, Chief Financial Officer. Following their prepared remarks, we will take questions.
Our press release was issued today after the close of market and is posted on our website. Slides which are supplemental to the call can also be found on the Elastic Investor Relations website at ir.elastic.co. Our discussion will include forward-looking statements, which may include predictions, estimates or expectations regarding the demand for our products and solutions and our future revenue and other information. These forward-looking statements are based on factors currently known to us, speak only as to the date of this call and are subject to risks and uncertainties that could cause actual results to differ materially.
We disclaim any obligation to update or revise these forward-looking statements unless required by law. Please refer to the risks and uncertainties included in the press release that we issued earlier today included in the slides posted on the Investor Relations website and those more fully described in our filings with the Securities and Exchange Commission.
We will also discuss certain non-GAAP financial measures. Disclosures regarding non-GAAP measures, including reconciliations with the most comparable GAAP measures, can be found in the press release and slides. Unless specifically noted otherwise, all results and comparisons are on a fiscal year-over-year basis. The webcast replay of this call will be available on our company website under the Investor Relations link. Our fourth quarter fiscal 2026 quiet period begins at the close of business on Thursday, April 16, 2026. We will be participating in the Morgan Stanley Technology, Media and Telecom Conference on March 2. With that, I'll turn it over to Ash.
Thank you, Eric, and good afternoon, everyone. Thank you for joining today's call. Elastic delivered yet another outstanding quarter beating the high end of guidance across all key metrics and showcasing the power of the Elastic platform and our business model. Sustained platform demand, strong sales execution and our relentless focus on customers drove Q3 momentum.
As LLM rapidly evolve their capabilities around inference and reasoning, it is becoming increasingly clear that context is the most important ingredient in making these models useful within an enterprise. With that backdrop in Q3, we continued to see enterprises choose Elastic to power context for their most critical AI needs.
Translating the success to our performance, we achieved 18% total revenue growth and an 18.6% non-GAAP operating margin. Sales led subscription revenue accelerated to 21% alongside our growing cohort of $100,000 ACV customers, which now exceeds 1,660. Q3 marked our sixth consecutive quarter of strong field execution, driving solid customer commitments and supporting healthy CRPO growth. That execution is also translating into a strong pipeline as we head into Q4. The lifeblood of organizations is the proprietary data that they create, manage and analyze every day to drive business decisions and operations.
This data is massive, often many [ perabytes ] in scale and simply cannot be moved for cost and security reasons outside of the organization's control. For businesses to use agentic AI, the LLM needs to come to the data. This is where Elastic comes in. With our ability to help organizations store and manage all of their data in very cost-effective ways and by providing accurate real-time context to AI by searching through all of this organizational data in real time.
Furthermore, Elastic is capable of doing this consistently across cloud and self-managed environments. This hybrid flexibility allows sensitive data and workloads to remain in their preferred environments eliminating the need for costly replatforming. This unique flexibility is why we continue to displace legacy vendors and niche cloud-native players alike.
And the results are clear. The number of commitments for over $1 million in annual commitment value signed this quarter grew over 30% compared to the same period last year, driven by new logos and customer expansion. Consolidation and AI are powerful tailwinds. As organizations manage exploding data volumes, they are turning to Elastic to drive both innovation and efficiency to their search, observability and security needs.
For example, we signed a 7-figure new logo deal with a Fortune 100 insurance institution for Elastic Security, seeking to modernize their security operations the company initiated a competitive process to replace a legacy SIM solution that was plagued by slow query speeds, inefficient data retention and rigid SOC workflows. By leveraging features like logs [ DP ] and searchable snapshots, they're consolidating data into a single cyber data lake with integrated AI-powered SIM workflows, all powered by Elastic and its capabilities, including AI assistant, attack discovery and AI-driven orchestration.
This transition enables their analysts to achieve markedly faster cybersecurity detection and remediation outcomes while meeting strict regulatory requirements. In another large deal from the quarter, a global leader in data resiliency software chose Elastic observability to power the monitoring layer for its new cloud offering as they migrate their vast user base to the cloud. They are leveraging our full observability suite, including AI assistant and [ LogsDB ] to transform from reactive troubleshooting to intelligent semantic aware analysis.
By integrating open telemetry and our vector search capabilities, the customer is now able to proactively detect anomalies and remediate issues using natural language queries significantly reducing mean time to resolution. They chose Elastic over incumbents due to our deep integration flexibility, superior handling of unstructured data and the ability to provide a single source of truth across the organization. Crucially, as companies navigate their cloud migrations, they require a platform that doesn't force them to choose between their existing data centers and the cloud. Our asymmetric advantage in supporting modern cloud and hybrid environments drove a significant win with a global financial group.
During the quarter, we closed a 7-figure expansion deal for Elasticsearch, which serves as the core of their online banking application for tens of millions of users. They needed a central data repository capable of supporting both cloud and self-managed architectures, allowing them to run mission-critical workloads in their preferred environment without compromising performance.
Elastic succeeded with the existing MongoDB implementation failed to provide the scalable retriever and precision necessary to move beyond simple search into production-grade context engineering. Moving forward, they are integrating semantic search and advanced AI features to further personalize the user experience through faster, more accurate retrieval.
Central to these enterprise engagements is the rise of agentic AI. Customers are moving from passive Q&A to active agents that drive workflows. Precise action requires precise data. The conversation has shifted from which model we use to how to feed it the most accurate context, enterprises realize that to unlock the value of AI, they must bridge the gap between their LLM and their proprietary unstructured and structured data.
Elastic makes this AI work. We are the engine that allows enterprises to build production-grade AI systems that are actually worthy of their business. While others offer simple vector databases, we know that vectors alone are not enough. We delivered the full retrieval toolkit from hybrid search to advanced reranking, ensuring that agents have the relevant context they need to take precise actions.
This ability to bridge enterprise data to the LLM with our platform is directly translating into expanded AR adoption. In Q3, new customer commitments with AI continue to grow. And we now have over 2,700 customers on Elastic Cloud using us as a vector database with additional customers using us for broader AI capabilities, including agent builder and attack discovery, bringing our total count of AI customers to over 3,000. We now have over 470 customers with an ACV of 100,000 or greater using us for AI. This includes more than 410 using us as a vector database. Cumulatively, AI use cases have now penetrated over 1/4 of our 100,000 ACV customer cohort.
We are seeing sustained demand from the largest companies in the world alongside interest from the new wave of AI native companies. During the quarter, we closed multiple new logo and expansion deals with AI-first innovators, validating that our platform is the standard for both established enterprises and disruptors. A leading AI recruiting platform used by large enterprises and startups alike chose Elastic's vector database to power their core customer-facing software because our search performance at scale was better than competitors.
An AI-enabled driver and fleet safety company expanded their use of Elastic search in Q3 as they scale into new global regions. Elastic provides the real-time retrieval necessary to power their platform, ensuring they can manage increasing data volumes without sacrificing performance and a leading AI native cybersecurity company focused on AR automated penetration testing has integrated our SIEM solution into their product. Elastic centralizes all of their logs without complication, allowing them to effortlessly scale through their massive growth trajectory.
At the heart of these wins is the performance of our Search AI platform. We aren't just adding features. We are aggressively optimizing our engine, focusing our development efforts on delivering market-leading relevance, speed and efficiency. In the last 18 months, we have driven 2 orders of magnitude less [ RAM ] required for vector search through innovations like better binary quantization or [ BBQ ], [ disc BBQ ] and our [ Acorn ] filtering algorithm among other things. This investment makes Elasticsearch vector search up to 8x faster than Open search.
Our superior performance led to 1 7-figure deal with a global heavy equipment manufacturer. The customer continues to migrate mission-critical workloads over to Elastic Cloud from OpenSearch to improve scalability and performance. They are relying on our platform to power their high-speed search for telemetry data collected via the StarLink network. By leveraging Logsdb, they have achieved a significant reduction in cloud costs while managing 7 years of historical customer data.
Our focus on performance extends to our partnership with NVIDIA as well where together, we help enterprises deploy AI applications faster without draining IT infrastructure. We recently announced the technical preview of our Elasticsearch GPU plug-in for a GPU accelerated Vector database which allows for 12x faster indexing. Additionally, the [ Dell AI ] data platform, now with NVIDIA and Elastic, delivers a tightly integrated AI stack that streamlines the ability to build, deploy and scale AI. By making Elastic search a core component of the Dell and NVIDIA AI factories, we are meeting the critical demand for building AI on customer-controlled infrastructure.
As we deepen these technical advantages, we strengthen our technical moat while removing friction from scaling AI. This quarter, we reached several product milestones designed to simplify the path from data to action for our customers. We are providing an end-to-end framework for building the next generation of intelligent applications.
First, we officially launched the general availability of [ Agent Builder ]. [ Agent Builder ] allows developers to build secure, context-driven AI agents in minutes. Unlike consumer apps that serve the web, our focus is on internal business applications using company data. We piloted agent builder with a [ Global 100 ] financial group to investigate and troubleshoot its production infrastructure, demonstrating an order of magnitude improvement in performance for complex issues and democratizing the specialized expertise necessary for rapid troubleshooting.
An international entertainment and media company created a [ change ] interface for customer interactions. They found the [ agent builder ] results to be significantly more reliable and accurate than the other LLM centric approaches they had tried. Building an agent is only half the battle. The other half is ensuring that agent has the most relevant information at its fingertips.
This quarter, we expanded our Elastic influence service to include [ GENA AI's ] multilingual reranking models. [ GENAAI ] delivers a best-in-class model for search accuracy with [ GNA V3 ] currently the #1 ranker in its model size category on the MTEB-English retrieval benchmark, a gold standard for search and rag relevance. [ GENAAI's ] [ V5 Nano ] and [ V5 small models ] continue to outpace peers as well, scoring high in retriever, reranking and other tasks.
By making these models available natively, we are allowing our customers to tune their AI applications for maximum precision and recall. [ Rea ] is the critical next step in a context engineering pipeline that ensures the most relevant data is presented to the LLM. [ Gena ] state-of-the-art models delivered superior performance across over 80 languages.
While AI provides the reasoning, enterprises still require the reliability of rule-based automation for critical business tasks. This is why we introduced Elastic Workflows in technical preview. Workflows adds automation capability directly into our platform, allowing agents to orchestrate actions across internal and external systems like Slack or ServiceNow. It moves Elastic from being a search box to a complete system of action.
Finally, we are delivering on our promise of hybrid flexibility with [ Cloud Connect ] for self-managed customers. We recognize that many of our largest customers, particularly in financial services and government maintain data on-premises for regulatory or [indiscernible] reasons. However, procuring and managing GPU hardware for AI is a massive hurdle for these teams.
[ CloudConnect ] allows customers to keep their data local while securely bursting to Elastic Cloud to leverage NVIDIA GPUs for high-performance inference. This ability to bridge modern AI capabilities with rigorous enterprise requirements is exactly why we are winning large-scale displacements against legacy providers. As organizations prioritize both innovation and operational efficiency, they're moving away from fragmented legacy tools in favor of Elastic's unified search platform.
The results of this quarter accelerating growth, large deal momentum and major competitive displacements, confirm that our strategy is resonating and that we are winning the race to become the essential infrastructure for the next generation of AI-powered businesses. I want to thank our customers for their partnership our shareholders for their trust and most importantly, our employees for their tireless spirit of innovation. With that, I will turn the call over to Navam to review our financial results in more detail.
Thank you, Ash. Good afternoon, everyone. We delivered yet another outstanding quarter. We outperformed the high end of revenue and profitability guidance ranges, driven by another quarter of consistent execution, strong consumption and strong customer commitments across search, security and observability.
The momentum in our performance throughout this fiscal year is a testament to our team's ability to deliver rapid innovation and sales execution consistently quarter-over-quarter. The ongoing market demand we see is translating to total revenue growth, sales-led subscription revenue growth and healthy increases in pipeline generation to support our future growth. These factors together underscore our increasingly strategic value as a critical data platform in the age of AI.
Our total revenue in the third quarter was $450 million, representing growth of approximately 18% as reported and 16% on a constant currency basis. Sales led subscription revenue in the third quarter was $376 million, growing 21% as reported and 19% on a constant currency basis. We saw commitment contribution from both our self-managed and cloud offerings, and aggregate consumption trends in the third quarter remained strong.
Our current remaining performance obligations, or CRPO, which is a portion of RPO that we expect to recognize as revenue within the next 12 months, cross the $1 billion mark for the first time in Q3. CRPO accelerated to approximately $1.06 billion growing 19% as reported and 15% on a constant currency basis. In our consumption business, we structured customer contracts based on their annual usage. So our CRPO gives us a very clear view into the revenue we will recognize in the next 12 months, giving us visibility and confidence in our business.
As Ash mentioned, we saw a deal momentum continue in Q3. This quarter's strength was balanced across all geographies, and we continue to see customers make multiyear commitments this quarter which serves as a clear indicator of how our customers view the Elastic platform as a critical foundational element in their long-term data architectures.
The positive momentum was reflected in our RPO. We saw strong growth of 22% in the quarter as reported and 18% on a constant currency basis. Our deal momentum is also evident in the growth of the count of customers with over $100,000 in annual contract value. We ended the third quarter with over 1,660 customers with ACV of more than 100,000, growing 14%. Quarter-over-quarter, we added approximately 60 net new 100,000 ACV customers.
We saw strong field execution and healthy growth across our solutions where search continues to see ongoing momentum from AI. This demand is benefiting both cloud and self-managed where both form factors are relevant for AI use cases. We continue to see customers taking a self-managed license and deploying Elastic into their own modern cloud and hybrid environments. The demand reflects customers' preference for Elastic, which uniquely provides necessary control and cost efficiency for AI initiatives.
AI also continues to be a powerful catalyst for customer expansion. 28% of our greater than 100,000 cohort now utilizes Elastic for AI, which includes incremental AI capabilities like attack discovery and agent builder. Today, we are still in the early stages of expansion and we see considerable opportunity for ongoing upside for both new and existing customers to accelerate their AI adoption in the years ahead, particularly as they scale into and within our 100,000 ACV cohort.
Now turning to third quarter margins and profitability. I will discuss all measures on a non-GAAP basis. Our commitment to balancing growth with disciplined spending, translated into robust operating leverage and strong bottom line results.
We continue to focus on cost and efficiency in our business. We recorded subscription gross margins of 82% and total gross margins of 78%, delivering an operating margin of 18.6%. The outperformance on Q3 operating margin was the result of our strong revenue performance, the sustained leverage in our model as well as some Q3 expenses moving into Q4.
Due to this outperformance, we now expect to see our full year margins to come in slightly ahead than previously anticipated, with updated FY '26 operating margin guidance now at 16.3%. Regarding cash flow, adjusted free cash flow was approximately $54 million in Q3, representing a margin of approximately 12%. Our cash flows are expected to fluctuate on a quarterly basis based on the timing of bookings and collections related to the enterprise booking seasonality.
So we continue to manage cash flow on a full year basis. For fiscal 2026, we do not see any change in our full year outlook, where we continue to expect to sustain the level of adjusted free cash flow margins that we achieved in fiscal 2025. We have made significant progress on the $500 million share repurchase program that we announced in October.
During the third quarter, we returned approximately $186 million to shareholders, representing purchases of approximately 2.4 million shares. Cumulatively, we have repurchased 3.8 million shares. I mentioned at our Financial Analyst Day in October that we expect to use more than 50% of the $500 million authorized amount in fiscal 2026, and we have already exceeded this goal. As of the end of Q3, we have completed 60% of our repurchase program, and we are continuing our repurchase program here in Q4.
Let's move to our outlook for the fourth quarter and the remainder of fiscal 2026. For the fourth quarter of fiscal 2026, we expect total revenue in the range of $445 million to $447 million, representing 15% growth at the midpoint or 13% constant currency growth at the midpoint.
We expect sales-led subscription revenue in the range of $371 million to $373 million, representing 18% growth at the midpoint or 15% in constant currency growth at the midpoint. We expect non-GAAP operating margins to be approximately 14.5%. We expect non-GAAP diluted earnings per share in the range of $0.55 to $0.57, using between 105.5 million and 106.5 million diluted weighted average ordinary shares outstanding.
Based on our fourth quarter guidance, we are raising our full year total revenue and sales led subscription revenue targets as well. We expect total revenue in the range of $1.734 billion to $1.736 billion representing approximately 17% growth at the midpoint or 15% constant currency growth at the midpoint. We expect sales-led subscription revenue in the range of $1.434 billion to $1.436 billion representing 20% growth at the midpoint or 18% in constant currency growth at the midpoint.
We expect non-GAAP operating margin for full fiscal 2026 to be approximately 16.3%. We expect non-GAAP diluted earnings per share in the range of $2.50 to $2.54, using between $107 million and 108 million diluted weighted average ordinary shares outstanding.
A few other financial modeling points to keep in mind. The diluted weighted average shares outstanding reflect only share buybacks completed as of January 31, 2026. As you consider comparing sequential quarters, keep in mind that Q4 has 3 fewer days than we had in each of the first 3 quarters of the year, which creates a sequential headwind to revenue, which we have accounted for in our guidance.
Also as is typical with prior Q4 periods, we expect to see seasonally higher expenses related to the timing of employee benefit costs. These expenses were already part of the guidance that we had initially laid out for the year. As in past years, we finalized our plans for the upcoming fiscal year during the fourth quarter, and we will provide our initial FY '27 guide during our earnings call in May.
In summary, Q3 was another very strong quarter elastic. Consistent sales execution throughout FY '26 continues to drive our sales-led subscription revenue growth expectations higher for the year, validating the durability of this business motion. As I said last quarter, while quarter revenue can naturally vary in a consumption model, our strong customer commitments drive strong annual growth, fueled by a highly differentiated platform and the expanding value we deliver to our customers, we remain on track to achieve our medium-term targets for both sales-led subscription revenue growth and adjusted free cash flow.
Looking forward, we are confident in our ability to continue to drive profitable growth. We are the critical technology that accelerates data discovery, secures infrastructure and maximizes application performance. With that, I'll open it up for Q&A.
[Operator Instructions] Our first question today is from Sanjit Singh with Morgan Stanley.
2. Question Answer
Congrats on the stability that we're seeing across the business. Navam, I wanted to go back to some of the themes on the Investor Day a couple of months ago. There was a data point that you provided around the AI native customers or the AI customers being a relatively small amount of the customers in fiscal year '24, but driving an outsized degree of expansion, that's sort of year 1 to year 2 expansion.
And so the gist of this question is, is that as we get to like 25% penetration of your 100,000 customer [ cohort ], is there an opportunity here for growth to not just be stable, but actually to accelerate on a more sustained basis as we hit those critical tipping points, if you will?
Yes. Thanks for the question, Sanjay, then -- the trends that we laid out during the financial Analyst Day for the generative AI cohort, they remain the same. So we continue to perform well and we're seeing stronger growth on those generative AI cohorts today as it was when we disclosed it to you during Financial Analyst Day. So we're seeing these tailwinds right now, and we're seeing more of our customers reached the 100,000 mark.
Now remember that each of these customers in the 100,000 mark are also early in their journey. So there's this other dimension of additional penetration and maturation in their own AI journey, which will drive faster growth as well. So we're seeing the tailwinds right now. We've seen tailwinds that average to 5%, but there's obviously more that there are some customers that have higher growth than that. And to answer your question, yes, absolutely, there is a possibility. The art of the possible is there for us to actually accelerate beyond that 5% that we laid out during Financial Analyst Day, and the trends remain positive.
And Sanjit, just to add to that, that is exactly why we are so focused on the penetration of AI within our customer base. And as these customers right now, every quarter, you're seeing us increase the penetration. The penetration initially starts with them using us in some small way. And as that usage grows, as you rightly pointed out, that's going to add to the consumption, it's going to add to the overall revenue, and that's going to show in the continued strength and acceleration of the business.
Understood. And maybe a question for you. You made the point in your script about vector search and vector databases are not enough in terms of building a resilient and powerful AI applications. And I think a lot of people would agree with that statement. So when we brand the company has a context engine, what are the core pieces that are mandatory to secure status as the leading provider of context for AI applications?
That's a great question. I think the most important thing to keep in mind is context is going to change from task to task. And so the data platform, the context engineering platform that you provide needs to be able to do a whole bunch of things all together in a very consistent way.
The first is the ability to bring in any and all kinds of data and as you know, we have some unique capabilities in our ability to bring in not just structured information, but also unstructured really, really messy information. The second is to then take that data and convert it into vectors for vector search, which is a very powerful technique, especially in the AI world for semantic search, but then also to be able to mix it with hybrid search techniques. That includes textual search, and then being able to rerank against multiple techniques to get the most accurate context. So the [ Gena AI ] embedding models, the [ GenaAI-rerankher ] models, those are a key part of their overall platform infrastructure.
On top of it, then you need something that will allow you to assemble agents using all of these capabilities, and that's what agent builder was all about. As you know, it's a relatively new feature from us and a relatively new capability, but we are seeing great traction and adoption within our customer base. Then on top of it, you need workflows because agents are not just about chat anymore. They're not just about conversations. They're about taking precise actions, and that's where the workflow functionality that we released becomes really important.
And lastly, the ability to monitor all of this, and that's where our LLM observability functionality becomes key. So we believe that it's all of these capabilities, Sanjit, that taken together, make the platform a very compelling platform for context engineering. And on top of that, we've also added our Elastic influence service. So you don't need to bring your own LLM, we can help your proxy to any LLM of choice that you might want to use. We integrate with pretty much all of them.
The next question is Rob Owens with Piper Sandler.
Great. I apologize upfront for the flurry of questions in one here, but I will keep it to one question, but maybe 3 parts. Really wanted to focus on the outperformance in other subscription. And I understand you're going to meet customers where they want to buy.
So I guess, upfront, was some of that strength potentially push outs that you saw in the prior quarter? Then if I look at your sales-led subscription forecast for Q4 and the fact that it's down quarter-over-quarter, which you haven't seen historically, it's usually a little bit up. Is that really a function of the strength you saw here in the January quarter or something else to be read into that?
And lastly, when we think about monetization of self-managed versus cloud customers and your ability to expand them over the coming years. Can you maybe articulate the difference between the 2 if there's much there. So again, I apologize for the 3 questions, but hopefully, they're brief answers.
Yes, Rob. Let me start. This is Ash. Let me start and then pass it on to Navam. In terms of our strength in self-managed, this is not just about pushouts or anything of that sort. We are continuing to see a lot of strength in our self-managed business.
At the end of the day, what we are seeing now, especially with AI is a lot of customers are applying AI on data that they consider to be extremely critical, extremely sensitive. This is not just with government customers. This is also in other regulated industries. And for that reason, they're choosing or they're preferring to keep the data where it's within their control, within their environment. And that doesn't always mean in their own data centers.
It might also mean within their own cloud VPCs and we give them the flexibility to be able to do that. So these are modern workloads, that continue to grow as that usage of AI grows, and we are going to continue to benefit from it. Which is why we believe it is really important to not just look at cloud, but to look at the whole picture and take into account the strong growth that we are seeing even on self-managed. And I'll let Navam address the other questions.
Yes, Rob, I'll address your quarterly sequential question. So overall, I'll start with how the business is doing. We're continuing to execute very well on the sales-led motion. This is another quarter of good execution from the sales side. And we saw that play out in our CRPO and RPO numbers accelerating as well.
If you're looking at commitments, we're seeing a good commitment volume, and there's no deceleration on that. And on top of that, the pipeline is very healthy and growing each quarter. So overall, from a business perspective, very happy with where the quarter turned out and very positive about the future quarters as well.
So that leads us to the guide. So when you think about the guide, we always guide with an appropriate amount of prudence on what we can achieve and outperform every quarter. So when you look about -- look at historical numbers versus actuals and guidance, you're comparing an actual number against the guidance number, and the guidance number has risk incorporated into that forward-looking projections. So I'll first point to that.
And the second point I'd make is that the fourth quarter has 3 less days, which translates to a 3% headwind or $14 million -- $14 million to $15 million headwind for us on a revenue basis because there's just less days of revenue to recognize. And all of that is incorporated in the guidance. And if you look at last year's Q4 guide or Q4 guidance in the past, there have been occasions where we've guided lower than the current quarter.
So just keep that in mind, we continue to keep well on track with achieving our midterm targets and we feel very positive about the strength of the business itself.
The next question is from Matt Hedberg with RBC.
Ash, I wanted to ask you about AI and obviously, we've all seen the pressure in the software market. And I appreciate your comments at the start of the past was really helpful, kind of get your perspective on AI. And it seems like there's a lot of great momentum from a customer perspective. I guess my question is, when we're looking at these frontier models, do you see them as future competition or more of a partnership opportunity?
Really, we don't -- in our opinion, AI doesn't displace us, it really depends on us because if you think about these frontier models, there are amazing reasoning engines. Like the way I think about them is they are going to be the operating systems of tomorrow.
But just as operating systems today also require data systems to feed appropriate data and context to these operating systems to actually build applications with, you're going to need the same thing going forward. And our role in this whole ecosystem is to make sure that we can very quickly in real time across all of the petabytes of data that every organization holds give the right context to these LLM so they can do their job. And that's the reason why I believe that in the world of tomorrow, you're going to have agents talking to each other.
You're going to have agents that you build with Elastic agent builders that are talking to cloud cowork that are talking to things that you build with open AI frontier and we already support the MCP protocols, the A2A protocols that allow for that kind of communication. So this is a world where we feel that the fact that we have this tremendous position, the capabilities with our vector database, the capabilities with our entire context engineering platform to become a critical part of the infrastructure going forward. And we're already partnering with hyperscalers, and we already integrate with all of these frontier class models today.
It's a great perspective. And then maybe just one quick follow-up about Elastic internally using AI how are you seeing some of the tangible benefits? And how might that impact head count in the future?
Yes. Look, we are all in on AI, not just in terms of what we are doing externally in terms of providing the platform that we are building, but also in terms of how we are using AI internally. Just to give you some context on this, a couple of years ago, we built out our first agent, our first support agent within the company and that's been in production for a long time now.
It's what our customers first hit when they have support questions and the amount of queries it's able to answer and the number of support tickets it's able to deflect has not only improved the overall performance, the overall experience for our customers when they come to us for support, but it has also significantly reduced the demand on head count from our side.
So in the last 2 years, even as our business has been growing, and as you can imagine, typically support workloads grow with the business, we have been able to manage that workload growth without adding any head count to that support team. In other parts of the business, whether it's in HR, whether it's in finance, in legal, we are heavily using AI tools. Some of these are built on our stack. Some of them might be external products that we are leveraging. And even in engineering, we are finding tremendous value in using multiple different code generation tools that we use within the company.
So overall, we believe that this is going to definitely help us not just accelerate the pace of innovation, which we're already seeing now. but also improve the productivity and improve the overall efficiency of the business. And that's what's exciting about this. We are able to help our customers with this, but we're also able to benefit from it ourselves.
The next question is from Brian Essex with JPMorgan.
I appreciate your response to the last question with regard to your vector database capabilities and content engineering platform. I guess as you look at the changing landscape and you look at different approaches, different ways to think about things? Are there any -- anything -- how do we think about the platform and its ability to adhere to some of those approaches, like, for example, the page index approach to RAG. You -- if they saw the cost and latency issues involved with that approach, are you well positioned to benefit from something like that and pivot with your approach?
Yes. Look, RAG, retrieval augmented generation, itself has progressed a lot since the last several years when it was first introduced as a concept, -- but fundamentally, this comes down to finding the most appropriate context that is relevant for the LLM to do its job. Sometimes that requires you to understand specific data relationships that might exist. Sometimes it requires you to just search through all of your data. Sometimes it requires you to understand specific things, things like preferences and so on that you might have captured in other data systems and it's an amalgamation of all of this.
And as RAG continues to evolve, as these techniques become more and more sophisticated, we are actually on the leading front of capturing more than one single technique into our platform. We were one of the first to adopt hybrid search, and we were the first to talk about it. And since then, we have continued with that kind of momentum.
So absolutely, I feel very, very confident that we're going to be on the bleeding edge. This is, at the end of the day, what Elastic was born to do, we've always been in the business of relevance. Without relevance, you don't get good search. Without relevance, you don't get good accurate AI.
Great. That's super helpful. Maybe just one quick follow-up. Any traction from the recent [indiscernible] win that you had, are any Fed agencies leveraging that for SIEM referenceability? And are you seeing better activity on the back of that win? It's been a great success.
Yes. Thank you. It's been a great success for us already. I think we mentioned it in our press release as well. That SIEM as a service with [ CIS ] continues to grow and we saw additional agencies coming on board even in Q3. So I would expect that CSI to be just the beginning of multiple agencies coming onto that service over the next several quarters. And fundamentally, [ CISA ] is considered to be the primary agency responsible for cybersecurity in the civilian government in the United States. And that just -- that kind of endorsement is something that goes a long way. So it's a very exciting win. Like I said, we are going to benefit from it for many quarters and many years to come.
The next question is from Brent Thill with Jefferies.
Ash, just on the CRPO, 15% constant currency, 15% last quarter. I guess I mean, good mid-teen growth, but I think everyone is asking why aren't we seeing a faster inflection? I know you have a true north of 20%. It seems like the numbers support that you can accelerate to 20%. But just curious kind of how you bridge to 20% and perhaps why maybe you're not seeing a little bit stronger AI tailwind in the near term?
Yes. Thanks for the question, Brent. So I'll start. CRPOs crossed over $1 billion. We're at 19% growth right now, RPOs at 22% growth. That's the best we've seen in 2 years, and we're very happy with the progress that we're making. And if you just look at the absolute dollar additions that we added in the quarter, it's progressing very, very well.
So that's all pointing to the core things that are driving that CRPO growth, which is strong customer commitments, which now we've been talking about for a couple of quarters now, and it's been yet another quarter of good very good sales execution leading to strong customer commitments. So the AI tailwinds we talked about during Financial Analyst Day, we're seeing them right now, and they are continuing to grow as we see more and more of the 100,000 have -- or adopt AI workloads from us. So we're -- we think that there's a good strong trajectory from this point ahead as we see more AI penetration among our 100,000 customer base.
The other thing that I will say to this, Brent, is that if you look at the full year guide for sales net subscription revenue, you can see that the strength in our business continues. And look, for us, the midterm guide that we laid out is not the place where we end up the place that we believe we can go beyond that. If you remember, we talked about 20 plus. And really, that's the way we see it.
So as more and more customers adopt our AI functionality, given the fact that those cohorts tend to grow and expand faster, we feel very, very good about how we are tracking to that midterm, and we feel very good about the fact that as that traction continues, we feel good about even exceeding what we've talked about in the past.
The next question is from Howard Ma with Guggenheim.
Great. I wanted to ask about cloud. And I guess this one's for Navam, I want to throw a caveat first, which is that I appreciate your deployment agnosticism and fewer days in Q4. When I look at cloud revenue in Q4 versus Q3 in FY '22 and earlier, there was more of a sequential step-up than in FY '23 through FY '25, which were obviously impacted by you had industry-wide cloud optimization.
Also Elastic had company-specific go-to-market issues. But now that the go-to-market execution has improved significantly. And given the visibility that you now have into how large customers ramp consumption relative to the commits, and that includes some of the $10 million plus TCV contracts that you signed last quarter. The question is, is there any reason why the sequential cloud growth in Q4 would not be more in line with the earlier years?
So I'll start off with what I always start off on, which is sales-led subscription revenue growth is the right metric for you to focus on in measuring us as a barometer as the success of the company and the barometer of success of the company. And I talked about this during our prepared remarks as well.
There's multiple examples including this quarter of AI workloads being sold as self-managed and deployed either in the customer's cloud or in their hybrid environments. So sales-led subscription grew a healthy 21% this year. If you look at just cloud and the number there again is what is the sales-led cloud number, that grew 27% year-over-year this quarter. So we're seeing very good traction on the metric that we matter -- metric that matters to us, which is sales-led subscription revenue.
And also on the annual cloud number this quarter was very good as well at 27%. The forward quarters -- number one, you have 3 less days, so that's 3 less days to focus on. The forward quarter is a risk-adjusted number. So you can't really compare an actual to a guidance number. But the point I'd like to make is that we're seeing very strong commitments and very strong performance on sales led.
Next question is from Ryan MacWilliams with Wells Fargo.
This is [ Dusan ] on for Ryan MacWilliams. I wanted to ask, it really seems that based on some of the work we've been doing that the number of agents and AI services and production have really increased over the past couple of months. And I wanted to hear from you what you're seeing within your customers? Like are you seeing the types of AI use cases broaden out compared to what you were seeing maybe 2 quarters ago how that's impacting usage and spend amongst those customers?
Yes, we are seeing the usage broaden out in the sense that we are seeing more and more variety of use cases that involve AI. 8 quarters ago, the bulk of what we were seeing was only around vector databases, vector search, hybrid search, semantic search, it was mostly around the chat style interface kind of work. Now we are seeing agentic workflows being put together not just around what you would typically think of as search-related workflows but also around security workflows, around observability workflows.
And that was the reason why we gave the stat around our total count of customers using us for various AI use cases beyond just vector database. And that includes things like agent builder. That includes things like attack discovery. And in these kinds of scenarios, people are trying to automate their workflows, their cybersecurity workflows for detection, for remediation, they're trying to do the same for SRE workflows around absorbability. So the variety of use cases is growing. And as that grows, we see an opportunity not just in our core search business, but also in the work that we're doing in security and observability.
The next question is from Miller Jump with Truth Securities.
Congrats on the sales led momentum. Ash, you mentioned a [ MongoDB ] competitive win in the prepared remarks. We haven't heard as much about this head-to-head between the 2 of you until fairly recently. So are you seeing [ MongoDB ] increasingly in bake-offs as customers look to build AI apps? Or is that more of a one-off?
No, this was a situation where the customer had started to use that technology for a basic search application. They had some issues scaling it and as they were trying to build a more scalable solution, especially for hybrid search, they realized that they needed something that could perform and that was the customer win that I talked about. At the end of the day, where we tend to typically play is in the area of unstructured data. We don't tend to see them as much. But from time to time, you do see these kinds of situations.
And if I could just ask a quick follow-up for Navam. As large deals are becoming more of a contributor in your go-to-market strategy, moving upmarket, can you just remind us how you're handling those large deals in your guidance process? And any considerations around seasonality there?
Yes. Seasonality wise, I think it just follows the normal typical enterprise seasonality pattern where they end up being more tail end weighted in Q3 and Q4. But we talked about large deals in the last quarter. They happen every quarter. it's just the volume of bookings are bigger and towards the tail end of the year. In terms of how we handle it, I think that this is a natural byproduct of just being successful with our customers, particularly the larger customers within the [ G2K ].
So we welcome it. When we look at our guidance and what we expect the full year to be, we naturally take a haircut on specific deals that could move from 1 quarter to another. So that's how we incorporate it into our guidance, a risk-adjusted number on not actually counting on everything going our way.
The next question is from Koji Ikeda with Bank of America.
This is [ George Marian ] on for Koji. I appreciate you guys taking our questions today. I wanted to ask just in the conversations that you guys have with customers and their strategy around adopting AI. How would you say that the tone and the conversations differ versus a year ago? And what kind of inning are they in today versus maybe a year ago in the adoption journey with Elastic?
The general tone is definitely one of greater enthusiasm for AI. I think there's been enough proof points now for AI helping in all kinds of use cases, whether it be around code development, whether it be around customer support, in legally discovery, like lots and lots of use cases across all functions. And so we are seeing the conversations be less evangelism and more about helping them put together these kinds of sophisticated agenetic application.
So there's definitely been maturity. In terms of the total number of these agents that people have within their organization, that number is still in the early days. Like if you think about the total number of business processes and workflows that can be automated by AI, I think you have to be realistic that we are still in the early days because AI just is a pretty powerful and transformative capability. And what you can do with these LLM in terms of reasoning can be applied to many, many different functions and different work processes. So we believe that the opportunity is still very significant and still ahead of us.
The next question is from Mike Cikos with Needham.
This is Matt Calitri on for Mike Cikos over at Needham. With all the advancements you're making to search with things like the [indiscernible] models, are you able to charge customers more? Or is the improved speed and accuracy more of an acquisition vehicle?
So we do charge in terms of consumption, right? So we have a consumption model, as you know. So pretty much everything that you do on our platform. It's metered and effectively based on compute, based on storage and so on. And for anything that's LLM or model related, it's based on tokens. And all of our pricing is sort of public on our pricing pages, but yes, with these newer models, we are monetizing everything. And as the usage continues to grow, as customers do more and more on our platform, that is what drives revenue for us.
Got it. Very helpful. And then maybe just taking a different slice at the guidance question here. So you beat on the 3Q guide in constant currency, and then you raised the constant currency guide for sales led subscription revenue, but you left constant currency unchanged for the full year guide.
And I can appreciate the 3 fewer days and the risk adjusted, but that would have been baked into the prior guide. Can you just help walk through the mechanics there of why that wouldn't have increased?
Yes. I mean it's quite simple. The number that we care about is sales-led subscription revenue. We handily beat that number this quarter. And we raised more than we beat. That's a reaction of what we think is happening with the business and the sort of the positive momentum that we're seeing on the sales line. So overall, what we -- we're not thinking about it too much more than we feel good about the forward momentum of sales led subscription revenue, and we beat the number, and we're raising more than we be.
The next question is from Eric Heath with KeyBanc Capital Markets.
Showing no further questions. This concludes our question-and-answer session. I would like to turn the conference back over to Ash Kulkarni for any closing remarks.
Thank you all for joining us today. We at Elastic are very proud of our business results and excited about the opportunity ahead. Thank you.
The has now concluded. Thank you for attending today's presentation. You may now disconnect.
Elastic NV — Q3 2026 Earnings Call
Elastic NV — Q3 2026 Earnings Call
Elastic NV Q3 2026 Earnings Call – Key Highlights
Elastic reported a solid Q3 2026, topping guidance across revenue, profitability and AI-driven customer adoption. Management emphasized Elastic as the enterprise context engine for AI, highlighting hybrid deployment flexibility, expanded AI capabilities, and a robust sales-led motion that supports healthy future pipeline and ARR growth.
- Financial highlights
- Total revenue: $450 million, up ~18% year-over-year (YoY) and ~16% on a constant currency basis.
- Sales-led subscription revenue: $376 million, up ~21% YoY and ~19% CC.
- CRPO (next 12-month revenue recognition): crossed $1.0 billion for the first time; $1.06 billion, up ~19% YoY and ~15% CC.
- RPO: up ~22% YoY, ~18% CC.
- Gross margins: subscription gross margin 82%; total gross margin 78%; non-GAAP operating margin 18.6%.
- Adjusted free cash flow: approximately $54 million in Q3 (~12% FCF margin).
- Customer & AI momentum
- ACV >$100k customers: over 1,660, up 14% YoY; roughly 60 net new $100k ACV customers in Q3.
- AI penetration: 28% of the >$100k cohort uses Elastic for AI; total AI-enabled customers >3,000, including ~470 with ACV >$100k using Elastic for AI (and >410 using Elastic as a vector database).
- Notable wins: 7-figure new logo for Elastic Security with a Fortune 100 insurer; large-data-resiliency/observability deals; partnerships with NVIDIA and Dell AI to accelerate AI deployments.
- Strategic commentary
- Elastic positions itself as the context engine, enabling end-to-end AI workflows via vector and hybrid search, agent builder, workflows and LLM observability.
- Introduced and expanded capabilities (Agent Builder GA, GENAAI multilingual reranking, LogsDB, Cloud Connect) to support secure, hybrid, enterprise data and AI workloads.
- Emphasis on hybrid environments to avoid forced replatforming and to serve cloud and self-managed deployments.
- Guidance and outlook
- Q4 fiscal 2026 guidance: Revenue $445–$447 million (≈15% growth midpoint), sales-led subscription $371–$373 million (≈18% growth midpoint), non-GAAP operating margin ~14.5%, non-GAAP EPS $0.55–$0.57 with 105.5–106.5 million diluted shares.
- Full-year FY26 guidance raised: Revenue $1.734–$1.736 billion (~17% growth), sales-led subscription $1.434–$1.436 billion (~20%), non-GAAP margin ~16.3%, non-GAAP EPS $2.50–$2.54 (107–108 million diluted shares).
- Q4 headwind: three fewer days vs. prior quarters, translating to roughly $14–$15 million in revenue impact.
- Balance sheet/capital: debt-free commentary not emphasized; ongoing share repurchase – ~60% of the $500 million program completed; $186 million returned in Q3; 3.8 million shares repurchased cumulatively; plan to continue in Q4.
- Near-term stance
- Management remains confident in midterm targets for AI-driven subscription growth and adjusted free cash flow, with a focus on expanding AI use cases within the 100k+ ACV cohort and extending pipeline into FY27. Initial FY27 guidance to be shared in May.
Elastic NV — 28th Annual Needham Growth Conference
1. Question Answer
My name is Mike Cikos. I'm the lead analyst here covering cybersecurity and infrastructure software. Pleased to say we have with us Elastic. I'm joined up here on the stage for a fireside chat with GVP of Finance, Eric Prengel. We'll go through some questions we have planned on our side, but please would love this to be interactive. If you guys have any questions, lob them in and we'll get them while we have Eric here.
With that out of the way, Eric, thank you for joining us again. Just in the interest of intros, do you want to walk through your background?
Yes. Thanks for having me. It's always a pleasure. I'm glad to be here in person. I think last year, I did this and I had technical difficulties on -- in the middle of the thing that was -- we can't have technical difficulties. We're literally in person. So we won't have that issue. That was terrible, especially as a tech company. But my background, so I've been at Elastic for 3 years now. I'm the Global Vice President of Finance. I cover FP&A, Investor Relations, procurement and a number of other functions.
I basically have all of the finance function. Before the 3 years at Elastic, I was an investment banker for 15 years, most recently at JPMorgan. And at JPMorgan as I got to know Elastic, I was the banker who took them public, and then I also did the debt deal for Elastic. So I've known them for a while, seen the evolution, and I joined because I thought they were a phenomenal company with a phenomenal team.
And super high level, just for anyone who's new to the name, I know you guys have been in the public markets for some time, but potentially revisiting the story, can you just do a quick overview of Elastic? What is the value prop they're providing to their customers compared to the differentiation?
Yes, I'd love to. So Elastic is a platform that was built to handle unstructured data. and it handles unstructured data incredibly well. We can ingest unstructured data, we can manage it, we can search it. And that's really what Elastic does. And that can be used to solve a ton of different problems. It can be built for ride app hailing where you can apply it to geographies. It can be built for website search. But as the company evolved, we also found out that there were some specific use cases that were very monetizable and repeatable that search could be used to solve. And that was observability and security.
In Observability, ingesting logs and then being able to search through those unstructured logs and parse them out was something that Elastic platform did phenomenally well. And in security, SIEM was a capability that was also involved dealing with log data and finding out incidents and being able to identify them was something that Elastic did tremendously well. Since that time, Observability has branched out, and we now have metrics in APM. And in security, we've added XDR.
In addition to that, as the world has evolved, Elastic has been a search company at its core and a new problem with search has come around with vectors. And so when I joined 3 years ago, Elastic was already deep into vector search and vector databases. And I remember when I joined and at the leadership level, we were talking about the work we were doing on our vector database. I had no idea what a vector database was at that time.
This is before ChatGPT really became popular, and it was something that Elastic has been working on for years. So when this whole GenAI revolution occurred, it wasn't that Elastic went and chased that. Elastic was actually very well positioned, had a lot of functionality in these GenAI capabilities with vector search with vector databases and really was able to build on them and augment them and really be differentiated in terms of what we can do in GenAI, where we have reranking models, we have embedding models. We've got a ton of different capabilities. We've got semantic search and hybrid search that really enable us to provide relevance and context when you think about GenAI. And if you think about the evolution of GenAI, where early days, it was just generating ideas and now it's becoming moving more and more towards Agentic, the importance of getting things right and the importance of relevancy is only increasing, where with an Agentic model, you're not just getting some words on a page, but you're actually taking actions and you need to make sure that you're taking the correct actions.
And that's where Elastic really shines, providing that relevancy in that context in these GenAI workplaces. So that's, in a nutshell, how I'd think about Elastic.
And on the search specifically, let's go there first digest this, right? But on search, you guys already looked at as being a leader within enterprise search as an example. I remember when we had this conversation last year, and it just -- it struck me. I was having a conversation with a colleague at the time where everyone was trying to figure out database vector, what does vector search mean? And I was actually talking with a colleague who was working at Pine at the time when they were coming out and they were like, listen, the only one that I would actually give credit to is actually Elastic. Because I think you guys had built out those vector search capabilities as early as like 2019, 2020, like way before ChatGPT.
So credit where credits to as far as being at the fore on that. I think one thing management has been astounding the alarm on is the fact that, hey, with GenAI, the search business has seen a resurgence in part because of GenAI, but also like there's incremental budget going into that search avenue.
So can you help us understand from like a boots on the ground perspective, what are you guys hearing in the field? How has customer adoption been tracking towards those newer GenAI capabilities and the pull-through of the core search that's always been there now?
Yes. So as we think about what's driving the acceleration in search, it's really predominantly this GenAI motion where more customers are adopting GenAI. And that's driven search to be the fastest-growing part of our business for multiple quarters now, which is really exciting and did not used to be the fastest-growing part of our business. This is really a shift in the dynamics, and it's all attributable to GenAI. And so we've seen customers who've adopted us for a number of use cases, and they've been a broad range of customers. You've seen smaller AI native companies who are building their applications on us. You've seen ISVs who are using us to augment their applications and provide GenAI capabilities to their customers. And then you've seen some very large organizations outside of technology, financial institutions, health care institutions, what have you, who are using us to build applications that are either internal or external facing within their organizations.
Now all that being said, I do want to remind everyone that we're seeing a lot of positivity in GenAI, it's still earlier days. A lot of the dollars that are being spent around GenAI are associated more with model training and the infrastructure that's needed for model training and the deployment -- the broad deployment of applications that are either internal or external facing is still a little bit earlier. And so that's going to -- we've seen some positivity in some revenue from GenAI, but it's going to continue as you see more applications be adopted more broadly.
And that was going to feed into the next one, right? Like it feels like we've been standing in this experimentation exploration. It was only like last year, we began talking about Agentic AI, and I was like really is that. And now it seems like it's almost certainly we're going to be going into that arena from where you sit today, does it feel like this year is going to have more of these workloads or applications moving into production environments? Or is it still too early to call that.
I think it will -- I think it's easy to answer there will be more because it certainly won't be less.
Coming off.
So more is a clear answer. I think the degree to which we'll see the adoption is still TBD. I think there will be an uplift and an increase, but I don't know exactly what that's going to look like. We're seeing a lot of positivity. We're seeing a lot of engagement. So I think that across the board, we're going in the right direction, and it's -- we'll see how it plays out in the year.
When you are seeing customers explore your GenAI capabilities, is that serving as an avenue now like walk us through what you guys are seeing from a new logo standpoint as far as customer engagement with the platform? Or is it predominantly -- I know that you guys have a massive customer base, just going back to the existing customers for cross-sell opportunity.
It's both, and it benefits us in so many compelling ways. So as GenAI has been more important, it's really up-leveled with the conversations that we're having with our customers where there's board level interest, there's C-suite level interest around GenAI. And so the level of engagement over the last year or 2 years that we've seen with our customers. Because we're at the forefront of GenAI has been really dynamic. And it's changed the kind of conversations that we're having. And so customers are investing with us because of what we're doing with GenAI. Customers are investing with us because of our GenAI road map. And they might not be using GenAI today, but they want to be partnering with a company who's got a clear road map and who already is doing things in GenAI because they see an opportunity to grow with us and to really partner with us over multiple years.
And it's also just getting us in front of customers in a way that we weren't able to in the past because what's critical to us and the things that we're doing are very compelling to them. And so it's really a manifolded way in which it's benefiting us, this whole GenAI capabilities that we have and the ability to engage with customers around it.
All right. And again, we're going to unpack the different primary use cases here. But if we jump over to security for a standpoint, you had noted SIEM and XDR. I think both of those categories within broader cybersecurity are extremely active right now, topical just given recent acquisitions, potential for share displacement.
Can you help us think about when you are winning a new logo from a security standpoint, it feels like it's going to be predominantly for that SIEM use case. And like correct me if I'm wrong on that. If that is the case, like how much of this is brownfield dual source?
You're not wrong. But we talked, in Q2, we talked about a $20 million-plus deal that we had, and it was a displacement of a competitor, and it was a net new customer for us. It was a large-scale global chemical manufacturer. And they chose us for not just SIEM, but also XDR. And they had us compete against, I think it was 8 companies that were in the RFP, the best of the best, and we competed and we won on the merits of our solution, both for SIEM and XDR.
So SIEM is obviously where historically, we've been really strong, but I think that our XDR capabilities are ready to go head-to-head with anyone as well. And so this was a phenomenal win and I think probably one of the better proof points around our XDR capabilities.
With the traction you are seeing for SIEM and XDR today, is it fair to assume that for the most part, organizations are dual tracking you like the market is pretty established. I feel like in some ways, someone already has that SIEM vendor they're already tapping into. And so they'll dual track it and then potentially wean off of an existing solution, bringing more over time. Is that what the evidence...
There's a migration process that has to happen where and we're doing things. We understand that we've got a big displacement opportunity, and we're doing things in our go-to-market motion where we're proactively setting our reps up to succeed in displacement scenarios where we'll be able to make concessions to help people get us, get onboarded with us if they're going to make multiyear commitments so that they don't have to deal with the dual costs for too long.
And how do I think about -- again, there are even I feel like some of the large platform cyber guys are getting more aggressive in how they're talking about SIEM. And everyone sees this opportunity because we're how many years out of the chute now with Cisco acquiring Splunk. There are some other tools that are just long in the tooth, right? Are you actually seeing more competitive replacements today versus 6 months ago? How does that pipeline continue to build?
Yes. I think that the competitive displacements don't just come up out of nowhere. You have to build the relationship, you have to engage with them. You have to work towards getting them to understand the value of your solution, what you bring to the table. And then as they come up for renewal, that's when you have an opportunity to win those deals. But these are large deals.
I mean some of them are 8-figure deals. And in order to win those away, you have to build a long-term relationship. You have to have a real path to migrate over on to your solution. And so it's not just that they're showing up today versus 6 months ago. They were here 6 months ago, they might be starting to close today, and there's a whole lot more that are in our pipeline that are going to take multiple quarters and even in many cases, multiple years to close, but they're definitely something that we've been putting a lot of effort into.
And last but not least is the observability element. So you guys, I think, predominantly known for your capabilities around logging. To your point earlier, you've built out metrics and traces, right? We've had this for some time. A lot of attention with the announcement that Palo Alto is going to be entering the market through its Cronosphere acquisition. What is Elastic's view on that consolidation? How is it you guys are thinking through either increased competition or just broader market awareness of what's playing out on that front?
Yes. I think that as you think about the consolidation between security and observability, that's hugely positive for us. It's very validating. I think for 5-plus years, Elastic has been talking about a convergence of those 2 and the benefit of putting them together. And the fact that the market is starting to follow suit plays really well to our strengths.
Where I think that we're nicely differentiated is we have a common data platform across security and observability. So people can leverage the benefits of having both of those in one data platform to make them more efficient. A lot of people who are going through this consolidation motion through acquisitions to be able to bring those 2 solutions together, they have 2 different data platforms that they're sitting next to each other.
So they can go to market together, but they can't necessarily have the data in one place or benefit from the efficiencies of not needing to have duplicative databases. And that's something that we can do. And so as customers get more accustomed to a buying motion that involves both SIEM and Observability or security and Observability together, the fact that we've brought them together on one platform makes us more compelling when they're thinking about that as a unified purchase.
Excellent. And we'll shift for a second over to the go-to-market. If I rewind the clock about a year ago, there were some changes where I think a little bit more disruptive than what had been initially anticipated. Those are increasingly, you could say they just are in the rearview mirror at this point. But can you just remind us what did the management team enact as far as the segmentation of the go-to-market effort? And we'll just start there.
Yes. At the start of fiscal '25, we made a change where we had an external consultant in and we did a lot of work thinking through what we could be doing to improve our go-to-market motion. And one of the things that was clear to us is that we weren't segmenting our customers such that we were paying enough attention to our high propensity to buy customers. And so we realized that reps might be covering 2x the number of accounts they should in conjunction with covering some really attractive accounts. And so they couldn't build that customer intimacy and go really deep with those customers the way that we should. And so what we did is we reduced a lot of our reps. We took away a lot of their accounts so that they could really focus on the core accounts that were going to drive the most value for us.
And as part of that resegmentation of our go-to-market where we moved around a lot of accounts, that created a natural transition where in Q1 of '25, a lot of our reps were getting to know their customers instead of moving the sales opportunities through the pipeline. And so Q1 of '25 was a much slower quarter than we would have hoped for and frankly, than we anticipated because of all that time that reps are spending getting reacquainted with customers.
Once we got into Q2 of '25, and we were worried after that. We wanted to make sure that, that was a onetime thing and not something that was endemic to our sales execution. In Q2 of '25, we had a very strong quarter. A lot of the deals that -- a lot of the resegmentation started to pay off, where now we're moving deals through the pipeline, things were much, we're showing a lot more positivity. And we've seen that continue in the 5 quarters since where with this new segmentation, we're paying much more attention upmarket to these bigger customers who have a high propensity to buy, and we've just got a lot more intensity around the coverage effort for those customers, and that's driving success in the larger accounts for us.
So it's played out really well, but there was certainly a very stressful Q1 '25 as part of that.
And I know it's -- well, I don't want to speak on Elastic's behalf, but at least across our broader coverage, there's been this gradual melt up of go-to-market organizations, right? Go to the higher spend customers where the budget is more durable, you could be stickier, you can identify more value. It's easier to sell into an existing account. But it is also an iterative process.
If the first go around, hey, my Coast gets cut from 20 to 15 accounts, then maybe the next year, it's 15 to 8 because we know, we've demonstrated value and we can drive that. Where are we in that iterative cycle with Elastic as far as the evolution, account assignments at the strategic or enterprise levels of this?
I got good news and I got bad news and the good news is we're a lot further than we could be. The bad news is probably because we moved too fast in Q1 of '25, and that's probably why we saw the disruption is because we basically took it. We saw where we were. We saw where we wanted to be, and we went straight to where we want it to be. And so we skipped all the interim steps of moving over. And so Q1 of '25 was pretty stretchful.
There was -- there were issues in that quarter, but that was 6 quarters ago, and now we're in the place that we want to be. And so as we think about our go-to-market motion today, it's a machine that's running really nicely, and we think about it as being highly investable and a place that we can deploy more capital and see more returns out of.
We talked about it at the Analyst Day in October, but we've seen a nice increase in productivity over the last year or so. And because of that productivity increase, because of the things that we're seeing both in our pipeline and in deals that are closing with some of these bigger accounts, we're really putting more dollars to work in terms of sales capacity.
That's great. Great to hear on the capacity. One of the things that you had mentioned as well as the productivity gains. And so I'm trying to get a sense of that from the outside. I'll recycle back to the Analyst Day since we were just talking about it. Company committed to 15% plus on just the core, 20% plus over some time frame if I start thinking about what the GenAI tailwind to the business model could be.
Within that construct, again, you guys are layering in capacity. It's probably easier to see, all right, X times Y and you have your outcome based on capacity. Does that top line growth assumption embed an additional assumption around sustained productivity enhancements? Like did you know?
It's a great question. As you think about what's driving our growth, is it productivity growth? Or is it capacity growth? Capacity growth is very tangible. I can tell you, hey, we're going to go from having 10 reps having 15 reps, hire those 5 reps and be really focused on to do it. But to say each of those reps is going to do X more dollars is a little harder and a little less tangible. And so as you think about where we're -- what we're underwriting to, it's going to be on the tangible things that we can control, and that's going to be more around the capacity growth versus the productivity growth.
Excellent. And in addition to the segmentation we were talking about, you guys also have an initiative relatively new in the grand scheme of things, but call it in the last year or so, you started building out a specific sleeve within the go-to-market that actively pursues new logos, call them the hunters, if you will.
The greenfield.
So where are we in establishing that motion? Are we continuing to layer more capacity in there? Or should I think about the capacity really being towards those AEs going after the strategic?
I think it's in both places. I don't think it's exclusively in one or the other. The greenfield territories, which is a greenfield territory, is effectively a territory where we have no revenue today. And so there are reps who are getting territories that have no revenue. They're going to have a smaller quota because they obviously need to do all new business instead of expansion business. But that's a place that we are investing. We've seen positivity out of it, and we're going to continue to put more dollars behind it. But we're also seeing more positivity in the core business, which is this new and expansion. And so it's both that we're really investing in.
Excellent. And then the last one on the go-to-market for the time being, but you had noted that $20 million deal, new customer, chemical manufacturer. Can you feather that in because we're talking about that was both SIEM and XDR.
As part of your go-to-market, you guys have also built out a security overlay team as well, right? So where are we in establishing that? We're obviously getting the tangible proof points with that $20 million customer, but...
Yes. I think it's not just a $20 million customer. We're seeing security really do well for us. I think that we're at a place now where when you compare us to other SIEM vendors and even other XDR vendors, we're in the top-tier best-in-class in terms of our solution. And what prevents us from winning isn't our product capabilities if we're in the deals. And more and more, we're getting into the deals, people understand that Elastic is best-in-class in the security space, and that's been phenomenal for our win rates and -- or just showing up. And then once we show up, our win rates are strong. And having this security overlay, I think that a lot of security companies are pure security sellers.
And so there's a language that they speak with each other, the ability to talk to a CISO, the ability to engage with a security practitioner in a way that's really compelling. And having those security, that security overlay with those security sellers really helps us participate in that market and be a compelling option, and we've seen tremendous traction in security. And we've talked about it in the last 2 quarters about how the security business has done really well from a bookings perspective in these last 2 quarters. And I think it's a convergence of all of those things. It's not just the security overlay, it's also the product where it's really best-in-class in SIEM and XDR and it's also the awareness that the market has around our products.
So all that has come together, but the security overlay has definitely helped.
And if I could come back to like, again, the tangible proof that these investments are starting to show up in the financials here, I'll come back to large commitments because that's something I'd like to unpack with you.
On the 2Q call, Elastic disclosed $5 million, $10 million TCV deals, TCV deals, including 2 of which were security, both over $20 million. There were 2 for observability and one was AI, right? So great complexion as far as tapping into each one of those pillars that you guys stand on. I guess, the number of those large deals, how repeatable is that at this point? Again, like I'm thinking about those competitive displacements you were talking about earlier, Yes, they've been sitting in the pipe and great, they all fit, right, versus this is something we have line of sight looking into our pipeline, like this is something we're building towards.
It's a change in the way that we go to market. So I run deal desk at Elastic, too. And what that means is when we do a big deal where there are terms that we might not have put in place before where there's questions, there's uncertainty. There's questions about it, I get involved. And 3 years ago, when I started, I was getting involved in deals that were very low single-digit million, high multiple -- close around the $1 million range. I'm not getting involved in deals that size anymore because Elastic has a repeatable and executable motion around deals that size.
When I'm getting involved, it's around those $5 million to $10 million-plus type deals because that's where we're moving. And just the type of deals that I'm engaging around has completely changed because Elastic and a business has gotten much more proficient, and we see many more of these larger deals. And it's just a fundamental shift in terms of what we did in Q1 '25, the fact that we're getting bigger as a company that we're maturing that a company coming in and writing a $10 million check to Elastic doesn't feel out of the ordinary to them anymore. It's just how we've evolved. And so that's been really positive, and we're seeing a lot more of those big deals.
Can I ask -- this is more just an odd ball question, but I've seen some other companies potentially get tripped up. Like as you are graduating into $10 million deals, like when you get to that scale, I give you an incremental 2 points of discount on this deal. That's not necessarily going to get this deal over the finish line on December 31, right?
So what kind of guardrails are you putting in place? Or does it cause you to change how you are constructing guidance to make sure like if this deal doesn't hit, like that matters, right?
Yes. I think it's fair. I think that for some of these larger deals, you kind of want to be a little bit more, hey, should this be a committed deal? Or is this like a strong upside deal in terms of how you think about them and you probably put a little bit more of a risk around them just because there's less certainty around it getting done and you don't want to be -- you don't want to put too much risk around the deal getting done where it's a binary outcome. And so I think your point is spot on, and that's how we've been handling things for some of these bigger deals. They're more like the cherry on top versus the core of how we think about the guidance.
That's great. I think that's just the right approach, especially like, again, not you guys, but I've seen other vendors which really need to take a fine comb and go through deals to implement tighter discipline on how they go through deals from pipe to ultimate signing.
On those larger commitments that we are seeing to -- is the sales team -- can you just remind us what are their incentives? How are you guys driving behavior? And I guess the build on to that is, are they being incentivized to drive larger commitments based on how those incentives.
No, absolutely. I mean they've got a quota, and it's a quota predominantly around NME, but also they've got a renewal component to their quota. And as the more business they drive, they get into -- they have 100% of their quota payment. Once they get beyond 100%, they start to see accelerators where they get paid a meaningful uplift from their core rate. And so if they can get some of these bigger deals done, Christmas is great.
Everybody is celebrating. People are going on, people are taking nice vacations. People are -- like those are memorable years in their family when their W-2s have that kind of -- the impact that doing some of these big deals can make.
Is there a push towards longer duration deals or not necessarily?
We always like more duration because it means we don't have to come back to the customer and renew it. It just gives you visibility. With all that being said, I think that like when people ask us questions about our RPO and they ask us to unpack that, we're not going to not do a deal because it's 1 year. Sometimes the customer will be -- there'll be a trade-off where they would say, "Hey, we'll do a 3-year deal for this and a 1-year deal for this, and we'll get them in the door on the 1-year deal. And we're not like myopically focused on the multiyear deal.
We'd love to have a multiyear deal, but a 1-year deal is great, too, and we're really managing our business to the ACV and the commitment level that we're seeing. Because we can always renew in the next year. And once you get on SIEM or once you've got a big observability implementation, it's not something you can replace that easily.
And for Again, I'm sorry, I'm spending so much time on the go-to-market with the 3 different pillars.
I spend so much time on the go-to-market, too, I promise you. So it works out well.
So like what are you seeing, whether it's security, search, I feel like it's a little bit more, again, if you guys are the leader there, but like what are you doing to ensure additional consolidation of the landed TAM within your existing customer base, right? How are you building on that success? And then the follow-on would be, how are you driving behavior if you already landed a security use case into a potential search case or into an observability use case. Can you see that?
You can. And I think that's where the benefit of having more of that customer intimacy and having a narrower scope of -- a narrower portfolio of customers for our reps is really benefiting us where they sell one thing. And if you've got a huge amount of customers, you sell one thing, you move on to your next customer. But if you've got a narrower base, you sell that thing and then you really double down, you invest with that customer, you're spending time with them, you're trying -- you're getting the appropriate people in front of them.
If they're a SIEM, sorry, if they're an observability customer, you get your security specialist in front of them and talk to them about what they're doing for security. You know they have SIEM. You know that logging and SIEM go hand in hand. And so you go and you have that conversation with them, and it's something that we're definitely investing in at Analyst Day, we talked about, I think it was something like 20% of our customers have multiple solutions and 80% of our ARR is coming from those 20% of our customers.
I'm paraphrasing because I don't remember the exact numbers, so don't hold me on this. But that really is the way that we're using -- we're operating in our go-to-market, where we're trying to double down and sell more products to our customers who are using us.
And if I come back to the large commitments, again, just those 5 mega deals, if you will. I think one of the interesting commonalities across those deals is the fact that they were all cloud. I know you guys are focusing on sales-led subscription revenue. We'll talk to that in a second. But is there a reason for why cloud again this quarter? Was there anything behind that? Yes.
I wish I could say yes to that, but I can't. The truth is we'll meet customers where they are. And historically, the way 5 years ago, you'd say, okay, cloud is modern and self-managed is legacy. For us, it's different. Our self-managed business is very frequently that customers are taking a license to our software and they're deploying it in their hyper modern cloud infrastructure to do some sort of AI use case with it. So it's not that self-managed is legacy for us. It can be just as modern as the cloud can be. And we really, our goal is to meet our customers where they are. If they want to buy us to the cloud, we'll sell to them through the cloud. If they want to buy to us through serverless, which is our next evolution of the cloud product, we'll sell them there. And if they want to buy through self-managed, we're happy to do that as well.
And I know the team has also been and this is shifting over to metrics a little bit now. But the team has been consistent in recent quarters as far as saying like, hey, sales-led subscription revenue is what you guys should buy us to that is how we incentivize and build this business. right? Can you just remind us for the audience, what is the calculation behind that? And why should that be our North Star when assessing the success of Elastic?
Yes. It's effectively, it's all of the subscription revenue, excluding the monthly cloud business. The monthly cloud is what tends to be SMB and it's self-serve business. And so the reason that we're focused on that part of the business is what we control. As we go through our forecast calls every week, as we think about our go-to-market motion as we incentivize our salespeople, they're not incentivized for cloud versus self-managed. They retire quota on both of those. And when we're thinking about our forecast, we're really thinking about our forecast for our commitments on both those basises.
And so we're investing and driving our go-to-market motion to support all of the sales-led subscription and less so for the monthly cloud.
I was going to ask just another question, too. Like there's been -- just with how the AI stack continues to evolve. I remember it was very topical middle of last year, there was talk about people actually repatriating data into their own private data centers or on-prem data centers for cost containment perspective, right? Is that part of the calculus here as well? Are you seeing that play out? Or no, that's not -- again, you just meet the customer where they are, you give them.
Yes. I think it's that we meet the customer where they are, and we've always had that, and we're not seeing it as much for ourselves because we offer that flexibility. But we've heard of other players in the market who are now saying that they need to have a self-managed option because customers, especially who are doing AI, are wanting that option. And so I think that by offering this, we've kind of given customers an opportunity to use our products, however they want, which is as things have evolved, it's actually played out to our benefit.
Do you have -- like I'd be interested what the percentage of your customer base is. Would it even make sense for a customer to deploy Elastic in both self-managed and Elastic Cloud setting?
Some customers do. It will depend how they want to use us, but some customers do.
Interesting. I'll turn it over. Any questions? I know I got more to go on my side, but all right, we'll keep it going. One of the things that I know a lot of people were excited about, I'll give it to you from my standpoint. We went to the Analyst Day, you guys took up the guidance, and then there was a ton of joy around that. And then, all right, what are we going to be take up numbers. Then we get to the next quarter and you guys took up numbers again.
So congratulations. I'll start with that. What gives you guys the confidence? What is it you see from a demand side perspective that instills that confidence that you guys have in the business today?
Yes. I mean we took the -- from before the Analyst Day until after Q2, we added $34 million to our top line guide, which is about 2 points of growth. So the reason we did that is because of the strength that we're seeing in the business because of not just the commitments that we've got today, but the demand environment as we look at our pipeline and as we see the way that the selling motion is working.
So we've just seen a lot of strength in the business. We've seen head-to-head customer wins where the product is really showing a lot of market interest and competitive differentiation relative to our peers. And so we looked at that. We looked at what we're seeing, and it was pretty clear to us that it made sense to raise our guidance.
And then the other thing, it just feels like ancient history at this point, but like we just had the longest government shutdown, right? So can you talk about federal exposure that you guys have, maybe feather in commentary on the SI deal just for the sake of the audience as well.
Yes. So I'd say that we've got a similar amount of federal exposure as other infrastructure software players like ourselves do. There are obviously some who have more than us and probably some who have less. But I'd say that having been on the other side, while I dealt with a lot of companies as an investment banker, we're not out of line with kind of where infrastructure software companies are exposed.
When the federal shutdown happened in October, there were some deals that didn't get closed because of the Fed shutdown. Those deals have subsequently been closed. So very happy to see that, and that is going to play through in terms of how that impacts Q3 revenue. And then just thinking about what we see in the demand environment and how we've forecast our business based on the likelihood of more impacts to the Fed. I think that we've got continuing resolution through January 30. And so when we put together our guidance, the assumption we had is that there is risk that you'd see another government shutdown. I hope it doesn't happen. I hope it doesn't become a regular part of doing business, but we're not discounting that as a possibility. And so as you think about our guidance for the full year, that's factored in.
And from where we -- sorry...
I was going to about CISO, go ahead.
Ask about CISO.
We're already on the topic.
So CISO was a tremendously successful deal where we signed a $26 million cloud commitment with CISO, and they've got the ability to utilize our cloud services to serve other federal agencies. It's $26 million for 1 year. it can -- the way it works is a little bit, there are some subtleties to it where they effectively have 1 year to deploy the $26 million. And then from the time of deployment, there's 1 year to use the $26 million. And then it will be effective, but it's effectively $26 million of annual usage.
Okay. I understand the mechanics there. Remind me how that's going to be recognized from a revenue standpoint. So it needs to be deployed in the next 12 months.
Yes, it needs to be deployed in the next 12 months. The cloud deployment, it's the clock starts and they have 12 months to use the amount of dollars that have been deployed for them. So it's effectively like they've committed to buying $26 million worth of subscriptions, and those subscriptions can start any time in the next 12 months. And then once they start, we're going to recognize revenue based on the consumption that they have towards the cloud commitments they make.
Excellent. Okay. And then we're saying that there's been a catch-up as far as the deals that might have gotten pushed out during that.
Those are going to be closed, yes.
So that's all in the rearview mirror at this point.
All in the rearview mirror.
With where we are, and I know we're talking about a CR, who knows what happens at the end of this month. But from where we sit today, how is the tempo or tone of conversations, the demand environment been from PubSec specifically?
We've seen positivity out of the public sector. We talked about it, and we talked about the positivity that we're seeing when we announced earnings in November, and there's been no change since then.
On the SMB side of the house, again, not part of the sales-led subscription revenue that you guided to. Is there any change -- like what would -- is that just out of your hands? And so as a result, that's why it's less of a focus? Has there been any meaningful change?
I don't think it's out of our hands. I think there are things that we can do in the product to help make it more SMB friendly as you think about serverless that makes it easier for smaller customers to adopt and get online because they don't have to provision and manage the infrastructure that underlies the subscription.
So I think that there are things that we're doing that make it easier for SMB customers to get up and running and to use our products more. But in terms of the go-to-market motion and where we're really putting big dollars behind, we're having less impact on the SMB, the self-serve motion through that. And so that's why we're more focused on the sales-led subscription.
And then last couple of points here with the time we have left. If I could just cycle back to competition for a second, please. Again, announcement comes out that Palo acquiring Cronosphere, we're going to get it. I'd be willing that you already got it. Did you ever overlap or run into Cronosphere competitively? What is that?
We actually partnered with Cronosphere a little bit. So we didn't see them as wildly competitive. They have a strong metrics solution. That's the core of their business. They tended to work in metrics and have some big customers there. And I think they'll be more competitive with some of the more metrics-centered observability players. We didn't -- they weren't competing in our core business in the logging part of observability nearly as much as they were in metrics. And we play in metrics and we compete in metrics, but logging is probably where our biggest strength and differentiation in observability lies.
Yes. And again, just to take it full cycle, but come back to your earlier response on the point, like you guys have been preaching this whole idea of a unified, hey, we can tie together observability and security.
So this is just another validation of your view and at the same time, your differentiation is the fact that you guys are on one single data plane.
Exactly.
Instead of coming from 2.
I couldn't say it better myself, Doug.
What you said. I'm just reiterating. No, but that's it. I think that's all we have time for, but thank you very much, Eric, and thank you to the audience.
Thank you.
Thank you for joining.
Elastic NV — Barclays 23rd Annual Global Technology Conference
1. Question Answer
Welcome to our first session. I'm really happy to have the team from Elastic here. Ash, Eric, thanks for joining us.
Maybe let's start like to get everyone grounded, like Ash, you reported some really good numbers last week. From -- a couple of weeks ago, yes. What was the highlight from your perspective? Like just -- what you saw?
So Q2 for us, probably the most interesting thing about Q2 was very strong commitments from customers. The way our business is set up is fundamentally our sales-driven motion is the primary motion for our go-to-market. And customers make commitments, whether it's on cloud or self-managed, doesn't really matter from our perspective. And those commitments then turn into revenue over the next 12 months as consumption happens. And we saw really strong commitments across the board. Some of the largest $1 million-plus deals that we've ever done, 2 deals that were over $20 million in total contract value, 5 total that were over $10 million and 30-plus deals that were $1 million deals.
So really good momentum in the sales organization. In terms of the business areas that we continue to see strength in, AI is our fastest-growing part of our business. We saw that continue to play out well. And then 2 of the largest deals were security deals. So we are now doing very meaningful displacements of incumbents. Both the $20-plus million deals were security. The largest was the one that we publicly talked about. This was at CISA, which is the government agency in the U.S. responsible for infrastructure and cybersecurity for all civilian agencies. And then the other was a large chemicals manufacturer that basically picked us for XDR. So that includes not just SIEM, but also endpoint protection.
And we won that deal against just about every incumbent, every endpoint security and XDR player out there. So we are seeing good momentum on areas -- on those 2 areas. Observability continue to do well. 2 of the top 10 deals -- sorry, $10-plus million deals were observability deals. So broad strength in the business. Consumption was strong. The only one thing that affected us a little bit was in the public sector in the U.S. because we had the shutdown that affected the last month of Q2 for us. And so some renewals where the customers are continuing to use our product basically did not close in Q2. And there were situations where they are still using it.
So the renewals are just going to happen in Q3, but there was literally nobody there to process the orders. And so that just shifts some revenue from Q2 to Q3. And we talked about it in the quarter, roughly, it would have added maybe 1 percentage point of revenue growth, but that was the magnitude. It doesn't affect the full year. It just shifts it from Q2 to Q3. But overall, momentum was strong. That gave us the confidence to raise the guide for the full year. And we feel really good about how we are tracking to the overall model that we laid out at Financial Analyst Day.
Yes, yes. And then the -- how does -- it does look like it's for you guys kind of coming together really nicely. How does it feel in terms of end demand in general though? Because like we had at the beginning of the year, the tariffs and all the uncertainties, et cetera. When you talk to customers, where are they in the head in terms of thinking -- in terms of spending, sorry, yes.
No, no, no, absolutely. So across the board, we are seeing continued strength in demand. And even with the tariffs, like we had the same kind of questions of how is this going to affect buying behavior? And what we saw was it hasn't really changed buying behavior. If anything, some of the geopolitical happenings has resulted in public sector purchasing in Europe pick up. And that is interesting because we do a lot of work in public sector, not just here in the U.S., but globally.
We get used for both search, observability and security, all 3 use cases. And given our roots as a Dutch company, we are seeing good success in Europe as well because of that reason. So overall, demand remains very strong. Even in U.S. public sector, in spite of the shutdown, what we saw was just movement of stuff because of renewal timing and so on. But other than that, like the demand just continued to be very good.
On that, that was my next question on U.S. federal. Obviously, at the beginning of the year, you had [ DoD, ] but like it's all about efficiencies, doing stuff better, getting -- doing it more cost effectively as well. And you guys have a good solution, but you've always had like a good pricing model. Like does that, in theory, mean like there's more discussions going on with them?
Yes. So there were a few impacts of that [ DoD ] happening that happened. That was more early part of the fiscal year, maybe even towards the end of the last fiscal year. What -- initially, there were 2 impacts to it. Like first was there were some agencies that were affected, right? There were some agencies whose entire budgets were decimated and so on. So that did have some effect on us, and it was relatively small. It's all public information. You can go and look at what contracts were canceled and so on. So you can see that for us, the impact wasn't very, very large, but we saw some of that.
There was obviously a lot of uncertainty in those days on nobody knew what they were allowed to do effectively. But as that settled down and as the administration has fully settled in, there is a true desire to move faster in terms of modernizing, in terms of really moving to platforms that can be more efficient. Like you rightly said, Raimo, that has been one of our greatest strengths, both the capabilities that we offer, but the pricing model that we have that is very customer-friendly. And that has really opened a lot of doors. I mean the CISA deal is a perfect example of that. So with CISA, they've been a customer of ours for a long time. But this is a situation where they basically are now offering Elastic SIEM as a service to other agencies within the U.S. federal government.
And so that's something that they've never done before. So rather than -- because they are like the group that defines what cybersecurity means for all civilian agencies, they don't do anything with the Department of Defense. But with the civilian agencies, like they are the ones who define the standards and everything. But now they are offering this as a service. This is pretty unique. We are very excited about this. So we'll be working with them over the next many quarters and years to make sure that we keep building this up because we feel that this is a beachhead that's going to allow us to keep growing our business in a very, very healthy way for a long time to come.
Yes. Okay. Perfect. And then I wanted to switch gears a little bit. Obviously, AI is a big topic for everyone at the moment. I remember when in the early days of then that team came up, it was all about vector and vector database and who are the vector database and who can do more and stuff like that. How has that discussion evolved?
So there are 2 things that have happened. So first is in terms of the companies that are moving fastest with building AI capabilities, the ones that are moving the fastest are the ones that are ISVs, companies, not just AI native companies, but even software businesses that have been around for a long time that are trying to -- working hard to infuse AI into their product, into their capabilities. They might be building copilots. They might be building their own agents. They might be building AI-based automation into their products. They're the ones who are moving fastest because they understand their software stack. They have more sophisticated engineering talent. And we are doing a lot of work with them.
Like we've talked about the work that we've done with DocuSign and IBM and so on, but there are many, many more, right? So that is a very fertile ground for us. And we grow as their usage grows, which is a great thing for us. And then within enterprises, what we are seeing is the shift has happened from people basically just using semantic search or starting with semantic search, vector search to now trying to build more complete applications. And those can be chatbots, those can be applications that take certain simple tasks or actions. In security, we are seeing people build security automation, like what people would think of a SOAR in the past. That used to be quite static.
Now people are building agents that can automate certain actions. So it just relieves the burden on their teams. So it's all about efficiency in those use cases. And for that reason, when you're building those kinds of use cases, what -- what is becoming more and more important is a complete platform to let them do that entirety of work. That is everything from bringing in that data, turning it into embeddings, using various search techniques, including vector search, but then having an interface that allows them to operate on that data, take actions on that data. And that was the genesis of Agent Builder.
So Agent Builder came about that this was the capability that we announced at Financial Analyst Day. It's now out in the field. It's in technical preview. We expect it to go GA soon. But fundamentally, the idea here is you start to build agents directly on top of your data because data, the context is what gives LLMs meaning in what they need to do. And that's the secret sauce for most businesses. So that's what the trend that we are seeing now.
And remember like a year ago, there was like POCs left, right and center. Someone talks about POC graveyard as like the new term. Like where are we in terms of taking these kind of POCs and then just getting them in production? Like -- and you gave a couple of examples already, but do you see that as a trend that we just need to be aware of the time line?
I think everybody is building something. Most people have had at least 1 or 2 applications in production at this point. So we are definitely seeing production -- live production scenarios across many, many customers. And when you have over 2,000 customers like we've talked about in cloud only that are using us for these kinds of use cases, that tends to -- you can imagine that there's going to be a large number of that base that is in production, especially given that we have hundreds of them that are in our $100,000 cohort that are spending a fair bit of money with us.
So these are all production use cases. I'd say, Raimo, the biggest thing that most people should appreciate is we are still early in the number of applications that most organizations have automated. So that will also grow, right? So you think about like the way I would maybe interpret the question is, think in terms of traditional applications that were being used for any kind of automation, whether it was Salesforce automation or financial ERP automation, like there are hundreds of different modules that we use in any given business.
With AI, you are still at the 1 to 2, 1 to 10 stage. We haven't gotten to the point where you have dozens and dozens of these kinds of applications that have been created. So penetration into an account becomes incredibly important because that's your landing spot.
Once you're in there and you are the standard, then you're going to grow with them as they grow. And that's really what we're seeing. So we are seeing contribution from the cohort. And at the Analyst Day, we talked about the fact that the cohort of customers that's using us for AI is growing roughly about 5% faster than the rest of the cohorts.
And then maybe one for Eric. like as you think about more AI adoption, like how do we think about pricing? And I think it's different for you, like for some of the other guys, it's like token usage, but you're more of the provider for data, et cetera, for that. Like -- but how does pricing fit into that AI story?
We don't have a specific AI SKU. And so there's not going to be a price that you pay to utilize a certain amount of AI. The way that it works is as you adopt -- well, first off, as you adopt AI, you tend to move to higher levels of functionality. So you might need to use enterprise versus gold or platinum. And that in and of itself raises prices in terms of what you're consuming. And then further, as you adopt AI, you're going to bring more data onto your platform, which means that you're going to be using more data, you're going to be ingesting more data.
So the way that we think about AI sort of benefiting our pricing and the dollars that we're going to bring into the ecosystem is there going to be new use cases which are going to be just net new things that we're going to be able to monetize. There's going to be more data running through use cases because you're utilizing all the Gen AI capabilities, and that's going to drive more data consumption and more data volume. And then the third thing is you're going to have to move to a higher tier of functionality in order to utilize some of the AI capabilities.
Yes. Okay. Perfect. And then at the Analyst Day, you talked about the opportunity in the different segments. The one question I get from investors a lot is like you -- in a way, if you think about your product evolution, product development, you have like the platform capabilities, but then you also have like the capabilities in the observability, security. I'm missing one search. How do you prioritize that? That's kind of the one thing for me all the time, like how do you go about that in terms of like, okay, 20% needs to go here and 20% somewhere else? Or like how do you go about that?
Yes. So I think the most important thing to first appreciate is that there is a reason why we are in these 3 precise categories in these 3 areas and not in other business areas. The common theme in all 3 of these is the data tends to be unstructured and messy. And a search platform like ours, like at the heart of our platform, what is different about us is we are a search engine. We're a search platform. And that allows us to work with messy data better than any database would. It doesn't matter if it's a SQL database or a NoSQL database. Fundamentally, those systems aren't designed -- they're designed for schema-based operations. Our system is designed for data that does not have any inherent schema in it. And that's really the big difference.
So security, why are we in security? Because the data tends to be logs, the data tends to be telemetry that's coming from all kinds of devices. It doesn't have a well-defined schema. And so to be able to connect the dots between all of those different data types is a really, really hard data problem. And that's the reason why you are seeing a pretty significant turnover that's happening in legacy SIEM providers where people are moving away from them because they're having all kinds of data challenges. The same with observability. Logs tend to be very, very messy. Metrics, less so. Metrics are simpler data types, but logs and observability tend to be very, very messy. And that's the reason why we are in these 3 areas.
Now getting to your question of how we think about resource allocation, the simple model is we should have the platform become capable of dealing with the fundamental problems that exist in the segments that we play in. So over 60% of our investment actually goes into the platform. And that is an incredibly high leverage model because just to give you an example, when we are -- when we build something like our vector database and we invest in that vector database and we build it in such a way that it's directly in the platform, that is now used for product components like Agent builder for you to build AI chatbots or for e-commerce search, which is more traditional, the business that Elastic kind of started with or it can be used for building things like detecting significant events directly from your log data for observability. So just from the logs without the human needing to create any alerts or rules, we can infer potential issues in the data.
It is the same vector database that is being used under the covers for doing things like attack discovery, where we can look at all the alerts that you're getting, enrich that data in your SIEM and correlate it to basically figure out what are the connected patterns within those alerts that tell you, hey, this is an APT32 style attack that's happening. And all of it is being done on that same component. So that is massively powerful for us. So the actual investment that we have to put into either security or observability or search ends up being a fraction of what any other organization would because the core is that much robust. So it's a fat platform with small solution layers on top. And that has worked incredibly well for us.
So we think of them as power plays, like in sports analogies like if I do one thing, it's going to help me in 3 different ways. Like that's the way we think about it. And there's like searchable snapshots was another example of that. When we built that feature, it was massively useful for observability. It was massively useful for security. It didn't help us that much in search, but that's okay. You have like one feature that we are building into the platform that's helping us in so many meaningful ways. And that's how we think about resource allocation.
And then related to that is then like how do you think about the growth you get from that? And like -- and yes, maybe we go by the 3 groups like observability, security, search.
So I have a pretty ruthless model on this where the model is like we have GMs for each of the areas. Their job is to drive the business case and make the -- it's like -- it's a resource allocation equation. And I don't really care which one grows faster. Like my favorite child is the one that's growing fastest. And we do think forward and we look at like forward-leaning investments that we make strategically. But each group has the mindset that you need to succeed on your own. And it's not that we are going to keep funding you just because we believe that this business should grow at x because what matters most is really driving the total growth of the company towards and beyond the midterm model that we laid out at Financial Analyst Day.
We unveiled that at Financial Analyst Day, but internally, we've had that kind of thinking within the company. And then the different groups, if they are able to run faster, if they're able to grow faster, they get more investment. If they are, for whatever reason, not able to because they need to build some additional features to become more competitive, then we might say, okay, well, let's get that right first before we add more fuel to the fire. But the whole, the goal is grow that like we've talked about. We've talked about Rule of 40. We've talked about getting past 20% growth as we look at sales net subscription revenue. And all of that is like the way we run the business.
And the -- as part of that on the Analyst Day, there was like -- I think it was like, if I remember correct, like 15%, close to 5% from AI. Is that just going back to that 5% point that you mentioned earlier that people that are using you are kind of just using more? Or is there other factors that we should consider?
No. So, a, we are getting new customers all the time. So one of the changes that we made in the sales organization was Q1 of last -- of FY '25, when we reorganized our teams and the segmentation, we made the segmentation changes. One pretty critical element of that was to create very focused hunting territories that were hunters that would go after greenfield accounts, accounts that we had never done any business in. And the goal for that was to go after new logo generation in a meaningful way. And this was not just SMB, which we do through our self-service cloud, but really like go after the mid-market, go after enterprises because even today, we have 40% of the Fortune 100 isn't a customer. Why? I want to get that to be a customer, right? So that's the mindset. And you have to drive that through the sales organization.
So we are seeing new customers come on. AI's growth will come from that as well. But that equation that we had talked about was purely for -- from a cohort perspective, right? So if you take the existing cohorts and the rate at which they were growing, what the analysis that we've done looking back for a period of time is the cohort that is using us for AI is growing at least 5% faster than everybody else. And so it was one way to think about the over 20% model, and there are multiple paths that we are working on. So it's not just about expansion of current customers. It's about the new logos that we are signing up. It's about expansion across multiple use cases. So all of that plays in. Our model is basically a land-and-expand model.
And then you mentioned the changes on go-to-market already as well. Like one of the other thing was just to be if I remember correctly from last year, like deeper on account coverage and how many accounts per sales rep. Like last year, that caused some disruption, like now that everything is settled down, like what do you see there in terms of results?
So I think the data kind of speaks for itself. We've done more million-dollar deals, larger deals like -- and you can see that in the numbers, the $100,000 cohorts and the growth in that. And just the sizes of deals gives us a lot of confidence that we are getting deeper into accounts. We are doing more meaningful larger accounts. Like the CISA kind of deal would not have happened if we hadn't made some of those changes, right? Because to get into that situation where we get a customer that's been using us for many years, but has been using us like they were a 7-figure customer, but had never gotten to the scale that they are now. For them to not only use us in bigger ways, but champion us and build a service with us that they can take and sell to others, that contract is just going to keep growing, right? And it's a 1-plus option year contract.
So the potential in that is much more than the number that we've talked about. So it's a wonderful opportunity. I think the model has settled in. We are seeing the right kind of behavior from the teams. And all of that, honestly, Raimo, fed into the confidence because our pipeline is very strong. So when we raised for the full year, it was not just based on the business that we've already closed and the contracts that we've already signed, but even what we see in the pipeline, and the signs are really good.
Yes. Let me just add one more thing to that. I think that Mark talked about this a little bit at Analyst Day, but we also saw a meaningful uptick in productivity in terms of what our sales force was able to generate on a per person basis. And we saw a really nice improvement in sales efficiency. And that's why as we look at our business today, we view the go-to-market motion 5 quarters after the issues that happened in Q1 of '25 being very investable. And that's why we've been adding to the headcount because we've seen success, we've seen repeatability. We've seen productivity and efficiency in that go-to-market. And so now we're deploying more sales capacity.
Yes. So that should be exciting because you have now have hunters, which you didn't -- so that gives you new accounts and you have like the more coverage there on the sales. On that note, how do you think about -- how do you think about like investments then going forward? Is that -- like is it -- are you looking at the signals on productivity and that just drives where you want to go? Or do you -- is it more driven on the growth that you want to achieve the old sales force model I just throw bodies at it? Like how do you think about that kind of dynamic there?
Yes. I think it's a mix of both. I think that we want to see sustained productivity, and we want to see that as we add to the sales force, as we add capacity into the model that people are able to continue to be productive and continue to be efficient. If we see a big step backwards, that would obviously be a signal to us of something negative. But we've been seeing quite the opposite. We've been seeing a ton of strength in productivity.
The business model is actually getting more efficient. And so that's why we're investing. Hopefully, as we continue to see the strength that we have in the product, where across all 3 of the solutions, we're seeing Gen AI benefit us. It's expanding our TAM in search, obviously, but it's also making us more competitive in security and in observability. As we see that continue where the product is really very sellable and as the go-to-market motion as Mark is really driving this replicable and efficient model, we're going to continue to deploy capacity.
And how long does it take -- like in theory, I would assume there's also some even more productivity gains because if I remember correctly, you kind of reduced the number of accounts per senior sales rep, but those that they lost went to someone else, but that person needs to ramp up, build pipeline, et cetera. So in theory, we should have like even the secondary effect coming at some point -- while it should be pretty much now coming...
I think the best way to think about it is, let's say that there were -- each rep had -- and I'm just making up numbers, but order of magnitude, not totally off. Let's say a rep had 25 accounts, enterprise accounts, maybe we had business in 5 or 6 of them and the others were greenfield where we had never done business. We basically kept the 5 to 6 that they had -- that we had in ARR and maybe give them 1 more or 1 or 2 more. So brought their number down to between 5 and 8. And then everything else that was greenfield, we moved to these 100 territories. The thing with 100 territories is it takes time to build that pipeline. Now the difference is now there is a person who only makes money if they close business in that new account. That is a different mindset than the prior model.
In the prior model, what ends up happening is human beings tend to follow the path of least resistance. So if I have existing business in 5 to 6 of these accounts, I'm just going to try and grow that. So expansion continues to be good, but you don't get new logos. And so part of this was to explicitly -- because, look, we can't become a multibillion-dollar company if we don't make some of these fundamental changes. So that was part of the reason why we did it. But you're exactly right that even now, we are just starting to see the benefit of the hunting motion kick in.
So there is more of that benefit to come. And we -- so it's not about just throwing bodies, like one thing that I am very focused on is growth is most important because in the long term, like it really shapes the business. But it's equally important to be continually improving your profitability every year. And so part of the focus is to make sure that we really get that productivity model right because that's the biggest lever. We can make every rep more productive. That means investing in better training. It means investing in better tooling. That's all part of what Mark's been driving for the last 6, 7 quarters. And it's -- we're really seeing the benefits.
And then I realize like we could have gone on for a longer. We have like a minute left, Eric, for you. On the margin side, the -- we've seen the improvements as an organization, like on the other hand, you're kind of investing into growth and want to do more stuff. Like how do you do that? It sounds almost too good to be true.
Well, the goal is to have a measured approach and to look at both profitability and growth and to weigh them against each other. At the Analyst Day, Navam talked a lot about our journey along the Rule of 40. So he emphasized that as well as this motion to get to the 20% plus sales-led subscription growth. And so every year, we look at our business, we see where we can invest and where we can drive really positive returns from that investment. We weigh that against maintaining both the growth and sustainable growth as well as continuing to increase our margin.
And we've been working towards that. And if you look at the last multiple years now, you've continually seen us have a sustained increase in our margin profile while maintaining the strong growth that we've had. And that's sort of the path that we've been on and that we'll continue to be on as we get to that Rule of 40 and beyond in conjunction with this march towards the 20% plus sales-led subscription.
Perfect. That's a great summary as well. Ash, Eric, really enjoyed our conversation. Thank you...
Thank you.
Always a pleasure.
Thank you
Elastic NV — Q2 2026 Earnings Call
1. Management Discussion
Good day, and welcome to the Elastic N.V. Second Quarter Fiscal 2026 Earnings Results Conference Call. [Operator Instructions] Please note, this event is being recorded. I would now like to turn the conference over to Eric Prengel, GVP of Finance. Please go ahead.
Thank you. Good afternoon, and thank you for joining us on today's conference call to discuss Elastic's Second Quarter Fiscal 2026 Financial Results. On the call, we have Ash Kulkarni, Chief Executive Officer; and Navam Welihinda, Chief Financial Officer. Following their prepared remarks, we will take questions. Our press release was issued today after the close of market and is posted on our website. Slides, which are supplemental to the call, can also be found on the Elastic Investor Relations website at ir.elastic.co. Our discussion will include forward-looking statements, which may include predictions, estimates, our expectations regarding demand for our products and solutions and our future revenue and other information. These forward-looking statements are based on factors currently known to us, speak only as of the date of this call and are subject to risks and uncertainties that could cause actual results to differ materially.
We disclaim any obligation to update or revise these forward-looking statements unless required by law. Please refer to the risks and uncertainties included in the press release that we issued earlier today, included in the slides posted on the Investor Relations website and those more fully described in our filings with the Securities and Exchange Commission. We will also discuss certain non-GAAP financial measures. Disclosures regarding non-GAAP measures, including reconciliations with the most comparable GAAP measures, can be found in the press release and slides. Unless specifically noted otherwise, all results and comparisons are on a fiscal year-over-year basis.
The webcast replay of this call will be available on our company website under the Investor Relations link. Our third quarter fiscal 2026 quiet period begins at the close of business on Friday, January 16, 2026. We will be participating in Barclays Global Technology Conference on December 10 and the Needham Growth Conference on January 14. With that, I'll turn it over to Ash.
Thank you, Eric, and thank you, everyone, for joining us on today's call. Q2 was an outstanding quarter for Elastic, driven by robust growth across the company with AI positively impacting all areas of our business. We beat the high end of our guidance across all metrics, delivering revenue growth of 16% and a non-GAAP operating margin of 16.5%. Our team drove strong execution, achieving sales-led subscription revenue growth of 18% with strength in both Elastic Cloud and our self-managed offerings. We also increased the number of customers spending over $100,000 with us to more than 1,600 at quarter end.
The importance of data, especially unstructured data is growing at an unprecedented rate as enterprises continue to expand their use of AI. The Elastic platform, with its ability to sift through and find relevant insights in petabytes of structured and unstructured data in real time is uniquely suited to address the need for context in this age of AI. This ability is driving the acceleration and adoption of the Elastic platform by organizations for their search, AI, observability and security needs. In Q2, we secured significant customer commitments across all solution areas. We maintained strong momentum in search and AI while also seeing an uptick in platform consolidation for security and observability with an increasing number of customers migrating from legacy products to our platform.
These factors led to an acceleration in the number of large deals we were able to secure this quarter. In Q2, we signed over 30 commitments valued over $1 million in annual commitment value with 5 representing over $10 million in total contract value. Of these 5 deals, 2 were greater than $20 million, a new record this quarter. In Q1 2025, we strategically realigned our sales team to focus capacity on our highest value opportunities. This quarter marked the fifth consecutive quarter of disciplined sales execution, demonstrating our continued commitment to driving enhanced performance and consistency across the field.
These increasingly larger commitments are exemplified by an 8-figure new logo deal where Elastic Security was chosen by one of the largest chemical manufacturers in the world. The company initiated a competitive search to replace its fragmented security tools and simplify its IT infrastructure, seeking an XDR platform that could deliver advanced threat protection and a 35% increase in operational efficiency. Elastic prevailed against multiple competitors. We demonstrated superior capabilities by detecting threats overlooked by all other solutions. The customer chose Elastic due to the proven effectiveness of our technology, our open ecosystem and ability to scale across their global operations. With the customer now progressing towards an AI-driven SOC, we believe our AI features will enable them to realize even more ambitious efficiency targets.
Building on our momentum in security, our leadership in next-gen SIEM led to a $26 million commitment with CISA, the U.S. federal agency responsible for safeguarding critical civilian infrastructure. CISA selected Elastic Security on Elastic Cloud for a unified SIEM as-a-service offering that will help to secure U.S. federal civilian agencies. This program will standardize security data collection, enabling real-time threat detection and rapid incident response across agencies while leveraging our standards-based highly efficient platform to significantly reduce costs associated with data access and retention. We architected our next-gen SIEM solution, knowing that security is fundamentally a data problem, one our Search AI platform is uniquely suited to solve.
Capabilities like attack discovery, ESQL and cross-cluster search help analysts investigate incidents and correlate events across environments without manually aggregating data or switching contexts, accelerating detection, response and forensic analysis. Our ability to overcome complex data challenges by unlocking the value of unstructured data is directly linked to our continuing success in generative AI. In Q2, we saw strong demand for our platform as an increasing number of customers adopted Elastic for developing semantic search and Agentic applications. Our deep expertise in managing unstructured data, combined with our clear product differentiation and context engineering leadership positions Elastic as the natural choice for building Gen AI applications.
This has led to widespread adoption and successful deal closures across numerous industries, addressing a wide variety of use cases. For example, a global financial institution operating in over 100 countries expanded its use of Elastic search in a 7-figure deal. This customer leverages the full Elastic platform in a self-managed environment for hundreds of use cases. Their search capabilities continue to grow as they centralized unstructured data to power insights for customer and employee-facing applications. Previously, they attempted to leverage a hyperscalers Copilot product, but it did not surface sufficient relevant results. Now they are using Elastic search as their context engineering platform, paired with an LLM for their internal AI applications.
Elastic's ability to ensure accurate context and relevance has improved their results, and they are preparing to move the application into production. Our leadership in context engineering and relevance is translating directly into significant GenAI customer adoption. In Q2, new customer commitments with GenAI continued to grow. We signed 4 Gen AI deals that included new business of greater than $1 million in annual contract value. We now have over 2,450 customers on Elastic Cloud using us for Gen AI use cases with over 370 of these amongst our cohort of customers spending $100,000 or more with us annually, representing nearly 1/4 of our greater than $100,000 ACV customer cohort leveraging Elastic for GenAI use cases.
In another GenAI win from Q2, a global supply chain software provider expanded its use of Elastic search in an 8-figure deal to leverage our AI and vector search features in an embedded fashion in their key products. The customer is now also expanding the use of our platform to support future Agentic use cases. We are seeing customers expand their use of Elastic search to develop their own Agentic workflows and to further empower enterprises in adopting AI agents, we've recently introduced Agent Builder. This new product builds on the Elastic inference service and provides an out-of-the-box conversational experience, allowing users to interact directly with any data in Elastic search and extends our technology into a new frontier beyond the vector database. It embodies a truly relevant-centric approach rooted in context engineering by enabling users to explore their data and assemble the necessary tools for quickly building AI agents with robust workflow capabilities.
Agent Builder dramatically simplifies the entire operational life cycle of agents, including their development, configuration, execution, customization and observability, all directly within Elastic Search. This powerful capability strengthens our moat of broader GenAI differentiation, which is also helping us land deals in observability and security as customers grow with Elastic because of our AI features. An increase in AI-based security threats fueled a large expansion deal with one of the world's leading investment management companies. They are deploying our AI capabilities to proactively combat evolving attacks. This customer expanded its use of Elastic Security to enhance runtime protection with integrated AI, a critical need for securing applications. Default LLM security controls alone were insufficient. The customer required a security solution capable of evolving with their unique requirements.
Elastic's automation-first architecture provided them the ability to rapidly evolve to keep up with ever-changing security challenges. As bad actors grow in sophistication, leveraging Elastic Attack Discovery and AI assistant allows their SOC to scale their capabilities and proactively address issues. We are seeing similar success and adoption of our platform capabilities across our observability solution, in one observability win from the quarter, a leading U.S. municipal technology and innovation agency signed a 7-figure expansion deal for Elastic Observability. The agency is tasked with providing Infrastructure as a Service to all municipality offices. They launched a new project to unify the city's data in a first-class data environment to modernize operations and decision-making. They chose Elastic Observability as a foundational technology due to our flexibility, open architecture and ability to deliver cost savings at scale through features like searchable snapshots.
The agency is now leveraging our AI assistant, which helps them remediate and triage issues, reducing their reliance on external consultant services. Building on foundational components for working with observability data, we introduced Streams this quarter. Streams is an agentic AI solution that simplifies working with logs to help SRE teams rapidly understand the why behind an issue for faster resolution. Streams can automatically organize logs, find meaning and problems in logs by applying AI and the power of Elastic Search to this unstructured messy log data. In Q2, we introduced a steady set of new AI capabilities, including a number of features that improve our performance as a vector database. We introduced a managed inference service natively through Elastic Cloud.
Inference at scale is incredibly important for vector search, semantic search and GenAI workflows, and we provide our customers with an API-based inference service using NVIDIA GPUs with our vector database for low latency, high-throughput inference. We also continue to improve our vector database performance with new functionality, including the release of DiskBBQ. DiskBBQ is a new disk-friendly vector similarity search algorithm that delivers more efficient vector search at scale than traditional industry standard search techniques used in many other vector databases. And finally, we announced our acquisition of Jina AI. Jina AI has developed leading frontier-class multilingual and multimodal embedding and reranker models, helping businesses and developers build powerful search applications.
As enterprises build AI agents and develop software in new ways, defining context and grounding LLMs remains essential. This is why we have invested for years in developing our own embedding models, reranker models, data chunking strategies and more. Jina AI extends and accelerates this strategy. These advancements in AI and vector search are not isolated. They are integral to our overarching strategy of delivering a powerful and flexible platform. This commitment to innovation extends across our diverse deployment options, ensuring our customers can leverage the full potential of Elastic regardless of their preferred architecture, Elastic Cloud or self-managed. We continue to innovate, making our platform more capable across both cloud and self-managed deployment profiles.
As part of this, we made AutoOps available for the first time to our self-managed customers. AutoOps simplifies cluster management through a cloud-powered service that processes telemetry for real-time issue detection and resolution, all while ensuring the underlying customer data remains within the self-managed deployment. It is these organic innovations and strategic acquisitions that gives us the confidence to be the leading data retrieval and context engineering platform for the AI era. Just last week, IDC recognized Elastic as a leader in multiple MarketScape reports, including in the Worldwide Observability Platforms report and in the worldwide general-purpose Knowledge Discovery for Search report. In the general purpose knowledge Discovery report, we had the strongest position of any vendor in the analysis.
We are proud of this recognition, which affirms our unique ability to deliver a unified platform that solves the most complex data in AI challenges. In closing, our market opportunity is stronger than ever, driven by robust growth, clear Gen AI leadership and a unique platform built for this moment. Our foundational investments in search uniquely position Elastic to deliver AI to enterprises everywhere. I would like to thank our customers, our partners and our shareholders for their continued trust and confidence in Elastic. And to our employees, thank you for your tireless spirit of innovation. And now I'll turn it over to Navam to go through our financial results in more detail.
Thank you, Ash. Good afternoon, everyone. As you may recall, we raised our guidance for the quarter during Analyst Day on October 9, and I am pleased to report that we exceeded both the top line and profitability of that improved guidance. We saw continued broad-based demand and notable strength in commitments across all geos, supported by healthy consumption trends. As Gen AI adoption and platform consolidation continue to be top priorities for enterprises, we are seeing sustained momentum in demand for our platform reflected in the continued customer momentum and expansion in our sales pipeline during the quarter. Our total revenue in the second quarter was $423 million, representing growth of 16% as reported and 15% on a constant currency basis.
Our sales-led subscription revenue in the second quarter was $349 million, growing 18% as reported and 17% on a constant currency basis. This strong performance reflects the strategic advantages of the Elastic search AI platform in addressing critical consolidation and generative AI use cases. Our current remaining performance obligation, or CRPO, which is a portion of RPO that we expect to recognize as revenue over the next 12 months remains solid. At the end of Q2, CRPO was approximately $971 million and grew 17% as reported and 15% in constant currency over Q2 of the prior year. Our top line metrics were driven by strong consumption, deal momentum and traction with greater than $100,000 ACV customers, all 3 drivers supported by Gen AI tailwinds.
First, the primary driver of revenue was healthy consumption across solution areas. We saw steady consumption growth throughout the quarter, fueled by a strong demand environment, driven by solid organic consumption growth from existing customers as well as revenue from new customers. Second, deal momentum during the quarter was significant. As Ash referenced, we saw an uptick in consolidation and Gen AI use cases, which led to overall strength in large deals. We closed over 30 commitments greater than $1 million in annual contract value, with 5 of them representing greater than $10 million in total contract value and 2 of those greater than $20 million in total contract value.
The strength of this can be seen through RPO, which grew 19% in the quarter as reported and 17% in constant currency. Our deal momentum occurred globally in both enterprise and public sector segments. Despite the U.S. government shutdown in October, the team closed a notable win with CISA, as Ash noted earlier. In the second quarter, deal momentum continued and supported our expansion of enterprise accounts and high-propensity commercial accounts. During the quarter, our greater than $100,000 annual contract value customer count grew approximately 13%, representing approximately 180 net new customers over the past 4 quarters. Quarter-over-quarter, we added approximately 50 net new customers, and we continue to see strong expansion from our existing customer base.
Gen AI is proving to be a powerful catalyst for customer expansion. 23% of our greater than $100,000 cohort now utilizes Elastic for Gen AI use cases, an increase from 17% just 1 year ago. We see significant headroom for customers to initiate their Gen AI journey and scale into our $100,000 annual contract value cohort. Even with our existing $100,000-plus GenAI customers, adoption is in its early stages. Now turning to second quarter margins and profitability. I will discuss all measures on a non-GAAP basis. Our commitment to balancing growth with disciplined spending translated to robust operating leverage and strong bottom line results. We continue to focus on costs and efficiency in our business. We delivered subscription gross margins of 82%, total gross margins of 78% and an operating margin of 16.5%.
Our disciplined approach to costs, combined with increasing revenue underpins our strong profitability and free cash flow generation. Regarding cash flow, adjusted free cash flow was approximately $26 million in Q2, representing a margin of 6%. The second quarter is typically a seasonally low free cash flow margin quarter for us, and we manage and view adjusted free cash flow on a full year basis. For fiscal 2026, we expect to sustain the level of adjusted free cash flow margin that we achieved in fiscal 2025. In October, during our Analyst Day, we announced a $500 million share repurchase program as part of our capital allocation framework. I am pleased to say that we are already underway on our program and began returning capital to shareholders during Q2. During the quarter, we returned approximately $114 million in cash to shareholders.
This represents purchases of approximately 1.4 million shares at an average price per share of $84.45. As I mentioned at our Financial Analyst Day, we expect to use more than 50% of our $500 million authorized amount in fiscal 2026. Now for our outlook for the third quarter and the remainder of fiscal 2026. Starting this quarter, we will begin providing guidance for sales-led subscription revenue. As we detailed during our recent Analyst Day and in the past 2 quarters, sales-led subscription revenue is a key metric for measuring our success with larger strategic and enterprise accounts and high propensity commercial accounts. Sales-led subscription revenue is the fundamental driver of our financial framework, and we incentivize our sales team to meet customers where they are in cloud or in self-managed departments.
The momentum we are building in this quarter is evident. Our sales pipeline is very healthy, and it has grown throughout the year. Given the strength of our business, we are raising our full fiscal year 2026 revenue guidance. For the third quarter of fiscal 2026, we expect total revenue in the range of $437 million to $439 million, representing 15% growth at the midpoint or 13% in constant currency growth at the midpoint. We expect sales-led subscription revenue in the range of $364 million to $366 million, representing 17% growth at the midpoint or 16% in constant currency growth at the midpoint. We expect non-GAAP operating margin to be approximately 17.5%. We expect non-GAAP diluted earnings per share in the range of $0.63 to $0.65, using between $108 million and 109 million diluted weighted average ordinary shares outstanding.
For fiscal 2026, we are raising our total revenue, which improves our expected non-GAAP diluted EPS. We expect total revenue in the range of $1.715 billion to $1.721 billion, representing approximately 16% growth at the midpoint or 15% constant currency growth at the midpoint. We expect sales-led subscription revenue in the range of $1.417 billion to $1.423 billion, representing 18% growth at the midpoint or 17% in constant currency growth at the midpoint. We expect non-GAAP operating margin for the full fiscal '26 to be approximately 16.25%. We expect non-GAAP diluted earnings per share in the range of $2.40 to $2.46 using between 108 million and 110 million diluted weighted average ordinary shares outstanding.
The diluted weighted average shares outstanding reflect only share buybacks completed as of October 31, 2025. In summary, I am pleased with our second quarter results. We remain on track on our execution this fiscal year and on track to achieve the medium-term sales-led subscription revenue target growth rate we laid out during our Financial Analyst Day. Elastic stands uniquely positioned as we bring relevance to unstructured data and allow enterprises to transform data into value. Our opportunity continues to grow. With that, I'll open it up for Q&A.
[Operator Instructions] The first question comes from Matt Hedberg with RBC Capital Markets.
2. Question Answer
Great. Ash, I want to start with you. I assume you're seeing strong consumption trends from your AI native customer base. But I'm curious if you could talk about the performance of your non-AI native customers. Are they seeing an increase or an acceleration in consumption due to sort of an increased AI focus within that customer base?
Yes, that's a great question. And yes, we are seeing that it's not just the AI native cohort, but we are seeing strong consumption across the board, even in our traditional businesses and not just in search, but also in observability and security. And part of this is also that we are winning more and more commitments, like I talked about in my prepared remarks. This was a remarkable quarter in terms of the number of commitments that we were able to secure large commitments where customers are consolidating onto our platform for security, for observability. And the 5 deals that we mentioned that were all greater than $10 million in total contract value are all cloud.
So I would expect that as deals like those, as customers start to consume, we are going to start to see the benefit of that in our cloud revenue and our total revenue. And just to bring everybody's attention to the fact that when we think about our business, we think about both cloud and self-managed. And that's the reason why sales-led subscription revenue is such an important metric, and it came in at 18% this year. So very happy about it, continuing to drive the momentum. Consumption is strong, commitments are strong, and we feel really good about the rest of the year.
That's really good to hear. And then maybe for Navam, just a follow-up. All of your reported growth metrics were strong, including both CRPO and RPO, all kind of growing in the mid-teens or better. I'm curious, though, billings isn't a key metric for you guys, but it did lag some of those focus metrics. Wondering if you could talk a little bit about why that was the case.
Yes. Thanks for the question, Matt. And I agree with you, Q2 to us was a great quarter. We saw strength across the business and what matters to us is commitments and consumption and both commitments and consumption was strong. You noted correctly, CRPO grew 17% in Q2 compared to 16% last year. And also RPO grew 19%, and that was because of the strength of the multiyear commitments that we laid out. So overall, the commitment side of the business was very, very strong. Now as it pertains to your specific question on the year-over-year compare, going into the quarter, we expected variability in the second quarter for a few reasons. And one of the main reasons is seasonality. And you have to keep in mind that last year was anomalous because of a weaker Q1 commitments that we saw.
So the billings distribution, the revenue distribution in last year throughout the year was just atypical. So you can't over-index on the quarterly seasonality this year. And as a matter of fact, when you think about sort of the ACV, which doesn't have the crosscurrents of billings, the ACV growth this year-to-date is stronger than what it was last year to date, right? And that's a great sign. And then the second point I want to make was you all know there was a government shutdown that impacted our third month of the quarter impacted everybody. And that caused a few renewals, specifically self-managed renewals to slip from Q2 to Q3. But net of all that, from a commitment perspective, the business is seeing really strong commitments, consumption is going good. And also the pipeline side is seeing strong growth as well.
And that's what gave us confidence to raise the guidance for the back half of the year meaningfully. And keep in mind, since Q1, we've raised FY '26 by $34 million or 2% year-over-year, and that's mainly because of the commitment strength of the business.
The next question comes from Koji Ikeda with Bank of America.
And so definitely appreciate the newly introduced guidance for sales subscription or sales-led subscription revenue. And so I wanted to ask kind of the compositions of that. I know underlying assumptions around monthly cloud, should we assume that's roughly flat with where it was in the fiscal second quarter? And that really leaves cloud and self-managed as the other inputs. And I do think cloud is probably the more watched metric of the 2, and so I'll focus there. And so what should we assume is implied in the guide there? Is cloud growth higher, the same or lower in compared to the fiscal second quarter to get to that sales-led sub guide?
Sure. So this is the first time we're doing a sales-led subscription revenue guide. We are doing it because it's one of the most important metrics of the company. That's what we drive our salespeople to go and get commitments for both cloud and self-managed. We also detailed what our medium-term targets are for sales-led subscription revenue. So because of that, we thought it was very important to start guiding to sales-led subscription revenue in addition to disclosing sales-led subscription revenue. So in terms of what the composition of that number is, it's what our sales team drives other than the monthly cloud self-serve business, which we, as you mentioned, expect it to be moving along the SMB segment. We expect it to be flat.
So we're not -- if it grows, that's great. But our goal is to drive what the sales team delivers from a commitment perspective, which is the self-managed commitments and the cloud commitments. And our expectations for how commitments and consumption flows is detailed in the guidance side. And as I said, we're very pleased with how Q2 went, and we are very pleased with being able to raise the full year by another percentage point from just a month ago.
Got it. And maybe a follow-up, just focusing on that sales-led subscription revenue result of 18%, 17% in constant currency. Last quarter was 22%. And I know there was some cloud kind of tailwinds there, pricing tailwinds in there. So maybe excluding the pricing tailwinds, can you help us bridge the gap between the growth between the second quarter and the first quarter on sales-led sub growth? And was there any Gen AI revenue growth contributions in the second quarter this year that you can call out?
Yes. Let me maybe first start by addressing this because we've talked about this at least in the last 90 days. And I think the most important thing to understand is looking at pricing in isolation is just an incorrect way to look at our overall model. When you're looking at a consumption business, there are lots of factors that lead to an increase in consumption. First is when customers bring new workloads onto the platform, when customers increase the data that's coming into the platform, all of those things increase the consumption. At the same time, we are constantly making our platform more efficient. In the past, we've released functionality like searchable snapshots. We've released functionality like logs DB, like TSDB.
All of these things make it possible for you to execute the same workload with fewer resources when we come up with support for new instance types from the hyperscalers. That also makes our platform more efficient and sort of access something that brings down the consumption. So what we care about is -- when we look at the net of everything, including the pricing changes that we do from time to time, how is consumption tracking overall. And net of all of these things that push consumption up or push consumption down, the net consumption has been very strong. So we see our customers consuming on a really healthy way. We see them bringing new workloads onto our platform. We are capturing new commitments and new wins like the ones that we detailed, CISA is one of them. But all of those large commitments are going to turn into revenue over time. So fundamentally trying to disaggregate pricing as one element is just wrong, and I would encourage you to not look at it that way, but look at the net.
I'll also add to that what I talked about earlier, which is you have to remember that not to over-index on a single quarter because the seasonality aspects of this quarter are very different from what it was last right? And the second point I want to make is that because of the renewal slips, you are seeing self-managed revenue change its shape from the second quarter to third quarter as well.
And by the way, one thing to say about those renewal slips, those government customers are continuing to use our software. They're very happy with our software. So we just expect those renewals to come in, in Q3. There wasn't anybody that was working during that shutdown in those agencies to be able to process those orders. So those are firm customers, firm workloads for us. It's just a shift from Q2 to Q3.
The next question comes from Sanjit Singh with Morgan Stanley.
Actually, I had a 2-parter for you. If we can wind back to the go-to-market changes at the beginning of last fiscal year or the beginning of the fiscal year, sort of mark-to-market where we are from a productivity standpoint. It sounds like productivity is going well. And if that's the case, is there a case given the momentum you're seeing with commitments to drive more capacity on the sales side? So maybe we tackle that first, and then I had a follow-up.
Yes, absolutely. So you are exactly right that the changes that we made 6 quarters ago are clearly now showing bearing fruits, right? So this is the fifth quarter of strong sales execution that we've seen. The commitments are doing incredibly well. And what that means for us is both the way our sales teams are executing, the kinds of deals they are able to get across the line and what that means for our future is very, very bright. So absolutely, like we've said in the past, this is an investment year for us. We are continuing to invest both in terms of our go-to-market capacity on the selling side, but also in AI, where our engineering differentiation is helping us win these deals, not just on the search side, but also differentiate with things like streams and significant events and observability and with attack discovery and other capabilities in security. And so those are the areas where we will continue to invest, and we expect to see the returns as we go along.
And then my follow-up, Ash, is sort of on RAG. As we have the industry conversation and we talk to some leading engineering departments at innovative companies, there does seem to be a friction with RAG. There still seems to be the hallucination problem. Chunking data seems to be a complicated task, if you will. And so when it comes to like monetizing your guys' AI search capabilities, do you guys -- is there a world where you have opportunities for growth outside of RAG, maybe some of the agent builder stuff that you discussed on your script. I'd just like to get your point of view on how durable is the RAG opportunity? And then are there other ways to monetize the company's AI search capabilities outside of RAG?
Sanjit, it's really an and, not an or because the way you should think about it is, fundamentally, it's all about connecting your private data with the large language model to make that large language model actually become relevant in the context of your business and your enterprise workflows. So that's really what it's all about. Now your -- the thing that you're pointing out is building these kinds of agentic applications takes some amount of work because getting that relevance just right. And by the way, relevance has always been our sweet spot. We specialize in messy unstructured data. We specialize in relevance. This is what we've been doing the entire existence of the company.
And so we are specialists at this, and we do this better than just about anybody else. But the complexity of this whole effort is what we are continually working to simplify, and that's what Agent Builder does. Agent Builder under the covers uses our vector database, uses our hybrid search capabilities, but also comes with embedding models that we have tuned to make sure that they can perform incredibly well for that grounding to connect the LLM to your data. That was what the acquisition of Jina AI was all about to bring multilingual and multimodal capabilities to everything that we could do. So Agent Builder will absolutely be yet another way for us to monetize our core strength in context engineering, but it's going to be an and.
The next question comes from Raimo Lenschow with Barclays.
You talked about the slippage in the quarter. Like the one question I got from a lot of people was like, historically, you guys kind of beat in the quarter by a little bit more. And obviously, I appreciate we have a new CFO, so there could be a new guidance philosophy, but like -- but there also could be the slippage situation. How do you think about the quarter? I appreciate the bookings, but like on kind of cloud beat on total revenue, the beat level was kind of lower than what we've seen before. Were there any kind of puts and takes there?
Yes, Raimo, thanks for the question. You may remember that we guided the quarter in the beginning -- at the end of Q1, and we also updated that during Financial Analyst Day, which was just a month ago. And at the time, we gave you a much closer to the pin number for the quarter and the year. And as I mentioned, the second quarter was a very strong quarter. So we beat that number by $5.5 million in Q2. And we raised very, very healthily $16 million at FAD and another $34 million in total.
A total of $34 million from Q1 to Q1 for the year. So we feel the business is going very well. The guidance obviously gives you a sense -- the guidance closer to the quarter gives you a sense of where the quarter is ending. So that's the first point. The second one on the slips, this was expected variability in the quarter. Like I mentioned, we don't over-rotate on a single quarter's performance. But the renewal side, obviously, is going to come in the year, and that's reflected by our strong year. And the bookings shape is just going to be different this quarter than it was last quarter.
Okay. Perfect. And then, Ash, one for you. On the big win in Fin, is that -- do I have to think about that as like -- or maybe broader, like is this kind of like there is obviously a play that used to be strong in that space that is takeaways from that? Or like what are you seeing here in terms of fee momentum?
Yes. Actually, both of our -- the 2 largest deals this quarter were both $20-plus million security wins. And what this highlights is just the level to which our security offering has evolved and matured and the AI capabilities that we offer are absolutely unmatched. And you're seeing an organization like CISA, the cybersecurity and infrastructure security agency of the United States. I mean this agency is responsible really for shaping the direction of cybersecurity for all federal civilian agencies in the United States government and them choosing Elastic to offer a SIEM as a service on Elastic Cloud is an unbelievable endorsement.
It just shows the strength of the platform, the flexibility and capability, the AI capabilities. And as you can imagine, these kinds of agencies have been using other incumbents in the past. So this is a consolidation onto our platform. This is us taking share. This is us now really being in a place where with all the experience that we've had with our security technology, now really demonstrating what we can do. And this is very exciting the way I look at it going forward.
The next question comes from Rob Owens with Piper Sandler.
Ash, I want to build on one of your initial comments in your script about how AI is positively impacting all areas of the business. And I appreciate all of the color that you've given. And the question is really around ESRA as a percentage, both of overall customers and of large deals. And it's great to see that growing. I think it was 23% of your $100,000 deals. But why isn't that number greater if everyone has some level of proof of concept right now going on in Gen AI. Where is the unlock for Elastic relative to those types of opportunities?
Yes. That's a great question. A couple of things to keep in mind. First of all, the number that we've given is only on Elastic Cloud because that number is something for which the telemetry that we see is very, very clear, and it's sort of indisputable. For customers that are using us on self-managed, we have many customers. I gave one example of -- in my prepared remarks of a financial services institution that is using us and they're using us in a self-managed way. So for those, those are over and above the numbers that we sort of call out. So the penetration is growing. It's meaningful, like you called out, 23% in the $100,000 cohort. So we feel really good about it.
As more and more companies start to deploy more and more of these kinds of applications, I would expect our penetration to grow. I would expect the breadth of revenue that we capture from each of these accounts to grow. As Navam had outlined in our financial day -- Financial Analyst Day that happened about a month ago, in the cohort of AI users, we see them growing faster than the rest of the cohort. So that, to us, is a very important metric. We measure it, we track it. We are constantly looking to make sure that we win the AI workloads in every account. This is going to be something that we just keep working on. It's going to keep growing.
The next question comes from Brian Essex with JPMorgan.
I guess maybe, Ash, for you, I'd like to dig into the security side of the business a little bit. Would love to understand what you're seeing competitively, whether the deal wins that you're seeing are against or at the expense of more observability-focused vendors? And are you starting to see maybe what I'll call some of the next-gen security platform vendors more frequently in the marketplace? And then I have a quick follow-up.
We tend -- so when it comes to security, we tend to see all the players that you would think of. We consider ourselves to be the leading next-gen security SIEM platform out there. So from that perspective, we tend to typically be the ones displacing incumbents -- and the reason why we see that is, first and foremost, security is a data problem. I think everybody is starting to say that now. And our back-end data platform is the best in terms of the flexibility, the scalability that it offers. We were built first and foremost as a data platform, and that allows us to do the kinds of analytics that others struggle to do.
The second thing is our AI functionality. Like that, again, comes back to our core differentiation, and we are able to apply that AI depth to things like attack discovery, which are capabilities that, again, are very, very differentiated, which allows somebody to reduce massively the amount of time that it takes to do the actual threat detection and then remediation of that problem. So that's where we are seeing a lot of success displacing incumbents. On the observability side, we tend to lead with log analytics. And when it comes to log analytics, like that's where we land and then we expand into metrics and traces. So as you can imagine, the number of players that are able to do sophisticated log analytics at scale is a very small number.
And so we have a very, very differentiated advantage, especially with new AI-related features like streams, like significant events that we talked about in the Financial Analyst Day. And that's what is helping us win these deals faster. So of the 5 deals that were over $10 million, like I mentioned, 2 were security, the largest 2, 2 were observability and one of them was AI. So there is a really nice breadth of wins that we are seeing and each of our business areas is seeing great success.
Got it. Maybe just a follow-up on that point. We've seen a couple of recent acquisitions by some of the larger platform vendors. We saw the acquisition of Chronosphere last night and then a little while earlier from CrowdStrike. Any initial thoughts on those and whether or not you see those in the marketplace? Or are they maybe responding to the capabilities that you have in that space in that regard?
Yes, it's a great question. And look, we've been talking about the fact that observability and security are 2 sides of the same coin. We've been saying it now for at least the last 7 to 8 years. And it's because fundamentally, it's all about the data. The 2 things I'd say is, one, we have the best data platform, like I said, in terms of our ability to scale, in terms of our flexibility. We can bring in all kinds of telemetry, including the telemetry from these other players that you referred to, and we are able to do analysis on them. That's not something that others are able to do. So we have a tremendous way to get into accounts and then expand that others just don't share.
The second thing is we've been at this for the last 8 years, and we've built out our security capabilities, our observability capabilities. So we are way ahead of everybody in terms of our AI functionality, in terms of our ability to bring in all signal types and observability, whether it's logs, metrics, traces in one single platform. So it's a great validation, first and foremost, that others are trying to emulate us. But it also means that our advantage in terms of us being in this for so long is just showing fruits in terms of the wins that we are seeing in terms of the customer commitments, and I expect that to continue.
The next question comes from Tyler Radke with Citi.
You talked about, in prior quarters, how you introduced some product optimizations into the platforms like the logs DB product, which cut storage costs for customers that took advantage of that. I was just wondering if you could tie in that dynamic into sort of the cloud revenue trajectory? Because obviously, last quarter, you saw some of the pricing dynamics impacted and I imagine the optimization side impacted that as well.
But I guess the question is, are most customers kind of through that optimization in terms of adopting the logs DB product and now you're starting to see those come on in terms of greater use cases and greater commitments and perhaps that can sort of drive an acceleration in the cloud growth sequentially just as they've been able to kind of optimize and bring on new use cases?
Yes, that's a great question. Look, the first thing I'd say is overall data growth is just expanding at an unbelievable pace, right? So the reason why we are constantly introducing features that make the platform more and more efficient is because without us doing that, it would be just near impossible for anybody to be able to really store and analyze all the data that they're generating. Data volumes in most organizations is doubling, tripling every year. And it just does not make sense for them to be able to manage all of that. So making the platform more efficient does 2 things.
One, it allows customers to keep up and continue to use our platform in more ways. And second, it makes our platform more attractive for customers to bring other workloads from other observability vendors, from other security vendors onto our platform because we become a much more efficient way for them to do all the analysis that they might have been paying somebody a lot more for. And that's how we grow. So you need to look at everything in the overall context of things. And what really drives consumption growth, Tyler, is the commitments. So as commitments as we get bigger and bigger commitments, that as it turns into consumption is what drives our revenue. And so what I feel most excited about is not just the fact that consumption has been strong this quarter, but also the fact that commitments have just been absolutely wonderful for us.
So that is what gives us a lot of confidence, and you're seeing that reflected in the guide and the fact that we raised the guide again in such a meaningful way.
I'd add to that. I just want to add to that to what I ask said, both of our largest deals, the $20 million-plus sales that we talked about were cloud deals. So that's something we'll recognize over time.
Got it. The $20 million security deals, those were all cloud?
Not the security deals. But the 2 we referenced $20 million-plus TCV deals, both of those largest deals were cloud deals.
Okay. Okay. Great. And just a quick follow-up for you, Navam. You talked about ACV growth being stronger in the first half. I assume net new ACV stronger as well. Is that ACV growth kind of tracking above what we see in terms of reported subscription or sales subscription growth, too?
Yes, for the reason that cloud revenue trails these subscriptions, right? So you'd have commitments that then eventually turn into revenue over time. sales-led subscription revenue is always going to trail the ACV aggregate amount that you have. So yes is the answer and also the point that I made earlier, which is that the ACV growth year-over-year has been accelerating.
The next question comes from Miller Jump with Truist Securities.
So Navam, you mentioned the cloud strength, but you have also called out some pretty strong data points on the self-managed side as well. So I'm just curious, like we've talked about strength across all 3 use cases here. Like are those distributed the same when you look at the people consuming in cloud versus those consuming on self-managed? Or do they skew differently?
There's going to be variability quarter-over-quarter. So some of them are going to be cloud and some of them are going to be self-managed. Like we said, we incentivized our sales team to go meet the customers where they are, be it on cloud or self-managed. So some quarters, we're going to have some self-managed strength and some quarters, we're going to have some cloud mix strength. There hasn't been any meaningful change in the mix trajectory. Both of those lines of business are expected to grow to reach our sales-led subscription revenue target that we laid out in the midterm.
Okay. And then just a model question I had was looking at the monthly subscription, I know that, that's not part of the revenue you're guiding to, but it did tick down in the second quarter in each of the last 2 years. So is there a seasonal element to that or is there anything else to unpack in this year's downtick?
Broadly speaking, that's going to be self-serve customers that are mostly smaller SMB customers. So we'd expect that line to be flat and that's our expectation. Our revenue guide of sales-led subscription revenue is basically where we're driving the business to and which is why we separate it out and give it to you as a guidance point starting this quarter.
The next question comes from Shrenik Kothari with Robert Baird.
So you called out or called out production Gen AI workloads across DocuSign and NHS Seismic as proof points at the Analyst Day. Just curious like how are you seeing these large-scale embedded use cases evolving and just how enterprise customers are deploying workloads involving vector search inference. Are these usage patterns proving to be more stickier, more volumes than your traditional sort of log metrics, which I would think are often more compressable and how to think from an NRR point of view? Yes. And then I have a follow-up.
Yes. Let me maybe answer the -- what's the nature of these kinds of use cases. So first of all, anybody that's using us for any of the AI use cases, it tends to be more compute-intensive, Shrenik, than if it were just, say, textual search. That's just by nature of what these algorithms are like. And as we described, the cohort analysis that we laid out at the Financial Analyst Day kind of talked about the fact that those cohorts, the AI cohorts are growing faster than the other cohorts. So that's just something that is built in. If you haven't had a chance to look at that information, I'd encourage you to look at it, but we laid it out at Financial Analyst Day.
In terms of those use cases, what we're seeing is broadly across all industries, not just in AI native companies that are also customers of ours, but broadly across all kinds of enterprises, financial services companies, telcos, government agencies, automotive companies, et cetera, we are seeing broad adoption. People are not just playing around. It's not just pilots, but it's production use cases that we are seeing. So we feel really good about the stickiness of our usage. And our overall AI functionality is so broad. It's not just about vector search. It's a lot more than that. And that's really what creates that stickiness, our ability to ensure accurate relevance.
Very helpful, Ash. And navam, a quick follow-up in how are you thinking about NRR dynamics broadly since you guys called out the sales-led subscription. How is that trending from an NRR perspective, if you can share an update? And I know it's early days, but just curious if the renewals closed in the quarter, what could have been the NRR versus now?
Yes. The net expansion rate played out roughly where we expected it to be. It's at 112%, which is stable, and that's buttressed by stable gross retention rates as well. And you may remember, we described the underlying trends behind the NRR, which is cohort expansion of each of our individual cohorts, and we gave you some details during Financial Analyst Day. All those trends remain very strong. So driven by many other things, including the cohort expansion, we're seeing very good net expansion rates today.
The next question comes from Ittai Kidron with Oppenheimer.
Ash, the large deal volume is impressive. Is there a way for you to break down the $30 million -- $31 million deals into how many of them were renewals versus actually new customers? And also, in that $30 million, how do I think about potential deals that were pushed out from 1Q into 2Q or perhaps pulled in from 3Q into 2Q? How do I think about that?
Let me answer the second one first. Just in terms of deals moving between quarters, like there's always some deals that slip a quarter, some that get pulled in naturally. This is -- now I'm talking outside of any of the government shutdown dynamics, but some of that movement happens naturally anyways. That's typically just a few deals typically that, that happens with. This quarter, Q2 was not different from prior quarters. It played out normally just as we would have expected. So there was nothing special there. In terms of the large deals, like I don't have the breakdown for the full 30-plus deals.
What I will tell you is that when we look at the 5 deals that are greater than $10 million in total contract value, 2 of them were security deals, 2 of them were observability deals and one of them was an AI deal. And one of those -- one of the largest deals that we signed was actually a new logo for us. So we do see a good mix of expansion on existing logos where we are cross-selling a new solution or something along those lines. And then there are ones where there are completely new logos. So I talked about in my prepared remarks, one of the world's largest chemical manufacturers, that was a completely new logo for us, and it was a deal over $20 million.
Very good. And maybe as a follow-up, Navam, on your sales-led guidance. I know you look at sales-led as a group, whether it be self-managed or cloud as both of them as important drivers for you. I think the challenge that investors have is that when you don't give more specific breakdowns on your expectations from cloud to self-managed, it's hard to gauge where you -- internally, you outperform versus underperform. And investors, no matter what, they're going to be very focused on cloud. So is there any color that you can give us, first of all, on 2Q that you just reported, did you outperform on cloud or self-managed or underperform in any of them relative to your internal targets? That's question number one. And question number two, can you give us any -- some sort of a little bit more granular perspective on how to think about the breakdown of your sales-led guide for the third quarter?
Sure thing. So Ittai, there is no internal breakdown of cloud versus self-managed for our sales team. We give them a quota and they go and hit that quota regardless of whether it's cloud or self-managed. So we're giving you a metric in exactly the way we think about the metric, right? We don't think about a cloud number. We don't think about a self-managed number. We don't think about migrations from self-managed to cloud. One is not an old platform and the other is a new platform. This is all one platform that we sell our -- one sales motion that we sell our customers to, and there are plenty of AI workloads, modern AI workloads that are self-managed. So frankly, we meet our customers where they are, and we are fine with either. So this is basically us informing the Street on how we internally think about our metrics. So I think that's important to talk about.
And the sales-led guidance that I gave you in the third quarter was primarily related to the strength we're seeing in the 2 things that I talked about. The commitments momentum, and we talked about the large deal momentum that we're seeing, which is also a factor in the commitments we're seeing and the consumption momentum. Both those things are the factors that lead to a strong Q3 number and also, frankly, a very strong full year number that we increased twice in a row now since the end of Q1.
The last question comes from Jacob Roberge with William Blair.
Yes. You referenced the CISA deal during the quarter, but can you talk about how the rest of the federal business came together? And then you mentioned there was some impact to term license in the quarter from the shutdown. Would you expect that to catch back up pretty quickly during the third quarter? And any way to kind of size that impact that it was to Q2?
Yes. So let me maybe start with that. So the best way to think about our overall performance in the U.S. public sector was great. Like absolutely, we were very happy with the performance. The team -- obviously, we had 1 less month in the quarter when the teams were able to close meaningful business, but they were able to work around it. Demand remains very, very strong. and the execution of the team was excellent. And the CISA deal came in, in the month of September before the shutdown happened. So all of that worked out very, very nicely.
In terms of the renewals that slipped from Q2 to Q3, the best way to think about it is those were renewals where the customers are still using our product. So we did not take the approach of shutting them down. We just let them continue using it because we know that when -- we knew that when the government reopens, that they will process those orders. So that's the right way to think about it. So those renewals will come through in Q3. And so it's not business that's at risk. It's just something that slipped because the government was shut down.
This concludes our question-and-answer session. I would like to turn the conference back over to Ash Kulkarni for any closing remarks. Please go ahead.
Thank you all for joining us today. So we here at Elastic are very proud of our strong results and are very excited about the opportunity ahead. Thank you.
The conference has now concluded. Thank you for attending today's presentation. You may now disconnect.
Elastic NV — Q2 2026 Earnings Call
Elastic NV — Analyst/Investor Day - Elastic N.V.
1. Management Discussion
Global Vice President of Finance, Eric Prengel.
All right. Hello, everybody. Welcome to Financial Analyst Day. Now before we begin, I want to get the obligatory disclaimer language out of the way. Today's event will be webcast and recorded for future playback. Information and risks pertaining to forward-looking statements as well as a reconciliation to our GAAP and non-GAAP results, are available in today's presentation materials, which will be posted on the Investor website at ir.elastic.co at the conclusion of the event.
With that out of the way, on to the fun stuff. So for those of you who don't know me, my name is Eric Prengel, and I'm the Global Vice President of Elastic as well as the Head of Investor Relations. I was an investment banker for a long time before joining the company almost 3 years ago. And I've known Elastic for a while because I worked on the IPO, and some of you worked on it with me. It was a lot of fun.
Since joining, I've gotten to know the company a lot better. And I'm really looking forward to sharing with all of you what the team has built and all of the exciting things that we have and the trajectory that we're on. It's great to have so many familiar faces together. And all in the place I grew up no less. Ash mentioned the Yankees because I went to the game last night. I was sad to see the loss, but there will be next year.
We have a great program for you today. Ash is going to lead off and go through the opportunity. Ken, Steve and Santosh are going to talk about product. Then we're going to have Mark talk about go-to-market, and then Navam is going to talk through the financials of the business. Unfortunately, Shay couldn't be here with us today due to a family health issue that he needed to attend to. He's regularly at ElasticON events. And actually, if any of you are able to make it out to Amsterdam on October 30, he will definitely be there.
And with that, I'm very excited to hand it off to our CEO, Ash Kulkarni.
All right. Good afternoon, everybody. Thank you for joining us today. So I'm going to kick things off. My job today is to set the stage, talk about our strategy, our vision, who we are as a company. For those of you who might not be that familiar with Elastic, I want to make sure that you have a firm understanding of where we differentiate, the role that we play in the IT organizations of all of our customers, the opportunity that we have in AI and how we are helping customers in AI today and what that means for our future.
And the rest of the agenda is going to be folks in products, walking through the new product capabilities. We had 6 new product announcements today. We are going to have Mark talk about our go-to-market efforts and everything that we have done there. And then finally Navam bringing it home.
So with that, let's get started. The most important thing that you need to understand about Elastic is the role that we play in helping our customers deal with unstructured data. We are the world's most popular data platform when it comes to unstructured data. And oftentimes, when people say unstructured data, it's hard to know exactly what you mean by that.
Take a look at a log file. A log file is effectively every developer putting notes for them in the future to be able to go back and debug their own code. Typically, these messages tend to be very, very free-form. They tend to be very, very messy. The information in there is different from line to line. When you look at a log file like this, you can't put it into a regular database. It doesn't matter if it's a SQL database, doesn't matter if it's a document database, doesn't matter if it's a columnar store. You can't put this information into a rigid schema.
By definition, if you're looking for patterns in it, if you're trying to identify and sift through it, analyze it, you need a different paradigm. You need a search platform. And that same thing applies even when you're dealing with freeform documents, Word documents, PDFs, all of these kinds of structures. They do not have a good schema. That's unstructured data.
Because of our dominance in this area today, over the years, we've had over 5.5 billion downloads of our software. That's over 3 downloads a second over these 15 years, if you average it out. We have been ranked as the #1 search engine in vector database according to DB Engines. And if you look at the GitHub stars, it clearly indicates the popularity that we have.
And all of this is because, yes, we can deal with structured data, but most importantly, what we can do with unstructured data with the power of relevance, that is something that is very specifically, our greatest competitive advantage. And because of this, we have built a tremendous incumbency when it comes to this kind of information. So we have estimated just the data that is in Elastic Cloud that we have a lot of clear access to and visibility into, but also our estimates of the data that exists in paid Elasticsearch self-managed clusters around the globe.
Every day, over 30 petabytes of new data gets ingested into Elastic paid clusters around the globe. 30 billion queries per day just on Elastic Cloud. And when we look at the total data that's under storage, it's well over 1.3 exabytes. That is incumbency. This is unstructured data. And when that unstructured data gets utilized for AI, gets utilized for observability, for security, where do you expect people would go? The first place that they go is Elasticsearch. This data is already there. So when they look to automate things using new modern AI techniques, we are the natural platform of choice. This incumbency is a huge advantage.
And as unstructured data has grown, so is our revenue. We have built a strong at-scale business as unstructured data, which is the fastest-growing type of data has continued to expand. The most exciting thing that's happened is the fact that with the advent of LLMs, the importance of unstructured data has just grown manifold. You look at any application in the past, whether it was CRM systems, ERP applications, HCM systems, they were all built on structured information, account ID, opportunity ID, customer name, et cetera.
All the notes that you put into your CRM system are just shoved in there, it's freeform text that you can't really analyze in any way. It's just an attachment that some human being has to read. Large language models have completely changed what you can do with unstructured data. Large language models are really the new operating system. We believe it, we believe it firmly. And you program not using Java or C or Rust or Python, but you program using English. That's the amazing part about these systems. And these systems are knowledge systems, but they are only as knowledgeable as the data they've been trained on.
So to use them within the enterprise, you have to provide them with context. You have to provide them with relevant data to be able to address the problem that they're trying to address. So AI fundamentally depends on data, being able to have access to it. And relevance is key to making any AI system actually worthy, production grade.
This is right in our wheelhouse. AI has literally come to us. It has made unstructured data, more interesting, more valuable. Our ability, this is what we've always been known for. This is what we were created for as a company. Our ability to be able to ingest, bring in all of this unstructured information, index it, make it searchable, allow you to run all kinds of interesting algorithms, ML queries on top of this data. This is what we have always been good at. And this is what is really needed to build new AI experiences.
We've been working on this ever since the company was formed. Relevance is not a new concept for us. From the earliest days, it was all about relevance. It was all about trying to figure out how to make sure that you can surface the most relevant information for the search query that you were firing at Elasticsearch and surface that. And over the years, we continued investing in machine learning, in AI. When it was clear that transformer models were going to be an interesting thing, we started investing in building out our vector database well over 5 years ago.
Since then, we have made our vector database more and more capable, highly scalable. Today, we have customers that are using it to store and retrieve billions of vectors at scale in a very high-performance way with great efficiency. We built our own embedding and retriever models. We built our own reranking models. We added additional capabilities like MCP tools. We are working on GPU-based acceleration with NVIDIA.
There's a lot that we have been doing in this area. This is not something that we just woke up and decided to do a year ago. This has been in the making because unstructured data has been at the core of what we've always done. So today, we feel confident that we have the best platform for context engineering.
Now what is context engineering? If you ask ChatGPT, which is what you should do, it will tell you that context engineering is the techniques involved in ensuring that you provide the right data and the right tools to a large language model to allow it to do its job accurately. The right data and the right tools. That takes more than just a vector database. Of course, you need a vector database when you're dealing with data that might not easily be searched through textual techniques.
Also if you want to do things like semantic search, but you need more than just a vector database. You need to be able to deliver hybrid search. You need to be able to ensure that you can actually verify the outputs. So have a playground. You need LLM observability. You need embedding models that you're constantly tuning and improving relevance with. All of this becomes critical.
So why do we win? We win today because of these 3 broad reasons. First and foremost, like I said, we have been investing a lot in making our vector database and our overall retrieval platform the absolute best when it comes to speed, scale and efficiency. And I'll talk a little bit more about that. But more importantly, the team is going to go into it and actually go into the details.
In the past, we've talked about things like better binary quantization, BBQ, allows you to manage vectors in a much denser way. So you're having to use much lesser memory and CPU. We've talked about capabilities like ACORN, a new filtering algorithm that allows us to improve query performance because any search always happens with some amount of filtering. You don't search for restaurants, you search for restaurants in a particular neighborhood. In a particular neighborhood is a filter. You need to be able to do that efficiently. That's what we do incredibly well.
The second reason why we win is relevance. We have put a lot of effort and energy into optimizing our models for relevance. And we don't just do this using vector search, but with the rerankers that we've built, the ability to use multiple techniques, hybrid search, semantic search. And then on top of it, to use reranking to get the best possible output, the most relevant data. And lastly, because we have assembled all of the tooling that you need to be able to build these chatbots, these agentic workflows, these agents in an efficient manner.
Today morning, we made two announcements in this area. The first is a new capability called Agent Builder. And the team is going to demonstrate this. If data is the most important aspect for context, wouldn't you want to start with the data as you're building these agents? How do you start directly on top of your data with almost a conversational experience, explore your data and assemble the right tools that you need to quickly build a complete agent with workflow capabilities and everything that is needed? But a completely different approach that's truly relevance-centric, that's all about context engineering.
The second thing that we announced is the Elastic Inference Service. This is our own GPU accelerated service in Elastic Cloud, where we make it possible for our users to get access to our embedding models, the retriever models, our reranking models. And over time, more and more models that we'll deliver so you have everything that you need, not just for Agent Builder, but even outside of it, through this easy API.
We also today morning, announced our acquisition of Jina AI. We have been partnering with Jina for a long time. Our ELSER model is a world-class Sparse EncodeR model, but it was English only. With Jina, we get access to an amazing multilingual and most importantly, multimodal set of models, both for retrieval as well as reranking. When you look at any document, most documents will often have multiple types of information in it, some text, but also images. If you are dealing with a single-mode model, you would need to break up that information, separate the text from the images, run it through two separate models to chunk it up differently, just makes the whole system extremely complicated, and you don't get the relevance, the accuracy that you need.
With a multimodal approach like what Jina has been able to do, you can put all of that information through a single model and get exactly what you need. This is going to be available through our inference service and will be available to our customers as we integrate this. This team, the team of researchers, the work that they have done, they have made it -- they do a lot of work with academia.
They have published a lot of reports about the relevance quality that they're able to generate. We are very excited about what this brings to Elastic. This is allowing us to win the kinds of customers and have the kinds of customer successes that we are incredibly proud of.
And I wanted to just talk about a few of these examples. So the first is DocuSign. The reason they chose Elastic was because they were trying to build what they call their Intelligent Agreement Management platform, a new service that they're delivering to their customers. They want to go beyond just being able to sign documents. For that to work, they needed to have some ability to be able to search across each and every document, literally many, many billions of documents that are in the DocuSign store.
How do you make that possible across the different modes of data, like we talked about? At scale, with immense relevance. We were the only ones in their testing that they found capable of doing it.
Legora, an AI native company. It's all about how do you use AI to improve the process by which lawyers are able to do research on case law, write drafts, optimize those drafts, do their work better and faster. They chose us because of the quality of relevance. When you're dealing with legal case law, the kinds of semantics involved are very specific. You need to understand those semantics. They found that the relevance quality that we were able to deliver was amazing.
Another example I'll touch upon is the National Health Service in the U.K. They use Elastic as the platform for bringing in all of their patient records and being able to search across them for helping doctors decide what's the best next step in terms of the procedures that they want to recommend, helping their doctors work faster, more efficiently. Now they chose Elastic not just because of our scale, not just because of our relevance, but also because we were the only platform that had the very fine grained document-level permissions that gave them the confidence that it would not violate patient privacy rights. We are the only platform that has the ability to do all of this.
What's interesting when I look at this slide is, first, the variety of customers. We are not looking at just customers that are AI native companies. Looking at ISVs like DocuSign and Seismic, looking at agencies like the National Health Service, that breadth is what gives us tremendous strength. This is diversified.
The second thing that I'll call out is these use cases are very durable use cases. This is not experimentation. The National Health Service is not trying to experiment with people's health. Legora, their whole business model is built on this. DocuSign, the entire new business that they created is dependent on this. These aren't experiments. These are durable use cases.
And the last thing I'll call out is just the fact that they had very clear understanding of the differentiation and the competitive advantage that Elasticsearch has that made us the only right choice for their needs, scale, relevance and the ability to do everything in one single platform. You look at the numbers of customers that we have today. I look at that middle box. That represents about 20% of our customers in the cohort that is paying us over $100,000 a year. That's 20%.
But that tells me 2 things. One, that there is a tremendous opportunity still ahead of us because we still have 80% of that population to go after. And second, that each of these companies, even the companies listed here, they have built one really amazing application on our platform that's AI-centric. But that's just the first. There's so much more that they are planning to do, intending to do, and we are in such a great place as part of their infrastructure for AI that we feel very excited about what this means for the future.
Now I'm going to shift gears a little bit. Everything that I've talked about so far has been about search. But what does this mean to our observability business? Well, first, why did we even get into observability as a company? I'll take you back to what I started with. We are the best data store for unstructured, messy data. Observability data tends to be incredibly messy. Logs are the messiest form of machine-generated information. Our ability to get into this entire space started with the functionality that we delivered in log analytics. But over the years, we've assembled a complete platform, everything from infrastructure monitoring, APM, AIOps, real user monitoring and more.
And the reason why we win today are these three. The first thing is very simply, what you see at the bottom. We have the best data store, and we continue to invest in this. We have the best data store capable of ingesting every possible type of signal needed for observability in one single store, allowing you to run complex correlations, allowing you to see the links between the infrastructure, showing you that the CPU is running hot, to understanding the specific services and application components that might be falling behind to then getting to the relevant logs, the specific logs related to those issues, to then be able to diagnose the root cause.
Having one data store that's optimized, and we have built distinct back-end specialized stores within Elasticsearch for logs, for time series data like metrics and so on. So we can store each of these data types efficiently and still get you correlations across all of it using a singular query language, ESQL.
The second reason why we win is because of our big bet on open standards. Observability is a mess, generally because of the fact that in the past, none of the data was ever normalized. It was really hard to do any kind of correlation. OpenTelemetry has started to change that in a very material way, in a very material way.
And so we leaned in hard because with the open standards that OpenTelemetry provides, we can now have an OTel native way all the way from collecting data with OTel collectors and OTel SDKs, all the way to a OTel native back-end schema. Incidentally, we donated our Elastic common schema to the OpenTelemetry project, and their common schema for logs is based directly off of Elastic's common schema.
What that means for our customers is when they use OTel to bring in the data, the dashboards automatically light up. The data is naturally correlated with each other. That is a huge advantage. And lastly, because we have been more aggressively using AI to help with investigations when you're dealing with any kind of issue in observability than anybody else. When you're dealing with observability, the thing that matters most is mean time to detection, mean time to resolution. How quickly can you spot the problem? How quickly can you understand the root cause? How quickly can you do something about it?
And towards that end, the fourth big announcement that we made earlier today was something called streams and significant events, and the team will demonstrate this. Using AI to automatically help you get all the richness and all the information that exists in logs because logs have always been the last port of call. That's where every developer goes at the end when they want to root cause exactly what line in their code is causing issues.
But it has never been the first port of call because logs are hard to work with. They're required to do a lot of work. You have to write a lot of Grok rules. You have to parse the data, you bring it in, you got to write the right alerts.
What if AI could do all of that for you? That is what Streams and Significant Events does. It automatically uncovers what's important in your log data. And our customers are showing with their faith in us that our approach is the right approach. So we've talked a lot in the past about our land and expand strategy. And this just gives you a sense of how much progress we've made even within the subcomponents of observability.
We always start with log analytics. Over 90% of our Elastic Cloud Observability customers use us for log analytics. But what most people might not realize is over 35% of our Cloud Observability customers use us for what I describe as beyond logs, APM, infrastructure monitoring or metrics, AIOps and so on. This shows that our land and expand motion is working. It's proven. But there's also a lot more room for us to keep growing. This is what's exciting for us.
That same approach also applies to security. Because if observability is a data problem, security is 10x more. You literally miss every single threat in the data that you don't ingest, analyze and alert off of. Security is absolutely a data problem. And that's why we started with SIEM because we have the world's best platform for unstructured data.
And all of that security telemetry is unstructured. It's network logs, it's application logs, it's identity and access management logs. It's web logs. It's telemetry from endpoints. It is in so many different shapes and sizes, being able to bring it all together and actually do analytics on it is a data problem. Yes, we've invested a lot in first-party threat research and so on. But make no mistake, security is fundamentally a data problem. And by starting with SIEM, we then, over time, have expanded beyond adding EDR and XDR functionality, adding cloud detection and response functionality, adding UEBA or entity analytics.
The reason why we win, and you'll see the themes here. First and foremost, at the bottom, the best TAM data store when it comes to being able to bring in all of this network telemetry at speed, at scale, very flexibly, irrespective of your deployment type in the cloud, on-prem, do threat hunting across all of your data. The second reason, we have truly used AI more aggressively in security than anyone else. Attack Discovery, the functionality that we released 1.5 years ago, which is now being used very widely across our entire security portfolio by our customers, takes away the job of an analyst to try and sift through all of the alerts and figure out what are the real attack patterns in there. The AI does it for you.
And the third reason, the ability to not just unify all of the signals, but then to act on it, to remediate, and I'm going to touch upon that in a second. Because the fifth big announcement -- product announcement that we made earlier today was this. We announced Elastic Workflows. This was the acquisition of Keep that we made about 6 or 7 months ago, and we have very quickly integrated that functionality directly into the platform. So now not only do you get security alerts, not only can you do threat hunting in the platform, but you can create the remediation workflows.
And depending upon how automated or semi-automated a way you want to actually do those remediations in, you can fire off those remediations, complete case management, complete workflow, stateful everything, incredibly powerful. And our customers are proving that we are the right choice.
So again, over 95% of our Elastic Cloud Security customers use us for SIEM. This is where we land. Just like in observability, we land with log analytics. In security, we land with SIEM. What most people might not realize is that over 20% of these Elastic Cloud Security customers are using us for what I call beyond SIEM. They are using us for EDR and XDR use cases.
We don't lead with EDR, but we expand with EDR when we are in, because those endpoints that are bringing in the data required for SIEM have the functionality built in for things like ransomware protection, for things like host isolation. So once that agent is deployed, all the customer needs to do is turn on the configuration flag, and that's how we expand. That's how we grow our consumption.
So I've talked about land and expand over and over again. So I'll try and put it in a visual form for all of you. What's great about Elastic is given that we have had such strong roots in open source, it is really hard for me to meet a prospect, somebody who's never done business with us, where there isn't somebody who is already familiar with Elasticsearch is actively using Elasticsearch.
Maybe the community editing, the free edition, that's fine. But they already know us. They are already champions in there. Awareness starts through our open source routes. And then when we land, when we have the first transaction with a customer, it happens in 1 of 2 ways. Either the self-service motion, if it's an SMB customer, they just come to monthly cloud and they start using us that way.
It's typical for our SMB cohort. And our sales-led efforts where we go after the enterprise and mid-market accounts. After we have that first land, then we focus on customer usage. And Mark will touch upon this. But we have a customer architect team that focuses just on this. There are engineers who work with our customers to make them successful with that implementation.
When that implementation is successful, consumption starts to fly, the flywheel spins because as they do that, the next natural thing then with the customer is a conversation about how else can we help you. Just as I talked about beyond logs, beyond SIEM, and then going from one solution to an additional solution, that's how we grow.
Customers adopt higher tiers if they want our AI Assistant, if they want searchable snapshots, these capabilities that we put in the premium enterprise tier, and on and on. Another thing that's important about Elastic is the fact that we have been very disciplined about making sure that we meet our customer where they want us to be.
We have, of course, Elastic Cloud hosted and Elastic Cloud serverless, but also the self-managed offering. And that gives us tremendous advantages. There are lots of customers even today who want to run AI workloads in their own data centers because the data is regulated information that they don't want to put in cloud. That gives us an asymmetric advantage. We are one of the few that can do this.
All of this taken together is setting us up -- has set us up in such a great way in a market that has a massive total addressable market. We are very excited about this. And we can see the recognition that we've been getting and earning from analysts. In the most recent reports, we are now a leader in each of the areas that we play in according to Gartner and Forrester. We didn't have this 5, 6 years ago.
But we still have so much headroom ahead of us. That box on the bottom right, I always think about that. We have over 50% of the Fortune 500 companies as customers. That means there's 50% more that we can go and get. And that is exactly what Mark and his team are focused on from a go-to-market motion. And the work that they have done in the last 18 months, transforming our execution, making it more predictable, making it more consistent is something that I'm very, very excited about.
What I'm most excited about is the fact that as we've been able to improve our efficiency, improve our productivity, we are very confident that even as this engine is humming, there is still more room for optimization. I know that we can continue to do even better. That's exciting.
So I'm going to bring it home. We are not chasing AI hype AI is really a wave that has come to us because of the role that we've always played with unstructured data, that's what our customers know us for. And that unstructured data has now become incredibly exciting and important. It is what's fueling a lot of the work that's going on in AI. And that just means that we have a natural seat at the table. That just means that we have a natural advantage, an incumbency that we are taking advantage of.
And if I leave you with these 5 pillars, I think that's the most important way to think about Elastic. We are trusted by developers all over the globe. We are trusted by enterprises. We have clear Gen AI leadership. Analyst recognition is only helping us do this more efficiently with our go-to-market motion. And lastly, we've been able to consistently deliver strong financial performance.
So now I'm going to hand it over to Ken to really take us through the products. Ken?
Hey, folks. Thank you for being here. I get to do what I love now, which is talk about products. And I'm going to begin with a point that Ash made earlier. Ash was talking about the explosion of data that we're seeing, especially unstructured data. This is something I see all the time when I talk to customers. They're talking about how much data they have, how hard it is to manage it, how much that data is growing all the time.
But it's not just the volume, the amount of data that they're struggling with. It's also that it's siloed across the enterprise in a mix of structured and unstructured formats. And even when it's structured, it tends to be different schemas. So they're dealing with all this messy siloed data.
But they also know that in the age of AI, this data, this unstructured messy data is something has new value. If they could put it to work. If they could use this together with generative AI and agentic AI systems, this new messy unstructured siloed data has new value. But how do they do that?
Enter Elastic and the Elasticsearch platform. Now for years, we've been helping customers get more value added data. No matter how messy that data is, no matter how siloed, no matter what type of data is, we help customers get value out of data. And in the age of AI to build these AI experiences on top of that data.
Now in a few minutes, Steve and Santosh are going to walk you through the Search AI, Observability and Security businesses that build on top of this platform. But I want to talk about the platform itself, the Elasticsearch platform because I think that is why we win. Put very simply, we win because of the Elasticsearch platform, period.
For me, this means 3 things, though. One, it's a world-class data store. It's a blazing fast data store. It is highly performing. It is highly scalable. Now customers always know us for being the search engine, but they sometimes forget that we're also a data store. And I would argue not just any data store, but the best data store for unstructured data.
Second, we're the leader in relevance. As a search engine, as a vector database, as a context engineering solution, we excel at relevance. We're the leader in relevance. No one has a deeper set of capabilities than us for getting relevant context out of data and presenting that context to other systems. No one has more customers. No one has been doing this longer than us. We are the leaders in relevance.
And third, we win because we win with developers. We are loved by and we are built for developers. Developers worldwide, millions of developers have used Elasticsearch over the last 15 years. And we have deep roots in open source. And because of these deep roots in open source, we've built out a huge community that take Elasticsearch into the enterprise, where we're able to convert into paying customers.
All right. But let's unpack this a little bit, beginning with why we win as a data store. It starts by supporting all the data. It doesn't matter what kind of data it is. The Elasticsearch data store supports everything. It could be metrics. It could be traces. It could be IoT data. It could be product telemetry. It could be business data, any type of data, structured or unstructured, we support that.
And one of the things I think that is really, really unique about us is that we support the type of capabilities that are only typically supported by structured data stores, but for unstructured data. And let me give you an example of what that means. So it means that we can combine all this data together. Even though it is not the same format, even though not the same schema, even if it's different types of data, even if it's unstructured. And we can do things that are typically only possible with structured data tools.
For example, you can join data. You can -- using ESQL, or query language, you can actually literally do joins on 2 different data sets that are not only the different schemas, but are unstructured. You can create fields on the fly. You can do math operations on unstructured data. You can do sorting and filtering. These are things that are typically not done with unstructured data, but you can do that with the Elasticsearch platform. Or if you want to run ML jobs or AI or various types of analytics on this.
It doesn't matter that the data is all kinds of different formats. It doesn't matter if it's unstructured. You can run that across this. So you can run correlation analysis. You can run anomaly detection, not just on metrics and traces, but also on business data. No one else can do this.
And it's not just that we support any type of data that makes us a special world-class data store. It is also because we have a reputation for being incredibly fast, highly scalable and highly performant. But it's not a reputation that we take for granted. We are constantly reinvesting in making sure we are highly efficient and highly performant and highly scalable.
And typically, there's 2 types of investments we make. Sometimes, they're data type specific. We have types of improvements that we do to make logs really great on Elastic, to make metrics or vectors really great. For example, over the past year, we introduced LogsDB and TSDB. Both of these improvements are delivering 70% storage efficiency for our customers over previous versions.
We've also been doing a lot of work in vectors. Ash mentioned BBQ, Better Binary Quantization, my favorite product name. It is a type of compression for vectors. But what it does is it allows customers to have huge savings in terms of memory footprint and in terms of storage. So you get 95% efficiencies in terms of memory.
But not just that, it also improves performance. It's actually made us 5x faster than OpenSearch with their default quantization techniques. But now sometimes, the improvements that we do in our data store affect all data in Elastic. For example, the work that we're doing with NVIDIA to do GPU acceleration of all data in Elastic or the work that we've done on a data lake architecture. Over the last few years, we introduced a new data lake architecture.
It's built on object storage like other data lakes. But unlike other data lakes, you don't have to compromise performance. We are the only data store that allows you to have blazing fast performance, real-time performance. You can build real-time applications, latency-sensitive applications on top of our data lake. So you get the durability of object storage, you get the scalability, you get the efficiency of object storage, but you don't have to compromise performance and only we can do that.
All right. You can't talk about Elastic without talking about search, and you can't talk about search without talking about relevance. And we are the leader in relevance. And we're especially good when it comes to finding context and intelligence in any data, no matter whether it's structured or unstructured.
Now if you have structured data like you have a table or a relational database, there are plenty of good tools that you can use to query that data. But if you have unstructured data, what do you do? For example, if you have petabytes of logs, well, those logs might be different schemas. But even if it's the same schema, that same schema is going to have a mix of structured and unstructured content. So how do you sift through that? How do you find that needle in the haystack that could end up being a security vulnerability?
Well, you need a great search engine. Or if you have a huge repository of documents or PDFs, like what our customer, DocuSign, has. And you want to do semantic search on that, or you want to build generative AI applications on top of it. How do you do that? Because these documents usually are opaque documents. And even if it's not opaque, it's usually a mix of structured and unstructured formats. But what you need is you need a vector database, you need a semantic search system, you need a retrieval system, a great retrieval system.
And what makes a great search engine? What makes a great retrieval system? It's relevance. Relevance is at the heart of doing search and retrieval right. Now relevance has always mattered, but I think it matters even more in the age of AI. Back when we were mostly focused on returning results to a user like 10 blue links, you didn't want bad search results, right? You wanted good search results. But those are human there that can interpret those results. So you had room for error.
But in the age of AI, you're not going to get 10 results, you're not going to get 100 results. You're going to ask a question of an LLM or an agent, and you're going to get one answer. And hopefully, that one answer is right. And for it to be right, that agent, that LLM has to be grounded in the right data, has to have the right context. But it gets even more interesting and more worries when you get into agentic AI, when you get into agentic AI, now it's not just answering a question.
Now that AI, now that agent is performing an action, it's doing a task and potentially doing it badly. So now the consequence of not grounding that LLM or that agent, not giving it the right context could be disruptive, could be damaging. So this is why I think relevance matters so much in the age of AI, why context engineering as a concept is going to be talked about constantly as people move forward with agentic AI because it's all about having relevance. It's all about having context. That's what you need to do AI correctly.
All right. So the vector database companies have been saying that the answer to this problem is a vector database. And it is, to an extent. And I'm saying this as a vector database company. We were one of the first vector databases out there. We are the most downloaded vector database. We are the best vector database. But I also know that vectors are not enough. Vectors are not enough. It is not enough to simply store and query vector embeddings. You have to do a lot more.
For one, you have to help customers prep data and ingest data. And they're going to have all kinds of different data stores that you're going to need to help integrate, pull data from different places. You're going to have to parse that data. You're going to have to figure out a chunking strategy if you're going to chunk that in order to create the vector embeddings. To create vector embeddings, you're going to need a model, an embedding model. Hopefully, it's not just a single language embedding model, but maybe a multilingual embedding model, maybe a multimodal embedding model, but it doesn't stop there.
Because now you need to work on retrieval. And one of the things that we have learned is that to get relevance right, you have to combine different techniques here. It is not enough to just do vector search. You're usually combining vector search and lexical search or doing graph traversal or you're doing geospatial search or filtering faceting like Ash talked about. And if you're combining different data sets, you're going to need to do reranking using the rerank model.
These are all the different techniques that you use for tuning relevance. And if you're going to tune relevance, you're going to need a way to evaluate results and make sure that you're getting the right results from that tuning of relevance. So how do you do that? You need to have A/B testing. You need to have a framework for doing this evaluation. Then you're going to want to take this application to production. So you're going to need to monitor that application. You're going to need to have a query logging and metrics and tracing for that application. You're going to need to make sure that you're doing cost and token tracking.
It doesn't stop there, though. Because now we're in the age of agentic AI. And the patterns change a little bit. So it's -- previously, you just focused on passing the right data to an LLM in a context window. But in an agentic architecture, you're doing things differently. Now what you're doing is you're exposing that data as an MCP tool to an agent or to an LLM and you're helping with tool selection.
Well, now you need a whole new set of things. Now you need to have prompt management. Now you need to have memory management. You need to have a set of capabilities for building MCP tools and you need to have capabilities for helping the LLM dual tool selection, a lot more things you need to do. And all of this is context engineering. This is a term that you're going to hear a lot over the next couple of years. Context engineering is vital to doing agentic AI right.
And it's not a term that we invented. It is something that's used popular in the industry, but we did pioneer a lot of the capabilities in this space. We did trailblaze a lot of the technologies here because you see, we do all of this. Now Steve is going to show you, many of the capabilities, especially the agentic AI capabilities that we've been working on.
But I just want to make sure that it's clear, we didn't like pivot recently to doing this. As Ash pointed out, we've been doing this all along because context engineering is all about relevance, and we are the leaders in relevance. It is in our DNA. I believe that we were made for this moment.
All right. Finally, we win because we win with developers. We have -- over the last 15 years, we've built a community of millions of developers that know and use Elasticsearch. According to the annual Stack Overflow survey, 17% of all professional developers in the past year have used or built on Elasticsearch. 19% of all AI developers worldwide use Elasticsearch. And a lot of this is because of our reputation in open source. As Ash pointed out, we have been downloaded 5.5 billion times, which makes us one of the most popular open source projects of all time.
The other thing developers love about us is that we continue to expand our platform, offering additional capabilities all the time, make it possible for our customers, our developers to build amazing things on top of our platform. Over the years, I've been amazed at what people have built. They built all the ridesharing applications built on Elasticsearch, matchmaking sites built on Elasticsearch, fraud detection systems, signal intelligence systems, all these things built on Elasticsearch.
And 3 of the most popular use cases have been in Search AI, Observability and Security. And to make it possible for our customers to get up and going, get up and running, using us in these 3 scenarios, we created out-of-the-box solutions that make it possible for them to get started immediately using us as an observability platform, using us immediately as a security platform and for Search AI.
And with that, I want to turn the stage over to Steve and Santosh, who are going to walk us through these 3 solutions and these 3 businesses, beginning with Steve Kearns.
Thank you. All right. Hi, everyone. I'm Steve Kearns. I'm the GM of the Search business here at Elastic, and I've been with the company for 11 years. So I've lived through this time where Ash and Ken are saying, we've always been a search company. Relevance has always been at our heart. And I can tell you it's true. And it's really been fun to see the excitement, the interest around generative AI and how central relevance is to success in those applications and in those use cases.
And so when you think about the kinds of use cases that people run on top of Elasticsearch, you can think about search powered applications. For the entire history of the company, we've been a great data store, a great platform for engineers to build compelling engaging experiences for their customers. In fact, I bet a number of you here today, I don't, looked up a coffee shop, might have placed an order. You might have then filed an expense report. All of those kinds of applications, those things are built on top of Elasticsearch. And so I met many of you experienced Elasticsearch in one way or another today as part of these experiences.
And people build on us because of the performance, they build on us because of the relevance, but just as importantly, because of the flexibility that we provide as a platform. When you bring data into Elasticsearch, all of the fields in that data are instantly queriable by default out of the box. And that's a great experience for a developer, and it's why so many applications continue to be built on top of Elasticsearch.
But as we see the excitement around AI, we're seeing these new workloads. AI is driving the development of new experiences often in response to new expectations from customers or from employees that are using AI tools at home, using AI tools in their personal life, and they want that same experience in the business. And when you think about these conversational experiences, and Ken talked about this really well. The conversational and agentic experiences, they depend so much more on getting the right business data, the right context in order to give you the right answers.
And if you think about what does it take in AI to get that right answer, they're great. Language models have a wonderful world knowledge, but they don't know about your business. They don't know about your job. They don't know what problem you are trying to solve. And so the job then that we have to do on the data store side is to get the right context, the right information from your business to the model to help you with your task at hand.
And this is really important with conversational AI just asking a question. If it doesn't give you the right answer, users are going to lose trust in that system very quickly. And it's even more important, as Ken said, when these systems start to take action on your behalf, the agentic workflows and they're taking action, they're changing things in your business, it has to do the right thing. It has to have that right information to make those decisions and make those choices.
And so we really believe very strongly that relevance is at the heart of every successful AI implementation, every successful AI project. And so it's no surprise then that the core of why we win is all around relevance. Ken talked about all the features, all the capabilities that we've added into the platform. But when you think about relevance, it's not about one feature.
It's not like, yes, we added one new feature, done, relevance is solved. Relevance is really personal. It's about what's the data that you have available? What's the information need that the user has? What are they trying to do? And do we have the information available to help them with that?
And so relevance is about flexibility. The flexibility that we have as a platform to retrieve the right data to give you the tools. Because sometimes you're looking for one right answer, what's the document that contains the answer to the question that I have. Sometimes I need to see a chart. Sometimes they need to look at an outlier. Sometimes, I need to find just one piece of information, but see how it compares to the rest of the population. It's one customer, how do they compare to the rest of my customers. And so this is a really important element around why we win, this flexibility that we have to get the right relevance.
Another thing Ken talked about a lot of the work that we've done around speed, scale and relevance. And this is really driving a lot of the places that we win. If you think about speed, e-commerce companies, a lot of the major e-commerce companies that we know and love are building their e-commerce search on top of Elasticsearch because they recognize that better search quality delivered faster leads to more business for them, right? You don't want to wait for your search to complete. You don't want to get the wrong results. It makes a huge difference in the e-commerce space.
We also see this on the scale side. We've got one customer, document management customer in Elastic Cloud today, storing over 5 billion vectors in a single use case in Elastic Cloud, and they're only able to do this because of the efficiency work that we've done. Ken talked about BBQ. It's a new thing actually being talked about, I think, right now in the other room called just BBQ, another order of magnitude efficiency in memory, and this allows these multibillion document use cases to be built at all and to be built on top of Elasticsearch.
And finally, we really do focus on developers, right? Developers are the ones very often making the technology choices. And so the better experience we can provide them, the more batteries included, the more we can provide out of the box to make this easy to get started, the better developers are going to find success building on top of us. And one of the key things, and Ash touched on this at the beginning. One of the key aspects of relevance, right, is actually having the right models, the right language models to generate embeddings toe power of vector search.
These language models are really important. And so I couldn't be more excited to have the Jina team, Jina AI team joining Elastic. They're well known in the industry as a leading tier research organization, putting out incredible high accuracy, low resource usage, very efficient, very fast models.
And one of the things that I love about the team, the models are great. I'll talk about those in a minute, but I love the way that the team works. With every model that they release, they publish a research paper along with it. This has done a tremendous amount to help build the credibility in the market, the trust and the reputation that they have comes from the way that they work in the open.
They make their models available on hugging face under an open weights, but not open source license so people can download it, advance the state-of-the-art in research. And when they want to use it commercially, they need a license. This is a wonderful model, very well aligned with how we operate our business as well.
Now the models themselves are really exceptional. They've got a multilingual model that allows you to do same language and cross-language searching in over 100 languages. They've got a multimodal model that allows you to do searching in the images, searching in the embedded text and charts and graphs inside of other documents. And this multimodal search is really important. But that efficiency part is also important.
They just released a new V3 of the reranking model last week that has a novel approach to the way that they do reranking, but what it really allows them to do is provide a highly efficient model. It runs fast. It runs efficiently. And it does that while giving leading class accuracy. Really impressive work that the team has done, couldn't be happier to partner with them going forward.
And it's not just about Jina. Every major player in the AI ecosystem has an integration with Elasticsearch. And it's because they all recognize how important relevance is to getting successful AI implemented in businesses. And so all of these partners, we partner with them very closely. But we talked about some of the work that we're doing with NVIDIA on GPU acceleration. We're also inside their AI factory along with Dell. And we've got integrations to every one of the agent building frames like LangChain and LlamaIndex, who are here today, and so forth.
So this idea of being able to be the most flexible platform to integrate anywhere, it's central to our strategy. There's not going to be one model that's better than all of the others and rules. There's not going to be one agentic framework that wins. We want to make sure that no matter where you're starting, no matter what you're using, that you can use Elasticsearch to provide the relevant context for that application.
And this really leads into not just the models, not just the integrations, but the platform and the product itself. And when you think about Elastic, it's a search engine. It's a vector database. It's a no-SQL store. It's a columnar store. It's a geospatial store. We have all of these capabilities, and we wrap it up in a single API. That's a lot for a developer to learn to be able to just get started and start building applications. And so we're continually working to simplify that process.
When you bring data into Elastic, we use our first-party ELSER model by default out of the box, to generate embeddings for you, so you can get hybrid search without having to learn about what's a vector anyway. You don't have to start by doing that. But if you have a model that you prefer, if you fine-tune a model specific for your environment, great, you can plug it right in and there's a place for that. I mean this progressive disclosure of complexity, we really think about this a lot and how we can simplify the experiences for our users.
And nowhere is this more true than in the agent building space. And so if you think about all the steps that it takes to build an agent, I pick a framework, get a language model, connect those things together, set up memory, figure out how to write queries against the engine. It's a lot of steps that people can take. And if you already have a framework, we partner with them. It's great.
You have the best possible experience there. But if you're just starting with your data, you're saying well, what can I do with this? We want to do a lot to make that easier. And so that's why we introduced earlier today, our Agent Builder feature. And this is really designed to take any data that you have inside of Elasticsearch and instantly make it available for agents and chat and to build and extend from. And rather than try to describe it, why don't I just show it. If we can switch the laptop over, please, to the demo. Let's take a look.
All right. Fantastic. You seen that? Good. So what we have here, this is a live running cluster on Elastic Cloud Serverless. And what I did is I loaded up just a simple set of data. This is a financial services data set here. And it's got some account data, some sort of semistructured data around accounts, assets and holdings and then a lot of unstructured data, which is very representative of what we've seen at a number of our customers. News data, Financial analyst reports and then interactions between our financial advisers and the customers.
And I've done nothing other than that, I've just loaded the data. And when I come up to the system, right out of the box, I've got a new tab, I've got a new experience in the UI that says agents, and I can start asking questions. So now I can start asking questions of the system. And what's going to happen here is I'm asking the question, the system is now the agent, the built-in agent that we provide as part of Agent Builder is going to look at the data that it has in the system.
It's going to use a set of native tools, understands my question, using this, picks an index that it's going to search, writes the query, crafts this query and then runs the query, passes that result back to the language model, and we're going to see the answers coming back in terms of what it actually believes from the reports, what it's going to see.
And so right now, what I just did would normally take a developer days, hours, maybe even weeks, if you're just learning this technology to go and assemble all of the moving parts to answer this kind of a question. And you can keep going with these kinds of conversations, you can say sort of like, what are my customers -- so you can start to now just continue to ask these kinds of conversational questions with the data right out of the box.
Again, I've done nothing to customize the system. I just loaded the data and started a conversation. This is how it should be. This is a POC, the time it takes to understand what kind of applications can I go and build on top of this, went from days and weeks to seconds. You can start that conversation.
Now if I wanted to go further and say, "Hey, this is great. This looks like this is going to work for me. Now I want to customize this. I want to put this application in front of my actual financial advisers. I want to customize the system to make sure the most common tasks, the most common workflows are great. And for that, we give you an ability to customize the tools.
When I said before, we want it simple out of the box, but still to have the full power of Elasticsearch at your fingertips, this is where custom tools come in. So I can come in and I can define a custom tool. In this case, I know my financial advisers are going to be doing summaries of portfolios on a regular basis. I can add this custom tool, and I can do that with the full power of the Elasticsearch query language.
Here, I'm doing joins across the structured portions of the data. I'm doing hybrid search using a semantic search and a lexical search against the content and the news that might be related to this portfolio. And this ability to use the full power of Elasticsearch to customize it and provide that as a tool back to the language model is really powerful. So this is the first way that you can customize the agents that you build with Elastic.
The second thing that you might want to do is actually change the way that the agent engages. Out of the box, the default agent we provide just generally tries to be helpful and answer the questions with whatever data it has. But if I'm going to put this in front of a specific type of user, I want to customize it. I want to give it more specific instructions. How do I help the users more? How do I make sure that this knows exactly what tools to take advantage of?
And so here, you can see this custom agent that we created has a very specific prompt to help out AI advisers -- or sorry, help out human advisers, financial advisers. And we've got that set of tools, including the custom one we just looked at. And with nothing more than just a customized set of instructions, a custom prompt based on Elasticsearch query language, I can now start chatting with this specialized agent and start to ask a new set of questions.
So I can ask a question like this. Who are the top customers? And again, just like we saw before, this agent is going to look at the tools that it has available, figure out what's the best strategy for getting the answer out of Elasticsearch. And it's going to then figure out, okay, in this case, they need to write an ESQL query. Great. Let me write that query to figure out who our top customers are. Go out, run that query, bring the results back. And it's really nice because this is, again, a capability that's provided right out of the box.
And what you can see here is it's able to bring this data back. It sees that it's a tabular data. It sees that this is the kind of data that probably belongs in a chart, automatically starts charting it for me. Over time, I can customize. I'll be able to add this right to a dashboard straight from here to start building a regular view on top of the data. And if I come in and I wanted to just kind of look even more closely at some of the particular accounts, right?
So let's say I'm getting ready to meet with a customer. I can ask for a specific summary of that portfolio. So now, I can ask a more sophisticated question. Look at their portfolio, summarize it for me, then look up, we have further investments for the portfolio that they have. What's related in the news that might be interesting that they're going to ask about when I have a meeting with them later?
And so this idea here is going to trigger the model to, again, go and look and say, what tools do I have available to answer this question? And that custom tool that we took a look at before the portfolio summary tool is exactly what's needed for this sort of a query. And so I can go from having that top level query that says who are my top customers to a quick summary of their portfolio and then an understanding of how AI-related news might be affecting them. This idea of combining your structured view with your unstructured view is incredibly powerful.
And so this is, again, the second major feature here is I just created a custom agent in like 5 minutes on stage live. This is incredibly powerful for accelerating the process of building these applications. And it's not just about like answering questions. This is really nice. It's also about taking actions. And so I can do this. I can actually say, e-mail this to one of my colleagues. And what's going to happen here is it's going to say, okay, great. It looks like you want to take an action.
This is what Ash referred to as the Workflows feature. We've added a new set of capabilities for taking multistep complex actions into the system. And this ability to find these workflows is actually a set of technologies and capabilities we acquired from Keep. We acquired, I think, 2 or 3 quarters ago, really quickly integrated that, and we can see the send message here, very quickly looking it up. And what that's doing is it's actually going to our workflow system, and it's using this system to look up who is the contact that we want to send it to, let's look them up in the database, retrieve their e-mail, their contact preferences and send the right kind of message to that user.
You can imagine how these workflows can get a lot more interesting over time. This is just a taste, but this is how we make actions available to these agents. The last thing that I'll touch on before I get to the end of the demo is everything that we saw today, everything that we looked at, everything from these charts to the interactions, the whole thing, this is all a set of APIs in Elasticsearch. So it's wonderful. We provide this chat experience. If you want to bring your customers, your employees directly into Cabana to access it, that's great.
But if you already have an application where you might already be sending your users, you can extend that. These are just APIs. The tools are available over MCP, a very common way to connect agents to data or the agent itself is available over [ A-A ], so you can embed it directly into an agentic UI. And so this is just a sample of what you could build on top of Elasticsearch with those chat experiences as a native part of it. And so you can see here, able to just bring up the single account that we had just looked at with Elasticsearch queries directly.
And then we can pull out the chat experience, and we can actually have that same kind of a conversation with the same agent that we just created right here in this custom application. And so this idea of being able to easily walk up to your data in Elastic and start a conversation with an agent, extend that agent specifically for the workflows and the tasks that you have, connect that into your business and take action and then build that into the experiences where your users are, this is a dramatic simplification of what it takes to build these kinds of agentic applications.
All right. With that, can we switch back over to the slides, please? Just close out with one more here. So the thing that I wanted to just end on is the opportunity that we see in the AI space is huge. And I think it's a very simple story, right? We see, and I hope it's clear at this point that relevance is more important than ever before in the agentic world, in the AI-powered world.
And Elasticsearch is the best platform for relevance. And so that means that our opportunity is massive when it comes to this emerging market opportunity for AI and context engineering.
And with that, let me hand it over to Santosh to talk about our Security and Observability businesses.
Thanks, Steve. That's amazing. I'm Santosh Krishnan. I'm the GM for our Security and Observability businesses. And I'm really excited to share with you, some of our AI innovations as well as the platform advantages that we are bringing to the Security and Observability spaces.
Starting with Observability. As Ash mentioned, in observability, customers typically start their journey with us with log analytics. And they use our platform to efficiently store all their logs and then use the platform capabilities in search, machine learning and AI in order to triage and investigate issues. That's the primary purpose where we land most of our customers in Observability.
Over time, many of these customers have organically grown even in many cases, without our product, they have organically grown to add additional signals like metrics and traces and so on to bring together and use our entire end-to-end observability suite. One of the main reasons they do that is that they can now correlate all of these signals using a single platform, a single query language, a single set of workflows.
This is the main reason why they actually come to us for end-to-end observability all the while taking advantage of all the data store optimizations that Ken spoke about the LogsDB, the TSDB, all the specific optimizations that we have made for those signals, customers benefit from that as well.
The Observability space itself is changing. We have already seen a couple of generations. We have gone from legacy observability tools, which are really just alerting engines. They are health monitoring tools. It tells you what happened, but it does not really help you what to do about the thing that just happened. Those used to be the first generation of observability tools.
I would say we are currently in the second generation, where there is an added focus on triage and investigations. Unfortunately, though, that added focus has come with very complex instrumentations that you have to build into your data sources so that you may investigate your issues later. Dealing with messy unstructured data, which is prevalent in observability, it's actually a [indiscernible] to try to lend structure to it or try to solve it using instrumentation and such.
AI to the rescue, because things are changing again. Observability is changing again because harnessing the power of AI and all of that information, that dense information that resides in your logs in order to triage and rapidly resolve your issues is now going to be the focus of the next generation of observability.
Make no mistake, logs with AI will be the foundation of how you do investigations in this next generation. Together, as we have spoken about, OpenTelemetry is the other trend that is also happening at the same time. And this is really the industry's way of trying to get away from all this complex instrumentation to understand the semantics of data and so on and so forth.
So we recognize that. We adopted it. We contributed to it. So when you combine AI and OpenTelemetry, you essentially get to this next generation of observability. And of course, it's our goal to leverage our natural advantages in dealing with unstructured data and using the native AI capabilities to help our customers go through this journey.
To summarize why we win, customers continue to choose us for our platform advantages in speed, fast investigations, efficiency in storing all of those signals in observability and of course, those specific data store optimizations, which I mentioned. More recently, customers have started selecting us for our native AI and relevance capabilities in order to investigate faster. And I'll speak a little bit more towards that in a minute.
We bring all of these innovations in an open and extensible fashion. We have always been open source. But now with OpenTelemetry, we have gone all in. And over here, of course, we want to take this burden of instrumentation away from SRE teams.
Logs are back. So now I'm talking about the modern generation of observability. If you actually look at all the signals that you use in observability, logs are the most information dense signals which you have at your disposal. Your metrics and infrastructure monitoring can tell you what happened, what went wrong. Your traces and your application monitoring tools can tell you where something went wrong, so you can trace, as the name suggests.
But in order to do deeper investigations, you always have to go back to your -- to the information which is in logs in order to understand why something happened. Logs have always been the repository of knowledge, which answers the why question.
And now with AI, you can actually harness all of that dense information that's already sitting. It's already sitting in your data store in order to get to rapid issue resolution faster. By the way, today, in Elastic, we already offer our customers a combination of search capabilities using ESQL that Ken talked about, machine learning capabilities for anomaly detection and such.
And now we recently -- we just introduced this capability called Streams to just make logs magical. To give you an idea, even setting Elastic aside, in any observability tool today, if you want to get the -- get all the value out of logs, you need to understand where the logs are coming from, what are the sources of these logs. A human has to understand that, build integrations and such.
You have to understand what is contained in those logs so that I may know later what to look for. And this is especially true because logs are messy. And it does not come with structure, a priority structure and semantics. And then last but not the least, okay, I figured all of that out. I now have to also decide -- I need to figure out what questions to ask.
So when there is an issue, I have to go back to the system and figure out what queries to run, what questions to ask. And these have been burdens on the SRA teams until today. And we are taking all of those burdens away in understanding where your data is coming from, gleaning what it contains, as well as suggesting what one ought to be looking for and when time comes for investigation.
With that, I actually want to show you -- I'm going to invite David Hope, who is a leader in our product team to show you what we just introduced.
Thank you very much, Santosh. Right. So as Santosh was saying there, right, logs are back. But of course, you may not have seen them, but trust me, they're everywhere, right? You click a button on your remote control, you make a trade, large volumes of log lines are generated. They're used by practitioners to understand your experience or how quickly your trades are going through. Today, logs are incredibly difficult to work with in any observability solution. The observability industry has left a lot of room on the table to get a lot of value out of logs.
Engineers today have to code integrations. They have to create complex pipeline processing code, and they have to know exactly where and what to look for when they're doing investigations. Now off-the-shelf integrations like the ones you see on the screen here, they help a little bit. But quite often, you can't find the integration you need and application developers writing custom application code, they don't usually use a standard pattern or format, making it incredibly difficult and time-consuming to process logs.
Now with Elastic Streams, we're changing things. No need to install any integrations anymore, no need to fully understand all your log sources. All you do is point your logs at Elastic, and we take care of it. No more complex pipeline processing code to manage. No more trying to figure out what systems your logs belong to and no more hunting high and low for integrations. The magic here is that LLMs are amazing at understanding unstructured data. And Elastic, with its expertise in logs and context engineering, means that Elastic Streams can automatically organize your logs, find meaning in your logs and find problems in your logs.
So in this new world where logs flow smoothly to Elastic with any -- without any pre-interest pipeline processing overhead, the first thing that practitioners want to do is they want to organize their logs. What we do is like any good filing system, we look at the data to understand exactly how to organize our logs. And we do this with AI. So that click here suggests partitions with AI, and the AI goes off. And it's found 2 systems, a Hadoop system and a Spark system, perfect. I now have my logs nicely organized, and I can find what I need very, very quickly.
Now the next thing the practitioners want to do now that we've had our logs organized nicely is they want to find the meaning in their logs. Now you heard today a lot about unstructured data. The majority of our customers send logs to Elastic in unstructured formats. And doing analytics on unstructured data can be pretty tricky, right? So if you took like a written piece of text and you tried to put it in your Excel function, you probably wouldn't get a great result, right?
So Elastic is making things different here, right? We're an expert in dealing with unstructured data. And what we can do with Elastic Streams is we can find the patents and the meaning in the logs and the context. Let's just take a look at what that looks like here. I can create a processor, and I can use AI to look at the logs. And you can see straight away that it's found the patents in our log files. And it's not just found the patents, but there's some contextual data in here. All we gave it was the log file, and it has inferred that there are stock symbols, quantities and prices in here.
Obviously, we're using trading data because we want to bring this into your language a little bit. So now once I apply what it's found, you can see straight away that I can now do really nice analytics on this data like trying to find what the most popular stock is over a particular time frame, for example. And I can quickly save that and move on to one of the most important things that practitioners want to do. We've organized our logs. We found meaning in our logs, but now we want to find problems in our logs, and we need to make this easy. I don't want to drown in logs or dig around trying to find queries that I need to find problems. I use significant events and significant events can quickly find problems in our logs for the specific systems that we're working with.
So here, you can see that it's depicted that this is a Spark system, and these are specific problems that relate to Spark systems. I can bring these into Elastic. And all of a sudden, we can monitor our Spark systems for things like out-of-memory errors or where the task execution is performing correctly. When I do that, our machine learning-powered change point detection can immediately discover whether or not any of these problems have occurred. I'll give you an example here, this out-of-memory error. If we dig into this, we can see the query that was generated by AI. And we can see all of the logs that relate to that out-of-memory error. I can quickly dig into one of these, which makes lives a lot easier for practitioners, as you can imagine, and it automates the investigative process and root cause analysis.
Here, if I use our AI assistant to ask what this message is about, I can immediately see the root cause of the problem with the Spark system. It's given me all the information that I need to see what the problem is, and it's recommending how to fix that problem, too. So in summary, organizing logs, finding meaning in logs and find problems in logs has been a problem that has plagued the observability industry. Elastic, with its expertise in applying AI to unstructured data is bringing clarity to this chaos. We're bringing Agentic AI and LLM technology to logs, to organize logs, to find meaning in logs and to find problems in logs in minutes, not hours, so that your trades can go through successfully. Thanks, Santosh.
Thanks, David. So to summarize in observability, as you can see in this future, where we bring to bear the power of logs and our ability to deal with unstructured data in general and how we apply AI towards automating to that root cause analysis. Our objective is, of course, to grow our market share in logs as logs themselves become more important in the age of AI. We are growing beyond logs as well. So that's our additional opportunity on top of what I said. If logs are the center of investigations, our objective is to grow, is to expand from that center by adding those additional signals towards the multi-signal observability end-to-end offering. So those are the 2 main opportunities in front of us in observability.
Switching to Security. You will see a lot of similarities there. So in Security, customers typically start their journey with us with SIEM and security analytics use cases. This is largely to displace their -- or replace their existing SIEM or in many cases, to also augment them as well. So we do have both displacement as well as augmentation customers today. And the goal over here is exactly similar to the one which I showed in observability, which is to, in this case, to modernize your security operations center using the combination of the search, machine learning, anomaly detection as well as the AI capabilities that we offer.
Over time, and on the backs of a lot of investments that we have made on endpoint and cloud protection, many of our customers are now organically growing into those areas as well. So from the same platform, single click, you would go into our console add endpoint. And now suddenly, we are actually your XDR solution as well. Now it is not just the ease of use and tool consolidation why people usually grow into these other use cases with us. We actually offer a truly unified platform approach to bring all signals, whether they are coming from endpoints, identity systems, firewalls, you can use all of these signals together for your detection and investigation needs.
We are fast gaining momentum in endpoint Security. We have been making investments both in our threat research as well as in our agent capabilities for on-device blocking, remediation, forensics, all of those features that you expect in EDR tools. And on the back of all of that investment, we are now being recognized as one of the top-tier endpoint protection systems out there by third-party benchmarks like AV-Comparatives and such.
When you look at how the Security space, SIEM, Security analytics, that entire space is evolving, that is changing as well. And one might even say it is changing even faster than the observability space. So here, we actually went from legacy SIEM systems, which is all about compliance, compliance, visibility, single pane of glass to see all your alerts in one place and so on and so forth. It is the next generation of SIEM, SIEM 2.0, next-gen SIEM, whichever name you want to use, the current generation of SIEM, where we actually expanded beyond that into actually finding issues. So detecting issues with rules and machine learning, workflows for investigation, response and remediation, all of this got added in the second generation of SIEM. We have been beneficiaries of that. So when I said that customers have been adopting us to displace their legacy SIEM, we have grown on the back of that transformation. But that's changing again as well.
With AI, and this is not just a matter of adding an AI assistant or copilot or something to your existing SIEM. With AI, every key workflow that InfoSec analysts use is getting automated by AI. And by every key workflow, what I mean is all the way from ingesting data, writing your detection rules and dashboards and other content, triaging alerts and investigating attacks, finding the risk posture of your IT infrastructure, running workflows to take remediation steps. These are, I would say, the main things that you do with a SIEM. All of them are getting transformed with AI. And here, make no mistake, while we were beneficiaries of the previous generation, we are actually leading the charge over here. There is no customer conversation in security that I now have, which is not about modernizing their SOC with the AI capabilities, which we offer. We have been first to market in it. I'll show you a few of those in a minute.
Why Elastic wins in Security? Well, customers do choose us still for the benefits of the Elasticsearch platform in terms of its speed. We are the fastest security tool out there for doing things like threat hunting and such, efficiently storing all your security data so that you don't have to prefilter things away using ingest pipelines and such because the moment you prefilter, you will lose some threats in the data which you dropped. So we offer those benefits. We -- as I said, we are redefining the SIEM as we speak. We are actually leading the charge over there, and we do win because of that already over the last 1.5 years or so. And last but not the least, we actually provide a true platform for unifying all your signals. This is why we are actually starting to win in XDR. And that's because it's really our architecture. We are not taking a SIEM in one place, an EDR in another place, drawing a circle around it and calling it a platform. It's actually a true platform that brings all the signals together for your consolidated detection, investigation and response needs.
Let me speak a little bit more about what we have done when I say that we are embedding AI everywhere. Over the last 1.5 years or so, and I'm not even going to talk about our AI assistant, which, by the way, was the first one in the industry in the security space, we have actually embedded AI workflows throughout our product. We introduced a capability called automatic import, and this is to onboard your data. By the way, things like import used to take months and months in that initial part of the implementation. Now it takes weeks at worst. We introduced a capability called automatic migration so that you can bring all your rules and dashboards from your existing tools and they get migrated automatically into Elastic. And last year, a little more than a year ago at RSA last year, we actually introduced this capability called Attack Discovery. What that does is instead of your InfoSec analysts getting inundated by all the alerts that your detection rules and machine learning jobs actually found, it coalesces all of those alerts into a few attacks that matter.
So now the InfoSec analysts instead of looking at each alert to triage, they can actually go into those attacks and go investigate them and spend their time in a prioritized fashion. This has been one of the most well-received capability in our security offering over the last year. Now we have made a lot of those innovations in AI. We are even allowing our customers to use our AI capabilities on top of their SIEM tools and XDR tools because we want to meet them on their journey on where they are so that we can add AI capabilities as an entry point and then over time, migrate the rest of the SIEM onto Elastic as well. So this is something that we introduced this year. The Elastic AI SOC Engine goes by the colloquial term ease. So now you can easily adopt Elastic with AI.
Coming soon, we are going to be introducing the Elastic Workflow engine that Ash talked about on the backs of the acquisition by -- acquisition of Keep as well as AI-based entity analytics. But instead of talking about all of those, I'm going to invite James Spiteri, who's a leader in our product team in security to actually show you some of that.
All right. Hello, everyone. Let's dive right into Security. So can you all see this? Perfect. So just as David described how challenging it is to work with logs, Security teams face a very similar daunting challenge with what we call alerts. Every day, they log into their security analytics platform, and they're faced with screens like this. They're faced with situations where within a 24-hour period, they have 1,000 alerts or warning messages to deal with. These could all potentially indicate something bad happening within their enterprise. And these alerts can span multiple systems, multiple networks, multiple technologies. And the traditional way of trying to find out, hey, is this something I should investigate? Are they related? Are they not? Is to go through each and every single one of these manually and try and figure that out.
Well, as everyone else was saying about 1.5 years ago was the security industry was figuring out how to embed AI, we released Attack Discovery, where users don't have to go through that mess of alerts anymore. They go from 1,000 things to deal with to -- in this case, we reduced that down to 9 active attacks for them, 9 attacks within the organization, which matter most. And we've made this so simple for our users that any analyst of any skill level can understand, and it will work across all types of alerts and all types of data sets. So this particular ransomware attack, for example, we explained it very clearly in natural language. We very clearly highlight the hosts and other entities involved. We describe what we call the attack chain. So as an attacker within my environment, what did they do to actually be successful with this attack. And it's a really easy way for someone to digest and understand.
Just to see the impact of how powerful attack discovery is, this one attack alone is made up of 148 of those alerts. Can you imagine a human being sift through all those 1,000 alerts, find these 148, stitch them together and write out the story nicely and neatly. It would have taken hours. And that's unfortunately what the industry has been used to. But last year, as Elastic, we changed the game, thanks to the power of our platform and large language models. Now of course, usually, what would happen next is as a security analyst, I would need to grab this and do root cause analysis. I need to find out within our organization, how do we go from an attack like this one to be able to eradicate and contain the threat. And of course, this is something where like our AI assistant, our conversational agent comes into play.
Traditionally, before this stuff was available, analysts would have hundreds of wickies or pages and procedural documents that they would need to follow. They would have to manually sift through them or use traditional searches to try and find keywords here and there. That no longer works in this particular situation. We've brought Search AI to the mix. We've grounded the responses from the AI assistant with their own data. And now for this particular attack, they have an extremely tailored guide of what they should be doing within their organization, really clear steps to follow, really clear evidence and advice of what to do next. We've generated queries for them in case they want to dig deeper, so on and so forth.
As an example here, one of the first immediate steps that the assistant has told me is, look, you're going to want to take this host offline. You're going to want to eliminate the spread of this ransomware by isolating this host. Thanks to our XDR capabilities, as an analyst, I'm able to grab this remediation guidance from the assistant and straightaway run it in what we call our response console, meaning any endpoint, which I'm monitoring with Elastic Security, I can take this action right within the same window. And again, we're able to do that because of our advancements to XDR, and we can support multiple different systems with this.
Now you can see already how much easier we've made the lives of our users with Attack Discovery with the Assistant and many other AI features that we've implemented. But we want to do even more. We want to be able to eliminate the few manual clicks that I did today. And this is where workflow automation is really going to come into play. We're going to be able to not only tell analysts when an attack happens or give them remediation advice, we're going to be able to do all the triage for them manually. We're going to be able to provide these agentic flows to eradicate the threat and they go from having to look at a view of alerts or a view of attacks to going to a view like this, where, "Hey, look, we already tried this with AI for you. We've decided we can close these alerts or perhaps this alert needs a bit more work," and we're going to assign it to this particular user. So at the end of the day, what the user actually ends up with is a message like this, where, "Hey, here's what we detected in your environment, and here's everything we did when we detected that threat. We took this host of line. We quarantined some files. We created a case for you. We reached out to whoever is involved in this attack. There might be a few things left for you to do, but we're going to tell you exactly what to do." And this is the future with workflows, which is really exciting for us.
Now we saw with Anish -- with Steve, I should say, the power of Agent Builder and the conversations we can have there with agents and also with workflows. So what we've done, as Steve already demonstrated, is we've brought workflows to Agent Builder. Now in the Security world, our users are going to have potentially hundreds of these workflows that they've built, hundreds of automations that are going to run automatically in the background or perhaps on a schedule. They're immediately transferable to Agent Builder. So people can converse with them without having to do any additional work, which is really phenomenal power to be able to give our users.
So in this example here, I have my Agent Builder, I have created what we call a threat hunting agent, an agent specifically designed to work with Security data, whether that's structured or unstructured text, but also be able to take some of these actions with workflows. So what I'm going to do is I'm going to ask a very typical question that security analysts might want to ask. I want to ask, can you provide a summary of the top 10 processes run by administrator. Now what this is going to bring to me is full natural language searching of our structured and unstructured data at the same time. So agent Builder is going to identify what it should do. It's going to do that thinking step here. It identified in this case, I'm going to run a query and it found the top 10 processes run by administrator. Now some of these I recognize, but some I don't, especially this one. I don't really recognize this here as an analyst. It's being -- it's really caught my eye something I want to investigate further.
So what I'm going to do is I'm going to ask Agent Builder here, look, what is this particular process? And agent Builder is going to identify what it needs to do to give me that answer. It's going to grab what we call a hash, which is a unique identifier for that file. So it identified it should run a query to do that. And then it's going to look up that hash, that unique identifier against what we call a reputation system. Is it going to -- is this file malicious? Have any other vendor seen this particular file? And in this case, said, yes, this is a malicious file. And it broke down this to me in a way that's really easy to understand. And it did that by invoking a workflow to pass that hash onto this reputation service.
Now the next thing I might want to do is, okay, we know we have some form of malicious file in my environment. I need to open up an incident. I need to make the people who are on call aware. And I don't want to really leave the screen. I want to keep investigating with Agent Builder, but I also want to start that process. So we're going to ask Agent Builder to go ahead. So we're going to say, look, can you please check who's on call? That's the first thing we want to ask them to do, create a Slack channel for this incident. And then what we want is to also summarize all the findings so far, see how many instructions I'm giving the agent builder here. Add the person who's on call, add the on-call user to the Slack channel and explain what steps to take next, okay?
So along those of instructions, typically, I would have to go some other system, find out who's on call, manually go create a Slack channel or go somewhere else to run the workflow, so on and so forth. And in this case, agent builder is going to go ahead and do that for me. So we checked the on-call schedule, which is unstructured text in this case. It found who's on call. It identified that to create a Slack channel needs to call the workflow to do that. It added the on-call user, in this case, is also James, to that Slack channel and lastly, summarize everything that James needs to do.
If we go to our Slack here, we'll be able to see all of that. So this channel was just created. You can see 3:40 p.m. James was added and given all the information he needs to continue this investigation. So to recap, we went from a world where our users are manually investigating thousands of alerts. We fixed that with attack discovery. We allowed our users to eradicate the threat using assistant guidance with our XDR platform. And now with Agent Builder, we've brought the full functionality of context engineering to the security user to be able to contain, eradicate and solve security incidents. Santosh, back over to you.
Thanks, James. It's amazing. Let me leave you with a summary of our opportunity in the security space. As you can see behind all the innovations, which you actually just saw, our opportunity here is to grow our SIEM market share. Mind you, we are already doing well in the SIEM space. We are one of the fastest-growing vendors in that space. And our opportunity is to grow that market share further through, again, displacement and augmentation strategies, which I mentioned earlier, so that we can help our customers realize this future of the AI-powered security operations center. An additional opportunity that we have is to grow beyond SIEM, largely into use cases like XDR and CDR by providing that same unified platform. You can bring all your data together into a true platform to detect, investigate and respond across your entire IT real estate.
With that, let me actually bring Ken back on stage to summarize.
I'll wrap up. Thank you. Just to wrap up the product section, I think you hopefully see that we have a lot of conviction, that we have a huge opportunity in AI. I'm going to summarize it as two opportunities. One is we have an opportunity to become a fundamental part of the generative AI and agentic AI tech stack. As a vector database, as a context engineering solution, we have an opportunity to be part of that tech stack.
I think the other opportunity that I'm super excited about is using those same tools ourselves to disrupt the observability and security space. I think the observability and security space are going to see a lot of change because of AI. There's lots of manual things that happen in these two spaces. There's lots of pattern matching. Things are going to be much better done by machines than by humans. And I think we have an opportunity because we are developing these same tools to lead in that disruption of security and observability.
So with that, I'd like to end the product section, we're going to have a break now. We're going to take about 12 minutes. If we could be back in the room at 3:55, we'll go through the go-to-market and finance sections. So see you at 3:55. Thank you.
[Break]
Good afternoon. I'm excited to talk to you today about the transformation we've been driving in our go-to-market part of our business and to share with you the momentum we're seeing and the opportunity ahead. Ash mentioned to you that we have the advantage of incumbency. We're trusted by leading organizations around the world across all segments. Our Search AI platforms provide incredible value to customers for search, observability, Security. But I'm telling you, we are just getting started.
Now many of you know I came to Elastic 20 months ago as Chief Revenue Officer. And after I arrived, we embarked on a process to evaluate and assess our go-to-market motions, our systems, our processes and our teams. We took a number of actions to get better as an organization. We're seeing results now, and we're refining and making refinements to continuously get better. This is a never-ending process for us. But all of this is designed for us to serve more customers and drive more growth for Elastic. I wanted to share with you some of the improvements we've made in areas we focus to drive our execution. Number one, segmentation and coverage. I'm going to double-click on this in a minute, but I'll tell you that what we found is that we had outgrown our previous model, and we had an opportunity to do a better job of aligning our sales capacity to our largest opportunities.
Number two, incentives. We've aligned our sales incentives to drive incremental growth for Elastic and capture the AI opportunity that we have. Number three, operational rigor. We're running the sales organization with a much higher degree of operational rigor. This includes everything from how we forecast, how we generate and track demand, how we progress pipeline through the funnel, how we make sure we have hygiene in our pipeline, how we review deals. All of this is being done at a much greater level of granularity. And we're doing it -- importantly, we're doing it consistently around the globe up and down the organization.
Now none of that would be possible without number four, improvements in our systems, our tools and our underlying data. My RevOps team has done a great job here transforming how we run the business. We've also made improvements in generating demand, creating pipeline. We track this every 2 weeks in great detail. Our marketing team is doing a better job than ever. Our sales development team is doing a better job of processing those leads. Our sales team, our partner organization is generating more and more opportunity. And we focused our teams on 3 specific sales plays, which I'll share with you in a minute. The other area that I'll highlight is we've gotten better at hiring. We've reduced the cycle time for hiring. We're now tracking that with the rigor that we do our forecast.
We've gotten much better at onboarding and enabling our sellers. We've invested in underlying enablement platform that we didn't have before. We've got more structure, and I'm really happy with the results. Now let me jump in for a minute on segmentation and coverage. So I know this was a topic of conversation 5 quarters ago. And like most tech companies, at a high level, we segment the market between enterprise, commercial and SMB. And SMB for us is our monthly cloud business, our product-led growth. And what we wanted to take a look at after I got here is how are we assigning accounts, what was the logic we were using to sign accounts into enterprise, commercial and SMB? How many accounts did we have assigned in each? And how did we assign sales coverage to those accounts within the segments?
And what we found is we had outgrown the processes we were using. We weren't aligned to best practices, and we weren't taking the best advantage of our sales capacity to our greatest opportunities. So we went through a process of evaluating all of our accounts by looking at their total addressable spend, what they spend on the solutions we sell, their propensity to buy Elastic and that took into account a number of variables and their historic spend. And we use that to place accounts in the right place. Now we've evolved this, and I'll share with you at a high level how we segment the market today, still enterprise, commercial, SMB, the top in enterprise. We've subsegmented. A small number of our largest potential customers are in strategic. That's where we have our densest sales coverage. The bulk of our enterprise accounts are in this enterprise block. And what we've done here, particularly in our large markets where we have density, we have reps and entire teams focused on 1 of 2 motions, either expanding with existing customers or landing new logos.
We followed that same logic in commercial. You can see the commercial expand, commercial hunter segments. And then we built out what we call commercial general business. We literally moved thousands of accounts out of enterprise, out of commercial or out of the top 2 levels of commercial into general business. Not that these accounts aren't important, but they represent smaller opportunities. We wanted to align our coverage and our cost of that coverage to those opportunities, and we built out an inside sales team at lower cost. And this allowed us to do a couple of things.
One, our enterprise and our expanded hunter commercial account executives now have dramatically less number of accounts, so they can focus on those accounts to go deeper in the case of expand. And for hunter and going after new logos, they focus on the accounts that have the greatest opportunity. And as I mentioned, we have territories and we have teams focused on 1 of those 2 motions, so we get really good at it. Before, our accounts had too many -- our account executives had a large number of accounts. They were a mix of installed base and white space accounts they weren't able to be proactive. And what we're seeing now is that we're in opportunities. We're winning deals in places with customers that we've never been before because our reps have more time to focus.
In addition to this work, we've made strategic investments in the field and other areas to drive greater customer intimacy, to drive productivity of our account executives and to shorten our sales cycles. The customer architects listed here on the screen, these are our post-sales engineers that work with our customers to get the most value out of Elastic. They help our customers take advantage of the latest features like what you saw demonstrated here today. They also help our customers optimize their implementations to make sure they're running efficiently because we know if our customers are using Elastic efficiently and they're using our latest technology, they're going to be customers for life.
We've made additional investments in specialists in the sales organization. For example, 18 months ago, we built out a team of Gen AI specialists to work with our account teams because we saw this opportunity exploding. We charged our sellers with going to their customers and finding out who's building Gen AI applications, what baked their databases are they testing? What were they trying to accomplish? And once they get to those decision makers, we bring in these specialists and having a huge impact. We've also expanded the specialist team for security. We've had for a long time, technical security specialists, but we added sales security specialists to help us get in front of more opportunities, get us into more at bats.
You saw the technology that Santosh's team demonstrated. We win when customers evaluate Elastic. We're like -- we want them to go -- we want them to test us. We want to look at other competitors because we win. We're just going after more at that. We've built out a value engineering team that builds ROI models and executive messaging to help our sales teams close large transformational deals, oftentimes helping customers migrate off of legacy incumbents to Elastic. And then on the low end, we have a large number of low dollar renewals. We built out low-cost renewal managers to run a repeatable process for driving our renewal rates up. The other area I want to share with you that we've driven transformation is around our sales plays. We went from a fragmented model to 3 focused sales plays. We treat these like products. They're designed with intent. They're measured with rigor, they're scaled with discipline. Each of them has training for our sellers, content, collateral models to work when we engage with customers. The 3 plays are victor and vectors. This is our Gen AI play. The second is race to displays. This is where we're going after legacy incumbents. And the third is free to paid, just as described.
Now this isn't a new motion for Elastic. We've converted free users to paid for a long time, but we've got more structured. And how we do that, we've given our sellers insights into who's using free Elastic, how they're using it. We're giving them tools so they can go to their customers to show the value of going to paid Elastic. Now these transformations that we've driven are driving results. I'm really happy with my team. I'm proud of my leaders, how they've leaned in. And what we're seeing is better performance. We're driving better consistency, predictability. We've had 4 straight quarters of strong sales results, which you've heard on our earnings announcements. And I'll also share with you that we've seen improved productivity.
Last year, our productivity per AE per account executive was up high single digits after previously declining. And we saw meaningful improvement in sales efficiency, meaning that the more -- we're getting a better return on our investment in the sales organization. And because we have the right foundation and we now have an investable model, we've been thoughtfully and systematically adding sales capacity to drive our growth for the future. Some other signals of our success. We grew the number of accounts greater than $100,000 ACV by 14% last year, and we grew the average per customer in that cohort. We saw that continue in Q1. And I'm very excited to share what we've seen in growth of our $1 million-plus customers. We grew 27% last year. We continue to grow at that pace in Q1.
Now all of that, I'm happy about. I'm excited about what we've accomplished, but I'm really excited about the future. And I'll show you why. Ash mentioned to you that over 50% of the Fortune 500 are paid Elastic customers. But when I widen the aperture a little wider at the Global 2000, it's only 42%. That means we have 58% to go and convert Elastic customers. And I know we can help them. And this is part of why we now have dedicated territories, dedicated teams focusing on getting better at landing to go after new logos. And if you just put that aside and look at our existing customers, what this shows you is that only 19% of them use us for more than one solution. But that 19% represents 75% of our sales-led ARR. We have a massive opportunity to expand in our existing customers. And that's why we have territories and entire teams focused on expand, going deeper with their customers. They have fewer accounts per AE to go deeper, learn about their problems, show them how we can solve their problems, go to the new buying centers to expand.
Now I want to show you a customer journey with Elastic. This happens to be a U.S. headquartered retailer that has physical stores around the country, a large web presence, and they started with Elastic a few years ago with observability on self-managed. And you can see that their ARR for us was flat for 2 years, but then they chose us for search in the cloud and their ARR doubled. And shortly after that, we went through our segmentation exercise and the enterprise AE that covers this customer was able to spend more time with them, better understand what they're trying to accomplish, learn about their challenges. And we started helping them create the next-generation e-commerce experience, and they chose us for vector search and our Gen AI capability. They also started using our AI assistant and observability and their ARR doubled.
We see opportunity for this to continue to grow as their new e-commerce platform goes into full production. It's an example of customers going from self-managed to cloud, 1 solution to 2 and the potential and opportunity we have when a customer is using us for regular search, keyword search going to vector search.
I'll close with this. We've made a lot of improvements. I'm really proud of my team and where we are. We're operating at a high level, but we're continuing to drive improvements in the team. We're now investing in capacity for the future in order to capture the AI opportunity we have at hand. What I can tell you is it's a great time to be at Elastic. Thank you.
I will now turn it over to our Chief Financial Officer, Navam.
Welcome, everyone. I'm Navam. Thank you, Mark. Great to see you today. You heard about Agent Builder. You heard about Streams. You heard about workflows. Ton of innovation we're driving at the company. It's truly a dynamic and exciting time to be here. I want to start off by summarizing before I get into the finance stuff, what you heard from my colleagues about the Elastic Advantage. So first and foremost, we are a company with a massive amount of platform innovation. Customers use us where data has gravity, be it on the self-managed side or the cloud side. And we are driving innovation in both. You've heard about that from my colleagues, Ken, Steve and Santosh, about the features and functionality we're driving into both cloud and self-managed platforms.
Second, you just heard from Mark, our GTM strategy is gaining momentum. Mark talked about the revamped strategy that we have in place. It's been in place for over a year now. We are adding customers efficiently, and we are expanding them. Third, you heard from Ash about our unparalleled advantage in unstructured data, relevance and context engineering. This is our defensible moat. And because of this advantage, we were made for the Gen AI era, and we're ready to take on this Gen AI opportunity ahead of us. So in my section, I want to talk about how we turn these advantages into what you're all here for, revenue growth, attractive margins and growing free cash flow, all right?
So before we do that, I'm going to run through this pretty quickly to baseline. I want to talk about the progress over the last 5 years. We have built a solid base of revenue of over $1.5 billion over the last 12 months of trailing 12 months. This revenue comes from -- and at the same time, we've been increasing our revenue in double digits. This revenue comes from 3 sources. Bottom of the graph is our sales-led subscription revenue. Middle is the monthly cloud business, which is self-serve. And the top of the graph is our services business. If you look at our professional services business, this is in support of our sales-led subscription revenue. We sell it to help our sales-led subscription customers grow. It's about lowering barriers to adoption. It's about shortening time to value, and it supports our sales-led business, right? The monthly cloud business consists mostly of SMB customers.
In the past, this grew with high SMB spend. But around 2022, you saw that SMB spend was moderating, and that's the dynamics we're facing today. So over the past few years, we've matured as a company, and we've focused mainly on larger strategic accounts and high propensity commercial accounts, as Mark talked about. And we do -- we serve this segment through a sales-led motion. So this sales-led motion leads to sales-led subscription revenue, and let's take a look at that in more detail. We've maintained a very strong growth rate in sales-led subscription revenue. In 2025, we grew 20% and this sales-led subscription revenue is becoming a bigger and bigger percentage of our total revenue. In 2025, this revenue line reached 81% of our total.
This is the segment we spend most of our time and effort on and our investment in. We tell our sales teams and we incentivize our sales teams to go get customers in this segment, either in self-managed or cloud, and we incentivize them to meet our customers where they are. So as you think about our business and as we think about our business, sales-led subscription revenue is the primary barometer of how we measure our success, not just cloud, not just self-managed, sales-led subscription revenue in aggregate, both of them is how we measure success for us. All right. So we delivered these strong revenue lines along with rapidly advancing our operating profit and free cash flow margins.
So on the graph on the left, you'll see our non-GAAP operating profit margins. You'll see that we reached breakeven in 2022. Since that point, consistently adding operating profit ending at 15% in 2025. FCF follows a similar trajectory, right? Shown in the chart on the right, we've reached 19% in adjusted free cash flow in 2025. What's here -- what you're seeing here is basically the inherent leverage in our model. We have high product gross margins, and we have leverage on our sales and marketing and G&A line items, and that's causing us to be able to deliver these strong operating profit and strong free cash flow lines. We expect this to continue.
With improving product profit margins, with improving free cash flow margins and strong revenue growth, we're continuing to see increases and progress towards the Rule of 40. FY 2023, we had Rule of 40 of 29%, and we've progressively grown that to 36% by FY 2025. We're continuing to make progress there. So Rule of 40 is how we think about balancing how we invest in growth while at the same time, delivering free cash flow. So that's the state of the business over the past 5 years, very strong metrics. A few slides ago, I talked about the importance of sales-led subscription revenue. And these next few slides and sections is about diving deeper into that revenue line item, right? I want to talk about sales-led subscription momentum and how we can support this and make it a durable business.
Let's take a look at some data, and Mark mentioned this. Our GTM strategy is anchored on our highest value customers. While at the same time, our product team is delivering continuous innovation, leading the market in search observability and security. And this tech is resonating with these customers and more and more customers are joining our $100,000 customer ranks and $1 million customer ranks. The $100,000 customer rank that you see here on the left accounts for the majority of our sales-led revenue. It's 87% of the total. And these customer counts are consistently increasing. And at the same time, if you look at our average customer value, that's growing over time as well, right?
So let's look at how we are able to drive this growing average customer value on the left-hand side. We have a powerful model of landing new customers and expanding them, growing our $100,000 and $1 million ranks. New customers in the beginning drive a smaller amount of ARR, but that ARR compounds over time with expansion. Our platform basically is meant to adapt and scale with customers bringing in data, helping them become more efficient. And this includes some of the largest customers in the world. And the flexibility and scalability of our platform is the key differentiator for these customers and the reason we succeed with these customers. So customer expansion is driven by them bringing in more and more data into our platform, bringing more -- creating more workloads and then upgrading to higher subscription tiers to get premium features and then also adopting multiple solutions as they go deeper into our platform. And all of these dynamics result in a high sales-led net retention rate.
In Q1, we saw a sales-led net retention rate of 113% TTM. And this was driven by the strong expansion that I talked about and the stable gross retention that I talked about -- and the stable gross retention. So we've built a durable customer base, and there is great expansion opportunity from both new customers and existing customers. And we have still a long way to go. From the new customer side, when you look at the G2K customer count that Mark showed you this graph before, we still have a lot of white space. 58% of the G2K customer base still remain to become Elastic customers. That's a lot of white space for us to go get. The existing customer side has a lot of opportunity as well. On the left-hand side, I think you've seen this graph before. Mark talked about this. 19% of our customers have more than 1 solution, 2 solutions or 3 solutions, and they contribute to 75% of our sales-led ARR. We see much higher ARR per customer after they adopt multiple solutions.
On the right-hand side graph, you'll see that the median for a 3-solution customer is 12x that of a single solution customer. This is our opportunity. As we make inroads with existing customers, again, we -- as I said, we expect workloads to grow and Ken highlighted how we've architected our solution to make things more efficient for our customers and incentivize them to bring more into our system and bring more into our platform and also adopt more and more of our solutions. And this is our repeatable playbook for years to come. As I said, there's a lot more growth left for us.
So that's the expansion dynamics of our sales-led subscription revenue. I want to talk about what gives us confidence in the future. And I want to take a deeper look at our customer cohorts. So what are you seeing here? This chart displays our sales-led subscription revenue customer cohorts from FY '13 to FY 2025. Each band and color shade represents a cohort of customers based on when they were first and elastic customer of ours, right? And if we draw a dotted line from the end of FY 2020, you'll get to see that there's a good balance from -- of growth from long-standing customers and newer customers. Customers before 2020 contribute to -- there's almost a 60-40 split, contributed to 61% of our recent growth and customers since 2020 represented 49%. This is a good balanced growth dynamic from our customer cohorts.
The cohort data also revealed 3 very important takeaways, which I'll go into, related to the durability of our cohorts, the resiliency of our cohorts and the Gen AI tailwinds that we're beginning to see over the past couple of years. Let's dive a little bit more next into these cohort data and talk about these 3 takeaways. So the first takeaway is that these cohorts show remarkable durability. This is a chart of our most mature cohorts. Even these cohorts are still expanding. Though some of these customers have been with us a while, and normally, you would expect to see more stable ARR rates from these customers, they're similar to our new customers. They're bringing in more data, and they are very active. The FY '13 through '20 customer group -- as a group grew their sales-led ARR by 10% last year. Even these customers continue to be remarkably active just like our new customers. And this expansion durability supports our growth algorithm.
The second takeaway is that we see remarkable resiliency from our customer base. You all remember calendar 2022. This was a challenging time for software. I was there as well. Similar to most of the industry, everybody faced budget constraints and everyone was forced to prioritize optimization on their spend. And during that time, our customers were no different. They face the same dynamics. But we worked with our customers to reduce their spend and encourage them to adopt new features of ours like frozen tier storage, for example, which will help them become more efficient. And the aggregate result of all that is a slower expansion rate in that period.
But during that period, we also did not see an elevated churn rate. We saw a slower expansion rate, but we didn't see quite an elevated churn rate. Once those headwinds passed, the growth trajectory continued. And I think that was a great data point that demonstrates, one, how resilient our customers are; and two, how important our customers think our platform is, how much value they see in our platform and the amount of innovation we put into our platform, they basically are making our software essential technology in their workflows, and this is great news.
The third takeaway relates to the tailwinds we are beginning to see with Gen AI. Now this graph shows the year 1 to year 2 ARR expansion of each cohort. This is the first year expansion of each cohort over the past 6 years. FY 2024 is showing a greater year 1 to year 2 growth than any of the cohorts in the recent past. If you draw that dotted line that you -- or you see the dotted line over there, that represents the '19 through FY '23 cohort average. That's 20%. FY '24 is twice that size, 42%. This is a significant data point because that's the first cohort that has seen a full year of Gen AI impact in their first year growth.
In fact, if you look at this FY '24 cohort in a little bit more detail, you'll see that 11% of this cohort adopted some kind of GenAI functionality. But this minority grew more than -- or contributed to more than 60% of the cohort's net expansion rate. Right? This is an excellent outcome. And this is the data point that we have of the accelerated revenue growth we see when customers adopt GenAI use cases. And when you look at it more broadly and you look at our aggregate ARR in FY '25, split it between customers who use Gen AI and split it between customers who do not Gen AI, there is a clear difference in expansion rate that comes up.
Our customers have a 6% -- or we see a 6% tailwind from our customers if they are using Gen AI. Gen AI is driving acceleration for us right now. So while we're seeing all these promising results related to Gen AI, it's important to remember, we're still in the very early innings of customer adoption. We've seen strong adoption among our $100,000 customers with 20% -- more than 20% using Gen AI features. And we've made strong progress moving from 4% to 21%. But there's still a fair amount of room for our customers to start using Gen AI and grow into the ranks of the $100,000 category. And even among the customers who are in the $100,000 category, they're still in their infancy in the number of apps that are GenAI enabled, and there's going to be more and more apps that they build, which will then get them further into their journey into Gen AI and create more maturity and more tailwind for us.
All right. So now I've shown you a lot of our cohort data, our expansion data, and you've digested how our sales-led customer behavior is. You've seen about -- I've talked about how durable things are and how resilient our customer base is and how we're starting to benefit from the Gen AI functionality -- from the Gen AI tailwinds. Next, and I know this is something you've been looking for. How do you put this all together? How do you think about this from a midterm framework? And let's go there next.
So we view sales-led subscription revenue, both self-managed and cloud to be the midterm growth engine of our company. This growth comes from 2 components. The first component is the continued expansion -- sorry, continued execution of our land and expand model. on the core search, observability security use cases on the customer base that we have and the new customers that we're going to add in the G2K. We discussed the durability of our customers. We discussed the white space we have in the remaining customers where we have to get. We expect a 15% plus growth rate by the medium term, not counting the benefits of Gen AI for our sales-led subscription revenue.
The second component, and this is still in the early stages, is related to the continued penetration of generative AI among our sales-led customers, both in terms of the number of $100,000 customers we can get as well as the penetration and maturity into those $100,000 customer accounts. We expect a 5% plus tailwind gradually as Gen AI increases among our customer base. So we expect this core execution plus tailwind to result in a 20% plus target growth rate in the medium term. As always, we will operate with operating expense discipline, and we intend the total revenue and adjusted free cash flow margin to result in a 40-plus Rule of 40 target.
All right. Let's take a look at this in a little bit more detail. As I mentioned, sales-led subscription revenue target growth rate is 20% plus from those 2 components of the base growth rate and the Gen AI tailwinds. That revenue line, the sales-led subscription revenue line is expected to be 85% to 90% of our total revenue. Both non-GAAP operating margin and adjusted free cash flow is expected to exceed 20% plus, driven by our disciplined OpEx and operating leverage -- disciplined OpEx management and operating leverage. And finally, we expect to maintain net dilution rate below 2.5% as we remain disciplined in adding headcount, while at the same time, being competitive in the talent market. Okay.
So when you look at our operating margin improvements in the past and you'll see the leverage that we have, which gives us confidence in reaching this 20%-plus target. FY 2026, I talked to you about was an investment year for us. After those catch-up investments, we expect to decrease sales and marketing and G&A expenses as a percentage of total and get our operating margins above 20% through the combination of our disciplined OpEx on sales and marketing and G&A and also our gross margin improvements. Our product gross margins are already above 80%. You can see that in our subscription revenue line. That's grown, but there's more growth to have -- or there's more increases to have in our subscription margin line. So the combination of subscription margins, which results in higher gross margins and leverage in our sales and marketing and G&A will allow us to get to 20% plus. You can see the progress we've made in sales and marketing and G&A over the past 5 years as well. So we're confident about hitting this 20% plus target.
Okay. So now given that we're further along in the year, and you've all digested our medium-term framework now, I'd like to touch on our current fiscal year in the context of aligning to this framework.
In the beginning of the fiscal year, we detailed there were certain macro conditions that were emerging. It was very uncertain. We didn't know what the impact of consumption and commitment plans were, what patterns could be. We built some of that into our guidance that we provided in the beginning of the year, and we essentially carried most of that through in the first quarter -- after the first quarter. Since then, now that we're further along in the year and further along in the quarter, we've gained greater visibility into the demand environment. And we feel good about the commitments we're seeing. So there's still headwinds like -- you all read the news, the government shut down, that's still ongoing. But we believe we're better positioned than what we had originally anticipated.
So as such, I'm updating my second quarter and full year guidance to the following. You may remember that in Q2, we guided $415 million to $417 million. At the time, we had raised this by -- we were $6 million above consensus and a 14% year-over-year growth rate and '26 was $1.679 billion to $1.689 billion, also a 14% rate with a 16% op margin target. I'm updating this now to a Q2 total revenue target or guidance of $417 million to $419 million, an additional $2 million above the $6 million that we've already increased. And also in FY '26, we're updating the range from $1.697 billion to $1.703 billion, which is a 15% year-over-year growth rate. In addition to this, we expect our non-GAAP operating margins in FY '26 to be 0.25 point higher at 16.25%.
Okay. So moving on to discuss our balance sheet. We have a strong balance sheet driven by a growing cash balance that's fed by a growing free cash flow line. With our increasing amounts of cash, we have three primary capital allocation priorities.
Our first priority is to continue to invest in the business and our platform to position us to win in GenAI. It's a massive GenAI opportunity ahead of us, and we need to drive durable growth.
The second priority, and we've -- this is up because of the GenAI announcement we just did, we will evaluate and pursue acquisitions that further our strategy, similar to the ones that we just did. We'll do so with strict financial discipline. These traditionally have been tech and talent tuck-ins to enhance our search platform or observability and security platform. So this will be our second priority with -- second capital allocation priority.
And finally, this is new. We will begin returning capital to shareholders through a share repurchase program in order to partially offset dilution. And we will do ongoing share repurchases unless more attractive acquisition opportunities become available to us. So as part of this acquisition -- capital allocation strategy, I'm pleased to announce that the Board has authorized $0.5 billion for our initial program, and we expect to use more than 50% of the authorized amount in fiscal 2026. And going forward, we expect to return 50% of our free cash flow, as I mentioned, through share repurchases. And again, unless more attractive acquisition opportunities arise that require us to use some more cash.
Okay. So to close, we are incredibly excited about the opportunity ahead. We have a business supported by a strong land-and-expand motion. Generative AI presents a dynamic and exciting opportunity for us here at Elastic and our platform was made for this moment. And finally, our model supports a tremendous leverage, which allow us to grow revenue and grow our margins, expanding to rule of 40 and above.
Thank you very much for being here. I want to welcome back Eric, back to the stage.
Okay. Thank you, everyone. We're going to have a Q&A session in a second. They're just going to set up the chairs. We're going to get all the people who presented back on stage. [Operator Instructions] With that, I think we've almost got the chairs on stage. I would call the team to come back up, please.
These guys work fast. And by the way, [ Claire and Chantelle ] come bring microphones. Go ahead. Ittai, do you want to go first?
2. Question Answer
Ittai Kidron from Oppenheimer and thanks for the presentation today, very helpful. A clarification for you, Navam and a question for you, Ash -- a clarification for you, Navam. When you talked about the GenAI contribution to your long-term model, 5 points, you said gradually growing into it. Does that mean that in the early years here, it will not be 5%, meaning your targeted growth is under 20%. And in time, will get to 20% just on that?
And then Ash, you made a very compelling presentation to the -- you and your entire team around the technology, the differentiation, and I always come away very impressed with the technology. But when I look at the competitive space, whether it be a Datadog or a Dynatrace or the security companies like a CrowdStrike, they are all growing north of 20% for quite some time. So help me understand what is it in the model that is so difficult in translating the technology into reality of dollars. And I understand that there's a big GenAI opportunity ahead. So you can always say, well, talk to me two years from now. But a lot of the advantages have already existed for the last three, four years. What is it that's been missing in making that and how are you addressing that gap -- perceived gap between the capability and the reality of what the numbers are?
Why don't I take the question -- the second question first, and then maybe that will lead nicely for Navam to answer the first. So the -- look, the most important thing to understand is what is the role that customers use us for in an enterprise. And it's always been around unstructured data. Like that's been the primary problem that Elastic was always used to solve. We got into search first, and that was the core use case. Search in the early days just did not have the same market size and opportunity as maybe structured data and the opportunities around it or even observability and security.
That led us to go into other areas where unstructured data was a core problem. And so we got into observability, we got into security, but we were methodically building out all of the capabilities that we needed to be a very strong player, be a very compelling player, starting with our core strengths, starting with log analytics for observability and starting with SIEM for security.
So we've been on this journey. But keep in mind that when it came to search, that was, in some ways, the smallest part of the business. What has changed for us in every way possible is that unstructured data has become more important than ever before. Our core search business is seeing more interest than we've ever seen in the past. That market, that solution area is today our fastest-growing solution area, and that wasn't the case in the past. That's number one.
Second, even when it came to observability and security in the past, although we had the best back-end data store to deal with observability signals, to deal with security signals, we didn't have anything that we could completely and conclusively come forward with and say, this is why we can solve the problem better, faster in a more efficient manner. AI has been that unlock even in observability, even in security.
When you see the demos today, if you paid attention to the demos today, what you saw was stuff that matters to security and SRE practitioners that was not possible before and more importantly, that others aren't able to do even today. All of that comes from that really amazing advantage that we have from AI.
Now to me, this is definitely an opportunity for us to continue to improve upon our growth rate, accelerate everything that we are doing and get well past the 20% mark. That's the goal. That's the history of how we got here. That's the reason why I'm so excited because effectively, what was always our core strength, Ittai, has now become what the market cares most about.
Yes, let me take that first question, Ittai. I'm glad you asked it. So here's the way you should think about our model. And I hope I gave you enough data on the cohorts and the expansion rates and giving you enough cuts to show that, look, 15% is a baseline. We expect that to be there. Just based on continued core execution on things we have without anything coming from the background and helping us along. That's just the core execution. So that's something we want to be solid about, right?
And then beyond that, there's the tailwind of -- so it's 15% plus and then there's 5% plus. AI is just a very dynamic market, so it's going to be progressive as we go into the midterm, which midterm for me is from the end of the year, roughly 3-ish years is the way I think about it. So this year, we've guided to 15% for the full year. Sales led subscription revenue is about -- generally about 2 points higher than that, right? So from there, is the tailwind growing to a 20%-plus target rate which the framework suggests in the midterm period. So that's how we think about sort of a growing tailwind on the sales-led line, which will end in the 20% plus rate in the framework model that I just talked about.
But just to be clear, those AI tailwinds are happening now. We're confident about those AI tailwinds continuing. Just the timing, it's a dynamic market. So the timing of exactly quarter-by-quarter mapping it out is a difficult thing to do.
Koji Ikeda from Bank of America. Thanks for doing this, great presentation, guys. I wanted to ask a question may be related to Ittai's question about budget unlock with the customers. It sounds like the generative AI opportunity is tremendous for you guys. Technology is fantastic. I mean you talk with any customer out there. Elastic is just very, very well known in the end market. And so what does it take for the customers to spend more with you guys? Is it just more strategic shots on goal? I mean, Mr. Dodds, this question may be directed mostly towards you about what are you doing within the sales organization to really drive more spend over to you guys?
Yes. Maybe I'll touch upon it and definitely want Mark to elaborate. But in a lot of ways, Koji, as you said, the market opportunity has always been there. Like part of it has been just the opportunity around AI, making search more and more important, which has been a big part of why you see this enthusiasm. You see the cohort data clearly showing how AI is contributing.
The other part of this is when we looked at our segmentation model in the past, there was definite inefficiency in the fact that our sellers weren't really specializing. Our sellers were hybrid sellers, if you will. And a lot of the work, a lot of the hard work that we went through at the beginning of FY '25 in terms of the work that Mark did was to make sure that we could go deeper, we could go in a more intentional way into accounts, into enterprise accounts to capture a bigger share of the wallet. These deals take time. But when you're able to convert a customer over from an incumbent SIEM platform and consolidate them into Elastic, those deals tend to be very big. One example was the GSA announcement that we made in the public sector, I think it was a quarter ago.
It was in June.
In June. That is the perfect kind of example of the kinds of opportunities we are now able to go after with the kind of work that Mark's team has done. But Mark?
Yes, I think you said it well. But as I mentioned earlier, we've reduced the number of accounts per AE so that they can go deeper with those customers and cross-sell into new buying centers. And we're seeing that gaining traction and building pipeline and getting us into new business. We're also focusing on net new logos with territories and entire teams focused on that. And then as I mentioned, we're adding more sales capacity. We're getting more at bats to grow our business.
Thanks again for doing the Analyst Day. Mike Cikos with Needham. I appreciate all the information on the cohorts, the financial model. On the 15 points baseline that we're talking to, it would be helpful to get a better understanding of the different -- the use cases that are giving you guys that confidence, right? I know we're bulled up on search. We're seeing it at the conference here, but I think it was probably 5, maybe 6 consecutive quarters where we were talking about search AI budgets are accelerating. And we're now at least a quarter or two since we've gotten that last data point we're seeing the growth rate. So can you just help explain that dynamic?
And then the second, more of a tech question here. But with the Elastic inference service, I understand that you guys have the models now being served up on the GPUs, was it on the customer to actually -- it was on them to get the chips and then put the model on the chips? Like what did the customer have to do for that inferencing angle that the EIS offering is now unlocking that you guys are announcing today?
[indiscernible] first and then I'll do.
Why don't I ask Ken to address the second one.
Yes, I'll answer the second question, which is previously, if a customer wanted to use our embedding models or Reranker, they would run them on an ML node within our stack, which would be on a CPU-based architecture. If they wanted to use GPUs, they could, but they would have to direct it towards some other service that they -- either they would run or somewhere else.
With the inference service, we are providing a fully managed API-accessible inferencing capability that's running on GPUs. It's initially supporting ELSER and embedding models. We're going to expand that to cover rerankers and the [ GenAI ] models as well. So we'll be expanding the models that we host on the inference service, and it will all be on GPUs.
I'll take that first question you asked. So first of all, I think you've got to think about the core platform growth. There's more and more data coming into the platform. And you've seen the data behind the net retention rates that are 113% and stable. There is data behind each of the cohorts over a long period of time that support continuing that teens growth rate without much tailwinds, right? So that's the first point I'd make that outside of search acceleration, outside of all the unlocks that you're seeing on search. Just the core platform increase is going to be sustained at 15% plus, just based on the net retention rates and the cohort data that we see.
In addition to that, just when you think about all the great platform announcements or the search and observability announcements that we made today, that's driving differentiation to allow us to take more market share on that TAM that's still expanding. So observability and security businesses are still very large TAMs and there's still a long way to go there. And I think that our product differentiator now -- differentiation now just grew.
So that's what gives us confidence on that 15% plus. It's just driven by that core platform and the amount of data that's coming into the platform and supported by all the cohort data and the expansion data that you just saw, along with all the product announcements that we talked about in security and observability outside of search.
Sanjit?
My congrats on all the great data and from the presentation as well. Ash, I got a really clear view today of where the company is going, how they're going to win, why they're going to win. One of the most popular questions I get from investors is why did growth gets so low to begin with. And Navam, in your presentation, I think, speaks to part of that, which is maybe around some of the optimization activity. There are some go-to-market changes you guys are making, is there anything else that could explain the deceleration in growth that we've seen over the last couple of years? Was there headwinds in your security business or your observability business that you're now working through? Because I think if we put those pieces together, it makes much easier to underwrite the kind of where we're going on a 15% plus basis in GenAI. So any sort of comments there and then I had a product...
Yes, let me address that and then ask Navam to also jump on to it. Fundamentally, I think there was a chart. I can't remember the exact slide number, but there was a chart that, now I'm sure, that broke down the three components within our revenue. So there's sales-led subscription revenue, there is the monthly cloud business and then there is services, right? And if you look carefully at those three components, like they really tell the story, because monthly cloud, which is our SMB business, was a significant significantly larger component and faster growing component of the business if you went back 4, 5 years. And that clearly in the last 3 years has been roughly flat. And that's not something that just we are seeing, but across the board, like we see SMB spending hasn't really come back the way enterprise and other spending has come back.
Services, professional services, we have been very clear about that this is not something that we believe is something that we want to grow at the same rate of the business. Like that's not -- it's not the most strategic part of what we are trying to do. We are a platform company. We're a product platform company, and the subscription revenue growth that we are trying to drive through the sales-led motion, that's what we care most about. So services is just an enabler.
So what we really have been laser-focused on in the last three years is making sure that we get that growing and thriving and continuing to accelerate. That's what the effort has been in. And that's the reason why we had the -- so apart from it, by solution mix or any other cut, we don't see any issues in terms of competing, winning in the market, continuing to take share. We feel incredibly confident about observability. We feel incredibly confident about security. Matter of fact, we've been beneficiaries when it comes to taking share from incumbents. It is this dynamic of monthly and the rest of the business. And if you take out the monthly, then that's what we are really focused on.
Internally, that's the thing that I care about. And over time, that's going to be a bigger and bigger percentage of our revenue and the rest is frankly, not going to be what should matter to investors.
No, I mean nothing more to add. I think the intent of providing those two charts is to give you the data behind it. Ash summarized it clearly, which is the changes in the SMB dynamic, which is partially -- not partially, the main reason for the deceleration that you're seeing in those years. But the second chart, which is showing the durability of our sales and subscription revenue growth rate for multiple years. I mean, talked about multiple quarters in the last earnings call, but you look back, it's been many, many years of strong growth. And what we're saying now is that we maintain that durability 15% plus on the baseline just -- with bread and butter stuff that we're doing now without much GenAI and then the GenAI tailwinds which we're seeing now get us to beyond that, and there's even the potential to breach 20%. The GenAI tailwinds of 5% are just the map we see on the cohorts that we compare, but there's some data that has a higher tailwind than 5%.
Understood. On the security business kind of following the Ittai's question, investors underwriting like market share gains, displacements. I mean, you guys are a product company, security becoming more data-driven, compliant to all that, but are you -- and this probably might be a Mark question. Do you feel like you have the relationships with the security ecosystem to drive what are pretty formidable competitors in the SIEM space in particular. So just get a little -- get your perspective on that.
Yes, I'll comment and maybe Santosh, if you want to add. But what we see in the market is that many customers are ready to and want to replace their legacy security platforms. And they're evaluating Elastic, and they put us through our paces. And we love that because when customers evaluate us in detail and they see the innovation that we're driving, they see attack discovery, auto import we're winning a high percentage of time and we're winning large deals. That's why we have a program around race to displace. But we're finding a lot of success there, and we're excited about that opportunity.
And could you just say your name and firm when you're on the microphone?
Sure. Rob Owens from Piper. Ash, you do have a history in the security universe if we go back almost a decade now at this point.
I'm old.
And as you know, it's never been an efficacy game relative to endpoint. And while you're showing well in the scores, a lot of the independent scoring. Is EDR critical to your success as we think about that convergence of what was XDR, but next-generation SIEM in your view?
In my view, it's going to be another vector for growth, Rob. I think that the great thing about endpoint telemetry is. It's voluminous, and you can't get away from it. You have to have something on your endpoints to make sure that you have that threat vector covered.
And exactly for that reason, the most important thing that we solved a few years ago and we got -- solved it right, was to make sure that we made it easy for people to get our endpoints deployed, our agents deployed on their end points. The way we did that is by basically incorporating all of that functionality directly into the same agent that does the SIEM collection, that does the collection of data for SIEM. So you're already deploying that agent. And once you have it, then we go to them and say, "Hey, it's the easy button, just turn it on." Now you're absolutely right that efficacy isn't the only thing that matters, that there is more that's required, like there is people need to put you through their paces.
People need to see that you can have the one single dashboard that they can use for doing all their detections and remediation and so on. Having that data-centric approach and being the SIEM gives us the opportunity to start to talk to the SOC and basically say, you're already trusting us for doing all your detections across all threat vectors not just endpoint but across everything because that's what happens in the SIEM. Everything ends up in a SIEM eventually.
If you are trusting us for that, why don't you try out the endpoint functionality. So it's been this expand play and all through this time, we have been making our endpoint product better and better. adding not just efficacy capabilities but also management capabilities. How do we easily deploy, how do we do rolling upgrades, all of those things that for other vendors have even caused blue screens of death, as you know. Those things are important to get right, and we've been working hard on them.
So over time, I expect this to be a bigger and bigger and more and more interesting area for us for expansion. We're just getting started on it.
Great. Thank you, Howard Ma with Guggenheim Securities, and thanks for a very informative presentation and as well as the balanced profit and growth framework, which is what I want to ask about. So if you look at the top line, going from about 15% today to -- assuming you achieve the aspirational target of 20-plus percent, that's quite positive. But if you look at the free cash flow margin. I know you didn't -- you guys didn't give a discrete guide for this year, but I think it's -- you might have said Navam, on the earnings call, it's like high teens. So going from high teens to 20% is not that much expansion. So I wonder, is that because of conservatism or are you building in investments, specifically on the monthly [ Pago ] side because you have to drive the product-led motion still. And educating your customers that Elastic is the best unified data platform for unstructured data and driving consolidation versus a solid approach today. I would say really, those are the kind of the barriers today. So how much -- the question is how much investments are needed to overcome those potential challenges.
Before Navam answers the question on the free cash flow model and so on. I just want to clarify the inherent leverage in the model. And I want to make sure that people understand that one of the advantages of having a single platform on which we have search, observability, security, all of these solutions built is that our cost of engineering and our cost of building this platform is incredibly efficient. Like we don't have to build three different management consoles. We don't have to build three different ways to manage users and user profiles and so on. There is tremendous leverage that we get by having one single platform. And that applies also to our monthly cloud business. So it is important to understand that our monthly cloud business isn't a expense drag on the business, right? So it is something that tempers the top line because it's been flat. But it doesn't affect our cost profile in any negative way. But let me -- with that, let me just...
Yes. Let me kind of start first on the OpEx side, just to build on what Ash said. I think we broke out the components of what we expect R&D, sales and marketing to G&A to do in the midterm model on the operating expense side, and we expect strong investments into the R&D side, keep that stable. And then the sales and marketing line, I think we've shown the amount of leverage we can drive. Now 2026, we are investing in capacity. I think we're doing a really good job on the productivity improvements. We're seeing all the good things that are happening in the field. We want to double down on that and build some capacity there. So '26 is a build year.
But after the build year in '26, you're going to see the progressive improvements in sales and marketing as a percentage of revenue, similar to the G&A side as a percentage of revenue. So we should think of this as a build year and then after that, we're going to go back in the margin trajectory. And remember what I talked about capital allocation. We still want to invest to win the market and make sure that we're positioning ourselves for winning. But at the same time, we're going to be very disciplined, right?
On the free cash flow side, the model is to get to 40% plus under the target scenario of 15-plus -- upwards of 15 and upwards of 5. In any scenario, we were going to get to rule of 40 plus. But obviously, the growth components of the 20% plus are those two tailwind plus baseline growth rates. This year, our FCF margin is expected to be roughly the same as last year.
Yes, Tyler Radke from Citi. Thanks for doing this. I thought sort of the framing of Elastic is kind of the leading unstructured data platform definitely resonated across all the different presentations.
I guess my question is, as we think about the ways in which AI are changing the way that you can kind of productize that, I'd love to get your thoughts. I mean this agent builder that you demoed seemed pretty compelling. You are seeing a lot of newer vendors almost offer out-of-the-box solutions, whether it's on the search side, the gleams of the world, you're seeing vibe coding products probably leverage a lot of the core elastic functionality. But how do you sort of think about all the trends in the developer space around automation, AI, driving more usage of Elastic over time? What are you doing from a product perspective?
And then second question for Navam. You raised guide like 6 weeks after you reported, like what have you seen over the last 6 weeks? I mean, was this just strength on consumption? Was it bookings on the federal side? Any elaboration on that? What's driving that confidence?
Maybe let me just touch upon the first one in terms of monetization. So at the end of the day, our fundamental model for monetization is consumption, as you know, Tyler. And so everything that we do is designed to both give value to our customers with what they are trying to achieve and at the same time, drive consumption on the platform. And that is effectively how we are going to grow. So all the announcements that you heard of today, whether it's the Elastic influence service, the new models from Jina that will become part of that influence service will also be offered.
All of those are compute intensive. Our use as a vector database when somebody is building the retrieval system for context engineering to build any kind of agent that is a significant contributor to consumption.
Agent builder. I mean the whole -- the way you should think about agent builder is it's going to fast track the process by which somebody actually builds these kinds of end applications, right? That's the key. So yes, we don't have a business UI, but that's because, at the end of the day, the people who work best and fastest with Elastic are developers. And unlike some of these other companies that you mentioned, we have a huge mind share with the developer community, tapping into that developer community, which ends up being a massive community and is building applications that are used by enterprises by every user within the enterprise, we feel it's a much more efficient way and a much faster way to really get penetration.
But agent builder, what it lets us do is it fast tracks the approach for an end user to actually build these kinds of applications. And that is key. I don't know if you want to add anything to that?
Just to expand on one thing you said. Our approach has always been to allow people to drop down to the platform and drop down to code and have the flexibility to do whatever they want. And with a lot of the other solutions out there, if you can't do what you want, you're stuck. Like if you want to go customize this, you can't. If it doesn't support in the product, you can't do it. We never keep our developers from being stuck. Like they can always drop down. They can always customize. We try to make it very easy to get started by providing an abstraction. You saw an agent builder like we created an agent automatically by default, we create some tools automatically by default, you can go in, you can customize, you can extend. That's been in our ethos, like something we do.
We also approach this from a data point of view. Unlike anyone else -- like we start with the data, and we're trying to give you access to building tools and building agents on top of your data. So we look at this as, you want to chat with your data. You want to build an agent on top of your data. You have private data, how do you expose that to an agent? And how do you expose that to an LLM? That's the point of view we always take.
Others tend to start with the hosting platform or something else. We start with the data and try to figure out how to help a customer expose that data and build generative AI applications on top of that data.
Yes. On the guidance side, commitments are strong, and that's what gave us confidence to raise the year. So that's the first thing. And we're further along in the quarter. So we want to give you an update on the quarter as well.
And when you think about the government shutdown side, I think there'll be obviously no business conducted in October since there's no one there for the federal government. But overall, the government is going to open up at some point and our products are positioned very well. Once that happens, in fact, it was. We had several good contracts before the government shut down as well. So we're not worried about the U.S. public sector business over the medium term. It's just that October is obviously going to be impacted by the government shutdown, but overall commitments are going very strong. So that's the reason to do the update.
And we're going to do one last question. It's going to be Raimo.
Thanks for squeezing me in. No pressure on the question, quality, I guess. Thank you and thanks from me as well, a great event. Maybe one for Mark as well to get him back on the -- if you look at -- as a sales leader, if you look at the number of customers that only have one product compared to where it should be, that's kind of huge upside, and the question is like why is that number so low? And I don't - I'm sure you guys looked at it. Is that -- is it kind of the wrong customer? Or is there a lot more you can do there? Because that feels like way too low as a kind of ratio.
Yes. It's a great question. We believe there's a lot of upside there. And we looked at how we were covering our customers in the past. First of all, we weren't aligning our sales capacity to the largest opportunities. We had territories that had way too many accounts, a combination of existing accounts and white space accounts. And the sellers, didn't have the time to focus, get deeper with customers and focus on going to the next solution within the customer. That's why we made a lot of the changes that we made, and we're seeing progress on that already. But we see that as tremendous upside going forward.
That was the last question. All I would say is, hopefully, some of you or if not most of you had the opportunity to come earlier during the day and see the complete presentations. But this event, our ElasticON event is always something that we care a lot about because this is one of the greatest and best opportunities for our customers to learn from us, but also from each other.
You had the opportunity to participate in the Financial Analyst Day. And hopefully, you were able to get some energy and some ability to talk to customers who are here, get more insights into how they are adopting our platform, hear about some of their success stories with us, hear about why they are excited about what we are doing. We are really, really excited about what the future holds for us.
Just in terms of the business overall, the commitments that we are seeing from customers, the demand that we are seeing in the market, the opportunity to take more share as we consolidate onto our platform, the customer -- the needs that customers have around observability, security and so on. And then most importantly, how we can differentiate with AI, how we can capture this wave.
I am very confident that AI is going to be the dominant technology for at least the next several decades. And if that's the case, then you have to imagine that more and more applications are going to be built on this LLM based paradigm. We want to be the context engineering platform that every single one of those applications uses. That's our mission. That's our vision, and that's why we are so excited about the future.
Thank you again. I believe there are -- there's a cocktail hour for the entire event. You are all very welcome to join, and thank you very much.
Elastic NV — Analyst/Investor Day - Elastic N.V.
Elastic NV — Piper Sandler 4th Annual Growth Frontiers Conference
1. Question Answer
All right. Well, good morning, everyone. I'm Rob Owens, the Co-Head of Tech Research and focus on our infrastructure and security software practice here. So thank you for joining us this morning. Really happy to have the folks from Elastic with us, Eric Prengel and Ken Exner to talk a little bit about the story, kind of where we're at and where we're going, I think.
So gentlemen, thank you. Thanks for coming back to Nashville. Ken and I had a near death experience getting home last year, which we were just recounting as our plane nearly struck another plane on the runway, and we spent 9 hours in an airport together. So hopefully, this year...
We're taking off and we're starting to ascend and then suddenly, the plane hit the brakes. I thought they just ran out of runway. But apparently, we almost hit another plane until we were on the news and there was a lot of fun, but I came back.
Yes. Walked half mile on the tarmac to get back. So thanks for coming back, and we're watching that next year. So excellent.
Let's go back and chat a little bit about Q1. And I think in the Mongo meeting just before you Brent pointed out a lot of the inflection that's happening within the space. And I think it happened within your guys' numbers if we look at revenue or subscription revenue. But parsing that there was a price increase, which, by the way, does happen with software companies in there. I would love to just kind of understand the different components of success that you guys saw, how you're setting up for the rest of the year? And maybe, Eric, a little discussion on pricing as well.
Yes. Do you want me to start with just the Q1 and maybe we can...
Sure.
So I'd say on Q1, we are very happy with our results. We saw both strong commitments and strong consumption. And that's really the way that we measure our business is both commitments and consumption. We -- the total top line of the business grew 20%, which was great. We've pointed to this metric, sales-led revenue, and that's the subscription revenue, excluding monthly cloud. And that portion of the business grew 22%, which was a really nice growth rate for that. We also saw a really strong operating margin.
We came in just below 16%. So that was great. And that was really driven by a number of factors. The product has seen a tremendous amount of success. GenAI is obviously a big driver of the product. And I think that having relevance is even more important. That's what we provide as you think about Agentic, where it's not just giving you an answer, but it's actually potentially taking action.
And so the capabilities that we bring with RAG and relevancy become even more important there. In security, we saw a lot of consolidation, and that was tremendous for us as you see different components of the security stack, be it SIEM, XDR, cloud security starting to converge, and that's really been a benefit for us.
And then in observability, we saw strong momentum as well, fueled by some of the AI stuff that we're doing in security with the AI assistant and other capabilities. So across the board, the product was strong. The go-to-market performed really well. We obviously had some change a year ago, and we've seen that come back to a large degree where it's executing nicely. And so across the board, we saw strength in Q1, and we're really happy with how that performed.
Now it was a little bit of an easier comp given Q1 of last year and some of the different sales changes. But I think that we're seeing a lot of things accelerate here in the space from an infrastructure standpoint. Do you feel we're nearing that tipping point? And I'd love Ken to weigh in, in terms of where we're at and why?
With GenAI or...
Yes.
More broadly. So the whole GenAI thing happened a couple of years ago. And I think there's been a huge amount of excitement about generative AI and everyone is waiting for those huge inflection points. And it will happen. There will be significant growth. I think if you look at the last few big changes in our industry like cloud computing and if you look at the birth of the Internet, even the most conservative -- even -- sorry, even the most aggressive estimates tended to be conservative.
So I remember when the Internet came out, people were saying, "Oh, this is going to have like $200 billion worth of impact on the industry." And everyone was like, "Oh, no, that's crazy. That's crazy." I think the most aggressive one I saw was $1 trillion. And everyone said, that's outlandish. But I think 30 years on, we realized that it's actually had a bigger impact. It takes time to get there, but it eventually gets to step functions. I was at AWS at the beginning of cloud computing. I was actually at AWS when we launched DC2. And the first 3 or 4 years, it was kind of like the best kept secret. And we're like, why has no one paid attention to this? This is like start-ups are using us.
And it was probably like around the fourth year that people took notice and enterprises said, we need to figure out our cloud computing strategy. And it was still another 3 or 4 years before cloud computing actually had an impact on Amazon's business overall. Today, like we know that cloud computing is has sort of changed the space in very fundamental ways, but it took time to get there.
And then it grows in step functions. I think with generative AI, people realize that it's going to have a huge transformative impact on all industries. And the early couple of years has been about experimentation, has been about trying to figure out what is this going to be used for? How are people going to take advantage of this? I think a lot of the early experimentation has been around assistants and chat-based experiences and copilots. It's is interesting. It's good. But I think as people move towards automation, and I think this is where Agentic AI is really going to play a huge impact on all industries because it's no longer just about an assistant. It's no longer about clipping. It's no longer -- it's about how do you automate things and sort of fundamentally change how people are doing things and drive huge productivity.
I'm excited because I think Agentic AI is sort of sparking people's imagination about how AI can be used to fundamentally change how we work. So I think as we move into the next couple of years, you're going to see sort of huge amounts of automation driven by Agentic AI and that Agentic AI is going to be driven by context engineering and context engineering is at the heart of what we do.
So what are the parallels? And what are the proof points we should be -- you live this ground level at AWS. What are those proof points we should be looking for? Because from an investment perspective, we see cycle times compressing, right? We look at adoption of ChatGPT versus go back to previous cycles, just people using the Internet. It's crazy the momentum these things have upfront, but then there's always that expectation that carries with it, and there's kind of that period of disappointment.
So to that end, if you're drawing parallels with what you went through that first time and what we're seeing now, what do you think those proof points are going to be then?
I think it's going to be seeing people move from the first experimentation within the business to like broader uses across. Like one of the things we've seen is a lot of the businesses that we work with prototype and experiment in one area. And then as they develop success, it starts to move across the business. That's one. The other is the use cases start to change beyond the first couple of experimental ones. So I mentioned sort of these chat-based experiences have been sort of the canonical example of using AI.
Moving beyond that to other types of use cases is what we're -- I think it will be the sort of the signal to me. I think this year, Vibe coding and using AI to drive software development has kind of been the breakout use case. Over the last 12 to 18 months, it was chat. Going forward, I'm going to be curious to see how people expand into other use cases of automation. So seeing the number of use cases expand, I think, is going to be interesting.
And what is Elastic's role in all this? Near term, long term?
So at the heart of what we do, we're a search engine. And why that matters in this is when you're trying to build a generative AI application, you need to pass context to that generative -- you need to pass context to an LLM. It's essentially a search function. Everyone's been hearing about vector databases over the last couple of years. We've been a vector database since 2017.
We've been doing this for a long time. But it's not just being a vector database. It's about supporting the entire workflow that a developer has in building these applications from figuring out how are they going to ingest the data to how are they going to figure out how to chunk up that data, how to run inference on that data or encode it to create vectors. Then, of course, it's vector search or combining it with different techniques. We have a range of different models to assist in this process, like query understanding models and reranking models to further get better relevance out of data.
You can combine geospatial search together with vector search and then ultimately passing that context to an agent or an LLM. And you can do that a couple of different ways. You can do that through prompt engineering into a context window. You can do that through MCP interfaces. You can expose things as MCP resources or tools. All of that, the entire tool chain is what we do. So unlike a lot of vector databases that just do the -- they're going to store and query vectors, we support the entire workflow.
There's one thing I want to add that. I think is important that Ken kind of touched on a little bit. But as you think about this GenAI revolution, let's call it a revolution for now. In 2023, a lot of companies started thinking about GenAI when -- with the advent of ChatGPT and people, it was sort of this aha moment. A lot of companies said, "Oh, we need to do the things to get into GenAI." And they started chasing GenAI.
Elastic was working on vector databases in 2017. Elastic had a lot of vector capabilities. When I first joined Elastic, it was before the ChatGPT thing. I remember hearing so much about vector databases, and I'd never heard about what they were before and hearing -- there was a lot that Elastic was already doing. What I would say is rather than Elastic chasing this market, call it luck or whatever you want to or call it preparedness, which I hope it is, Elastic was working towards this market and building out capabilities that -- where this market is really coming to us versus us chasing the market. And I think that's something that's important to note about Elastic relative to a lot of other companies that are in and around this space.
Excellent. And it seems to be translating into other areas. So maybe you can touch on the security opportunity, which seemingly is improving around your SIEM offering, even observability as well. And and why customers are looking to consolidate these areas? Because typically, it's -- can be one buying center, but I think historically, it's been multiple buying centers in an organization, different users and just different use cases. So why do you think you're seeing the consolidation and the success that you're seeing there?
So first, let me explain. So in addition to our core search business, we are in the security business. And we got into the security business because threat hunters were using us to search through all their logs and all their different unstructured data to look for sort of that needle in a haystack. So we started being the choice of all these threat hunters for searching for information and all this data that they have in their businesses.
On the observability side, same thing. People were using us as a log analytics solution to search through the mass volumes of logs that they have. Over the last few years, that's been the sort of the core of our observability and security business, being a SIEM or security analytics platform and being a log analytics platform. But we've been expanding that to a number of different areas. So on the security side, we've been quietly building up a bunch of EDR capabilities and cloud security capabilities so that we can not just land in SIEM, but expand into EDR and expand into cloud security.
Our EDR capabilities are actually some of the highest -- actually the highest rated. If you look at AV comparatives, they rank us the highest rated malware detection solution on the market. Same thing on the observability side, where we've been expanding the metrics and APM. And our motion is we land with logs. We develop a strong relationship with the business there, and we expand into these adjacent areas.
So that's going very well for us. AI is playing a huge role in this as well because what we're able to do is we're able to use AI to improve the experiences for threat hunters and improve the experience for SREs and DevOps practitioners by automating away a lot of the things that they do. If you think about what a typical security analyst does, they're doing lots of pattern matching. They're doing lots of manual work. They're sifting through hundreds of alerts a day trying to figure out what's going on in their business. Is this an alert that is real? Is it a false positive? How is it related to some other alert? All of that work that they're processing can be automated away through generative AI.
So we've been using AI, our own capabilities to sort of transform these experiences to make it much faster for these practitioners to accomplish their tasks. And I've been surprised at how we were leaders in sort of deploying AI in these 2 spaces. But I've been surprised that no one's been catching up. Like when we launched Attack Discovery in Security, it was one best in show at RSA, and it was a very popular set of capabilities. It was basically taking all the different alerts that a practitioner gets, and it was automatically mapping an attack chain sort of saying, these are how all these alerts are related. No one has still figured out how to do that.
And I think a lot of the things that we've been able to do is because we are an AI platform. We understand how to use the context of all their data to build these types of experiences. So I think you're seeing some momentum from people starting to pick us because we figured out how to use AI to really change these experiences.
And Ash loves to say security is a data problem. Can you expand on that?
If you look at what a security analyst is doing, they're sifting through data. Like they have massive amounts of data that they have to pour through to figure out, is there a security incident. They have to find the needle in the haystack. And there's a couple of problems. One is if you're missing data or if you're not collecting all the data, you're going to be missing potential exploits.
So the first thing we always say is don't throw data away. like make sure you're keeping all the data that you -- if you have all this log data, like use the log data. AI can help you process it faster. The second part is, historically, we've always used manual means for how to sift through that data. So the process of threat hunting was getting better and better tools so that you could do the analytics. AI is proving that you don't have to do that manually. You shouldn't have to do all that correlation analysis, all that threat hunting manually. Robots are better at this. Machines are better at this.
So I think that's the thing for us is that if we can deploy AI to do that threat hunting to find that needle in the haystack and tell you how that needle in the haystack is related to this other needle and haystack and then to help you remediate it. That's, I think, where we can not only help people move faster, but remediate issues.
And maybe shifting gears a little bit, touch on the serverless opportunity. Maybe help explain it to audience to start where you guys are at in that journey?
This is something we've been talking about recently because we recently launched a serverless cloud offering and went GA on all 3 major cloud providers. I guess Oracle is becoming a major cloud provider.
Apparently it is.
I have to adjust my talking point there. But for Google, AWS and Azure this summer, the serverless offering is essentially a fully managed version of Elastic on cloud. So if you can think of -- there's 3 different ways we support customers deploying Elastic.
One is self-managed. So you can run it yourself, either on-prem or on cloud, wherever you want to. You manage it yourself, you're just paying for a license. The second is a hosted offering. So this is where we will host it for you on one of the cloud providers. We will provision instances. We will install the software. We'll keep it patched, but it's a shared responsibility model.
So customers are responsible for scaling, they're responsible for cluster health. They're responsible for charting, all these other things. our serverless offering is fully managed. You can think of it as SaaS. It is a SaaS offering. So it is versionless. There's no -- you don't have to think about the underlying resources. It's completely abstracted away from you. So from a user experience point of view, it's like comparing a PaaS to a SaaS, I guess, you can say, which is a fully managed experience. The other aspect to it is it's built on a cloud-native architecture, which allows us to take advantage of a lot of the efficiencies of cloud, including object storage. It's a completely stateless architecture.
So we've built essentially a data lake style architecture that underpins this. And this is important because it allows us to run more efficiently. So it's going to provide better margins to our business, and it allows us to control costs and lower cost for our customers as well, especially for smaller workloads where it's -- you're paying for what you use. So it's going to be cheaper for customers. And then finally, I'll mention is we are also packaging it a little bit differently. So we're able to package a security offering for security professionals and package an observability offering for observability professionals and price it that way. So if you are wanting a security solution, we have a serverless security project that is priced in a way that you would make sense to you. It's priced by gigabyte. You pay for gigabytes ingested and gigabytes stored, and that's it. You don't have to think about how much memory or how many CPUs you need to use for your workload. You don't have to think about the hardware.
Excellent. Eric, if I think about the last couple of years relative to Elastic, this is a story that has flirted with inflection many times. And I know investors get excited, and it's been a pretty volatile business. If we look at your recent success, especially this first quarter, are you finding more predictability within the model at this point? Are you seeing more visibility relative to those opportunities, especially with the changes in go-to-market that happened a year ago?
Yes, it's a great question. And just with scale inherently, you're going to have a little bit more predictability, a little bit easier to see what's coming. But there's also going to be things that in a consumption model can be just challenging. And you talked about at the beginning of the price increase, and we never got to that. But in Q1, we -- well, in Q1, at the start of Q1, we increased prices. And we've done that in the prior year and price increases are something that software companies all use as a lever to help drive value.
And so this year, we increased prices on the self-managed business as well as the cloud business. And the cloud business price increase, we saw immediately impact the business. And so we saw a lot of positivity in that because as you think about a consumption business, it's not so straightforward as just a P times Q analysis. There are different moving pieces there. There are constant optimizations that take place and an increase in prices will certainly have people rethinking optimizations. Also, a part of the reason we increased the price is because there's a lot of value that we've added into the platform.
So as you think about Logsdb, that's something that significantly reduces the amount of storage that our customers are able to use and lowers their total cost of ownership. It's similar to the searchable snapshot capabilities that we released a couple of years ago, which also reduced some of the costs. So at the same time that we were increasing prices to customers, we're also lowering their cost with functionality that we've added. There were additional optimizations that happened.
And all said and done, we saw an increase in our consumption from our customers, which means that their spend with us increased, which we saw as tremendously positive in a very positive sense. But just to talk a little bit -- to bring that back to predictability, with things like that, the consumption is going to inherently, I think, be a little harder to predict than some of these seat-based models that are more of a traditional SaaS, you pay for your seat.
And so as we've gotten bigger, as we've had more experience with the consumption model, I think we have gotten better at predicting it. We've started to build different models in our ecosystem. We're monitoring different things to track it. But I think that it will always be a little bit more complicated to predict a consumption model than it is some of these other models.
Great. We've got time for 1 or 2 questions if there are.
Go ahead, Ethan.
Yes, just on serverless, can you talk kind of about the process the customer would kind of migrate existing cloud workload or use case on to serverless, like how hard do you view that quickly [indiscernible].
Yes. It's -- it would be similar to if you're moving from self-managed to cloud. So typical process is you create a snapshot of your data and then you restore from snapshot. That said, we want to make this easier. So there's no reason we can't do this very transparently. So one of the things that we're working on over the next, say, 6 months or so is making that significantly easier for customers so that it's push button. It will happen in phases. We'll come out with some tools, and we'll continue to refine it. But I want to be able to, let's say, over the next year, allow a customer to just push a button and it's just seamlessly migrated for them.
I'd love to ask about eating your own dog food or finding...
[indiscernible] or champaign.
Where are you finding efficiencies leveraging AI and some of the different tools and some of the different capabilities Elastic has?
Well, I mean, the first thing is that we started using it to change the game for observability and -- so that was the first thing. And I mentioned this before, I was kind of amazed at how long it's taken others and they still haven't sort of caught up in some of these spaces to use AI. But internally, we use it, too. Like internally, we have a sales ops team that uses this to build sales automation. We have an IT team that uses this internally.
Our support team is building all kinds of support assistance using AI. So like the support space is ripe for a lot of generative AI. If you want to really augment a support person, you can do a lot of what they do through AI. So what we're realizing is that you can use AI to automate a lot of the work that they go through, like trying to figure out, has this customer called before for this issue? What's the sentiment of what they're -- are they pissed off? Knowing they're pissed off even before they get on the phone based on the previous sets of conversations. There's all the stuff you can do to bring a ton of information to the support engineer.
So we're using all that to really create a great experience for people when they call support because we can look at all the past information and understand a lot about the context for this person.
Has it resulted in tangible cost savings or lower headcount in any of these functional areas that you're starting to use it?
Yes. It's a great question. I think that we're still looking at that. There are ways where we can be more efficient. And so I don't know if we necessarily have taken heads out of the business. but we might have added less heads into the business as we think about being able to be more efficient with some of the ways that we're using GenAI to really drive productivity and efficiency. And like Ken said, it's really sales support. Even on the engineering side, we're starting to see some of these capabilities that we're able to leverage benefit us a ton.
Great. Well, I think we'll end it there. Thank you, guys.
Thank you.
Thank you.
Elastic NV — Goldman Sachs Communacopia + Technology Conference 2025
1. Question Answer
How is everybody doing. It's just Day 1 of the conference, right? I mean it's a 4-day conference, and you're going to hear a lot about tech software. By the way, software is not dead. We're going to talk about that. Ash has been at the helm as CEO of Elastic for a few years now. I had the pleasure of meeting him some 3 years ago. And we have in addition to the executive team, Navam, who many of you will know from HashiCorp, very experienced executive.
So Ash, great to have you back. I think it's the 4th Communacopia and Technology Conference, we're doing together. Really excited to have you here.
And I know you've been through a few conferences and people [indiscernible]. For those that are not familiar with the Elastic, can you please tell us your story. I'm not going to ask you that question.
What I'm going to ask you is the same question I've been asking in '22, '23, '24, what is the vision for the company? What does success look like in 4 to 5 years?
Okay. So the most important thing for me as I think about Elastic is what we are great at is search. Like that's our core bread and butter. When it comes to unstructured information, unstructured data, any sort, the messier, the data, the better we are at handling it and helping you find just the right relevant information within that data. And we have grown both as unstructured data itself has grown, but also as the use cases for unstructured data have grown.
And the most exciting one of all of them, obviously, is AI. And the role that we play is search for AI, specifically as people do context engineering or providing relevant context, accurate context to a large language model, so it can actually do its job, whether it's doing it for some sort of agenic workflow or some conversational app that you might be building. And LLM itself does not know anything about your private proprietary information and that's where Elastic comes in.
So we are one of the most widely used vector databases, but we do so much more than that, and it's all about providing that right context. So the vision for me is that Elastic becomes the platform, the data platform for data retrieval and context engineering as people build AI apps and that we are baked in into this new AI stack that's emerging across enterprises, mid-market, government agencies worldwide.
Got it. I was going to title the session, Kash asks Ash. So that should be at the front end of whoever is going so Kash asks Ash or Kash versus Ash or whatever you want to call it. Naman, We will find a word of way to weave in. It's coming, trust me. That's great.
So as we dig into AI, there's bits and pieces of the stack that you talked about vector databases, vector search, vector embeddings, search, concept of core Elastic search. Can you -- I mean I know you're an engineer. Can you put it all together, what is that ultimate AI application stack look like? And why do we need these different elements that do these things embedding search database. And where do you play in each of these layers of the stack, the way you are articulate.
Sure. So take any large language model. So first of all, we are agnostic to what large language model you use, we integrate with just about every single one of them. But if you are building any kind of agent, the 2 things that you need, the first thing that you need is LLM because that's the one that knows how to do reasoning on information it knows how to do inference. So it's able to predict the next token, so it's able to create an actual set of sentences that are reasoned and thought through and come up with a full detailed answer or it can take actions, what have you.
The other thing that it needs is some context of your information because otherwise, all large language models are only capable of answering based on what they have been trained on and what they're trained on is publicly available information. So when you're dealing with an LLM in the context of your business, it has no understanding about your inventory, your parts, your products, your customer tickets, like what have you, your policies, your internal knowledge basis.
It has no context if any of that. The only way to provide it with that information in real time because, by the way, all of your data is also constantly changing. So you need to connect the data to the language model. And that connection needs to be done in real time. It needs to be done with the minimum number of documents to pass to that language model because the more information you pass it, the higher the chance that the language model is going to hallucinate, so you want to keep that set down.
Thought that it should lead to less hallucination, the more information it has, right?
Not really because the more information you provided in a narrow context it can often go, okay, I have various choices without recognizing that you know internally because of various relationships that you might know about the customer, the segments are there and et cetera, that -- although these 5 documents are all related to the general topic, only these 3 documents are related to that customer.
So if you don't provide that bit of information, the language model might assume that all the documents you're giving it are equally valuable. And so this is the point of training and RAG. Like the RAG, retrieval augmented generation, the RAG of 3 years ago is no longer the same RAG that we see today. Retrieval augmented generation is becoming very, very sophisticated now. People take into account things like known relationships. So people will often model it in the form of a graph.
People take into account what you know about preferences and biases. People take into account what you might have to do in terms of filtering the set based on other parameters like preferences like geolocation, like other choices that customers might have given upwards to. So there is this whole process of learning to rank or reranking that has become very, very powerful and well understood. And this is what I mean by context engineering. Context engineering is more than just a vector database. It is about first organizing and chunking the data that you are working on correctly.
Then it's about using the right kind of embedding models to turn it into vectors. Then it's the vector search process itself with all the additional facets in like search facets that you can apply on top of it then there is hybrid search, which might be, okay, I've got an answer using vector search, but I also want to look at what text search gives me, especially if the data is textured. And then reramping all of that based on this [ learn to rank ] technique that I talked about.
Eventually, what comes out after all of that is ideally the most accurate bits of information that you pass to their language model and then the language model is very much going to get the right answer, right? So that process is involved. And if you give the wrong answer really, really fast, it's not very helpful. So accuracy of the context is what customers care about most. And that's really the evolution that we have seen in the market where customers are getting more and more sophisticated about this and all of this plays to our strengths. This evolving stack also has additional things to it.
Like you're going to see -- you're already seeing people talk about LLM absorbability. You're already seeing people talk about FinOps when it comes to understanding the number of tokens that are sent back and forth to these large language models because that also runs up cost. You're seeing people talk about LLM security. So the whole AI stack is going to continue to evolve. But our role is in that -- in the center of that retrieval and context engineering bucket. Like that's where we intend to have our greatest focus and then eventually, we'll expand from there. But if we capture that core ground, I think the opportunity for Elastic is massive.
On that note, I know in your most recent quarter, we'll bring Naman into the discussion shortly. You talked about a few use cases. What is the best use case, the most impactful use case where this whole stack embedding, vector search, vector databases and the context engineering is having the maximum effect...
There are so many examples that I think are super fascinating. We've got an agency -- a government agency that is using us for solving human trafficking use cases. Where they marry phone call information, so audio information with CCTV information that they look across using these kinds of vector search techniques to quickly figure out where a person of interest could have gone. It's like amazing kinds of use cases that are like helping address real human problems. All the way to AI user companies that [ user the ] covers for -- as a vector database and...
Detecting illegal use of proprietary music....
Well, I'm not going to go into the proprietary versus not. But there would be uses some vector database under the covers, as you are searching for music fragments and trying to create your own composition, Elastic is the technology under the covers. We are used by some DevSecOps platforms as the vector database under the cover for their code generation agents. So all the way from these kinds of AI native capabilities to more traditional use cases, we have banks that are using -- that have used us and have made us the -- have sort of put us into their core agent development framework and have built agents on top of us already for servicing their high net worth clients as conversational chat application that is used by their wealth management teams all the way to automotive companies that have built agents for dealing with their partner networks.
So it's very, very broad customer support, code generation, like some of these AI native use cases like I talked about, ISVs that have embedded us under the covers as they are building AI applications that they're taking to market. What's exciting is all of this is still just scratching the surface, in my opinion, because most organizations today have a handful of these AI applications that they rolled out. And the aspirations that are very clear are to build hundreds of these for all kinds of automation across the industry.
I think as each customer adds more and more of these AI applications, our consumption just naturally grows. And so our focus today is to get embedded into as many of these use cases as possible, which is why we give the count on 2,200 customers in the last quarter that are using just an Elastic Cloud. These are not trials. This is not -- we have free trials and all of that, but these are actual customers and actual use cases.
Got it. Got it. I want to come back to you later on about the -- how you participate in the economics of the AI stack. But Naman, if I recall right, you're an engineer, right, a former engineer, I mean... .
Former, recovering. I've long been a finance person that I've forgot...
No, I understand. But so I'm an engineer. I used to be an engineer, but I'm finance guy too. The reason I asked is, was that the reason you hired Naman [indiscernible] got to be an engineer, first and foremost, and then the finance stuff, the MBA and all the....
I mean, look, it's -- I'll tell you like what -- I know. And I'm not going to answer this seriously as a question. But one of the things that to me was really, really important is the ability to understand what it means to operate in an open source model, right? And Navam bought a ton of that expertise with his time at HashiCorp. And so the engineering piece might have been somewhere on the list, but it was definitely not one of the top Reasons.
That's greaT. so Navam, welcome to our first because of a podcast, I think better than a podcast, we're asking some real questions of real people. But how has it been so far for you at Elastic. How it's been your experience?
It's been great. I mean, as Ash mentioned, I've been in an open source company before. So the way I would describe Elastic is there's a lot of things that rhyme with my previous experience at HashiCorp, and there are a lot of things that are way better than my previous experience in HashiCorp. And the scale that we've achieved the amount of GTM success we've seen over the past 4 quarters and the testament we have with sales-led subscription revenues having such a durable value over 4 quarters.
And more importantly, a ton of product innovation we're delivering into our platform and also the tailwinds of AI. So a lot of things to get very excited about in this particular opportunity at Elastic and it's been a really good -- I've lost count because I can't play the new guy card anymore, but I think it's been about 2 quarters. So it's been a great...
And this quarter that you reported was your first full quarter?
This was my first full quarter of actual results.
Reacceleration margin expansion, I mean the guys they're crushing it. Yes. So how were you able to do this? And what is your prognostication of if you uncovered so much in 4 months.
I take very little credit for this last quarter. I think there's been a ton of work that the team has been doing over the past more than a year on the GTM side, on the R&D side, that I get the benefit of just coming in, in the last quarter and saying, "Hey, guys, here's how we did in this last quarter and it was a great quarter."
He's being very humble. I mean, Yes, talk to us more about the price increase thing, people debate this, oh, yes, all the growth was price increase. Most of it was not much. What is the best Personally, I like it when a software company increases prices and some look at it and say, well, that means the units are down, blah, blah, blah. Like, you want to invest in a company that has pricing power and is able to show that pricing power by raising prices common share with the value that the company delivers. Where are people wrong about. If you got a sense, I know you've been at a couple of other conferences before, are people being a little wrong headed about assessing the quality of your price increase and the durability of your growth.
I think there's a few fundamental misunderstanding. But the misunderstanding is the misunderstanding of how consumption works and how price increases is working in the context of consumption, right? So first and foremost, I would argue that most of our peers who are here at your conference today, particularly the innovative ones have most likely revisited prices from time to time, we're no different, right? Some of them reflect their innovation through new SKUs that they introduce and they charge for those SKUs.
The way we do it is we drive a lot of innovation onto a single platform. And that platform increases in value over time. And from time to time, we look at that and we reflect some of that value through a price search. We've done that in the past. Last year, we did it on the self-managed side a couple of years before that, we did it on cloud and self-managed. This last May, we did it on cloud and self-managed. This is not likely the last time we're going to revisit prices given the amount of things we're doing with the platform to actually give value -- sorry, give value to our customers.
The underlying platform is getting more and more valuable. So the thing we need to remember is how do we judge success in this context, we judge it in 2 ways. How are customers committing to us on a quarter-by-quarter basis and they have a choice and how are our customers increasing or decreasing consumption with us. And that's a day by day they have a choice on how they do that, right? And when you think about the puts and takes of consumption, there are multiple things that are happening under the covers.
First is the -- the data volumes increase and that increases the consumption the customer has. Price is one factor, which increases the consumption a customer has. And on the other side, there are things that decrease the consumption. Our customers optimize quite frequently as they optimize the increased data, they optimize the increased data and that kind of tends on an upward and downward trajectory. The second is we introduce things into our platform that is meant to make things more efficient to our customers.
About a quarter before, if I'm not mistaken a quarter or 2 before the price increase, we did it -- we introduced [indiscernible], which was meant to increase the efficiency of how our customers store their data and therefore consume less -- that's by design. Searchable snapshots happened a couple of years ago meant to decrease the amount of consumption a customer has to make things more efficient to our customers. So they're -- in the consumption model, there are multiple puts and takes, of which pricing is just one, and pricing is elastic so customers can optimize and decrease their consumption or they can see the value in the platform and grow.
So what matters is net of all these puts and takes, how is consumption going with our end customers. And Q1 was a testament where consumption was strong, commitments were strong and more importantly, consumption is strong, which gives us confidence that what we are delivering to our end customers were ultimately absorbed and they decided to increase their consumption.
Got it. So in the context of being able to successfully put through a price increase and the quality of the Q1 beat, people see the rest of fiscal 2016 guidance as being very conservative. How do you, as the CFO, balance the process of setting prudent expectations versus signaling confidence, which is always a ticky thing to do.
Yes. I think on the 1 hand, we had an excellent quarter. It was a very strong quarter, both as a -- on a consumption and a commitment basis. it was balanced without any outliers or onetime things that caused us to see this increase. The way you should think about the price increase, like I said, is it's a durable lift to the floor, just like you adopt a new SKU and then you grow from there. That's how we should think about how the price increase changes over the years. .
But to answer your question, we gave a prudent guide in Q1. We detailed the assumptions behind the prudent guide and -- sorry, in Q4 and in Q1, we delivered against that guide. And I think the meta point is that the results speak for themselves as to the confidence, right? The numbers will speak to the confidence. And we will continue to give prudent guides, but one thing to remember is we also give a lot of narrative behind those guidance behind the guidance numbers to talk about the underlying strength of the business. So the Q1 details we provided was in our opinion, a very strong quarter, which gives us confidence in the full year, which made us raise the full year guide. And we intend to execute every quarter and revisit the year as appropriate.
Yes. I mean just to be very blunt about it, the 2 things I look at in every quarter are how are commitments trending because commitments are a predictor of future revenue, as you know. And then second, what is the trend line on consumption. They were both very, very strong in Q1, and the underlying business is very strong. So the prudence that Navam bakes in into the guide, I think that's 1 thing. But to me, like as I think about the business, there's a lot of excitement.
We're better positioned today relative to a quarter ago, 2 quarters ago, 3 quarters ago after you went through your GTM changes? .
Yes. When you think about like when we had the issue over a year ago, 5 quarters ago, we talked about where we had a stumble, right? And we've always been very transparent about stuff like that.
things looking up now.
It's been great. I mean, the last 4 quarters have been very solid sales execution. The changes...
So you've tweaked and you've got the right model...
We've got the right model. The 2 things that Mark, our CRO, really wanted to get right. One was the focus on enterprise and mid-market where each rep had fewer accounts because the model that we have prior to him making that change had been there since pre-IPO. And it was right for when we were a much smaller company. And we had gotten to the point where like we needed to do something different to allow us to go deeper and broader in accounts. And the second thing that we wanted to get right was greenfield territories where we could have a dedicated hunting motion because that is also important because we have a massive open source presence out there.
So customers or organizations that are using the free version of Elastic search but have never paid us are prospects, our great prospects. So how do we make sure that we have a dedicated greenfield motion, hunting motion? So both of those we established with that change that we made. And as those settled, like we are starting to see the benefits. We are starting to see larger million-dollar customer accounts have grown faster. In the last year than prior years. So we're seeing the right kind of outcomes. So it just makes me feel very good about the future.
That's great. My go-to-market is actually the opposite of started with 12 companies and growing 37 companies. if the IPO markets continue to be healthy, that number will likely grow, but everything has a limit. I want to talk to you, and I Navam, I will come back to you. How are you deploying AI internally within the company as a CFO with with an engineering background, aren't you like jumping all over this and seeing how you can -- it's operating efficiencies within finance or sales? How are you deploying this stuff and getting advantage out of it internally and then I'll come back to you externally
Yes. I think in the broader business, there's a lot of AI deployments, particularly in customer success in the marketing organizations. In those organizations, we even have a internal agent that we talk to and get intelligence from. On the... .
What do you call it. .
Elastic GPT.
For Sales, it's got Elastic GPT.
We're very creative Okay. I think finance is in very -- in the, I would say in the behind from the rest of the company in our adoption for AI, and there are several reasons for it. It has to do with the maturity of the audit side and the acceptance of AI in audit. So naturally, I think the first places where we'd be using the AI and ML within the FP&A side. Accounting will be a little bit behind the FP&A side. .
How do you foresee using AI and something like accounting? And how does that...
I think the first thing that needs to change is that the audit firms themselves will have to accept AI as a form of something auditable. And right now, the problem is that the audit firms are not quite there yet and accepting that. But once that acceptance comes, there's a ton of things that we can do, both in preparation of memos or reconciliations that could be done with AI that just make our accountants way more efficient than what they are today.
On the support side, as an example, our support agent is very heavily used. Like the number of -- the case deflection load is somewhere in the 40% range where that percentage of tickets never get to any human being they just get deflected. And that's a huge advantage.
How long have you been doing in customer support.
Over a year , well over a year, like 1.5 years
It's is going to go higher, I think Say -- it's going to go higher. It has to go higher
Yes. I mean it's like we keep pushing down a lot on that, right? And like the way I think about it is as we grow, if we can help make the broader teams more and more efficient at just being [indiscernible] that we can drop to the bottom line or develop...
.
Yes, the -- I mean we had a huge kickupshop. As anybody who knows Elastic and Elastic Search, you know our public repos are all in GitHub. And so we had a very large [ Katapshop ], and we use their copilot but we also use multiple different coding bcoating tools.
So what's your view on coding versus cursor versus what you get with GitHub or the Codex based technology.
Well, we use multiple of those because we found different advantages for different ones. So we use 2 distinct vibe coding tools in addition to GitHub copilot. And what we have found is that the places where we are seeing the greatest advantages are in test development and in UI development. But anything beyond that even though you would argue that our repository is all in the open. So arguably, the language models have been trained on our entire source code. But it's still. Like we don't know...
Vibe coding or regular AI produced code.
When you look at AI produced code, right? It's not where we would want to use it for like core modules. It's still -- it's -- where we're seeing massive value is, in the past, we used to go into customer accounts where they would say, we love your platform, superscale, it's like amazing. But I need a what's called a searchindising UI. So I don't know if anybody is -- there's merchandising, right? So when you're talking about merchandising, like marketers like to change preferences. So when you do a search, like this thing will pop up before that thing, you want to pin certain results. So that kind of a UI is called a searchinding UI. And historically, we've always prefer to have a platform.
Kash versus Ash.
You're better at naming. But like this idea for [indiscernible] has existed in the market for a long time. The we didn't build these out of the box. And this used to be a reason why somebody would say, "Oh, I prefer if only this your UI was nice like that company there that only specializes in that. And we will basically say, look, we can help you with that, But like that's not where we are putting our product energy.
What we have disclosed is when you -- when you come -- when it comes to building those kinds of UIs, these VIBE coding tools are fantastic. And so we are able to very quickly churn out the appropriate searchindising UI and make it bespoke customer by customer. And then it's like, "Oh, yes, do you want to searchindising UI, let me create it for you. So that issue has gone away. Another area where we found a lot of value is conversion from language scripts in competitive products that we might be displacing to elastic scripts, right? So you have a scripting language, and we have a scripting language conversion. You can just use these tools, and they'll do the conversion in minutes, and this used to be like months of work. Now it can get done within a week with testing and acceptance testing and everything. Huge savings. So in migrations, in these kinds of areas, we've seen a lot of benefits.
Got it. anybody, you want to jump in with a question? Please raise your hand. .
I know it is the afternoon effect. It's like pushing 3, we all need a cup of coffee before we can rejuvenate ourselves. But I have another 1 for you, Ash. The what have we learned from the early deposits about a couple of thousand folks that use RAG in your installed base? And I keep hearing maybe it's [indiscernible] in the media that the context window is bigger for these latest models whether its GPT 5.0, whatnot. And people are rag is dead. I'm sure it's not. But how do you think about broader context windows versus the value-added RAG, which is essential for you to add value to your customers?
Yes. I think the part that people miss on this context windows, fundamentally, making context windows massive does not really help because your language model is running somewhere else, you allow it to receive 1 billion documents in a context window. Do you know how much time it takes to move a terabyte of data like physically to move a terabyte of data, like you'd be waiting for minutes for anything, just to shift that data out. So context window increases does not really come into any relevant context for building business applications. The context window improvements add value is if I'm having a long-running session for ChatGPT
Now I can maintain history with somebody's
I have a conversation. I can remember the conversation that you had with ChatGPT going back a year because it just stored in that context window, and it keeps building it up. So there are use cases where context window increases are incredibly valuable. They are almost entirely or irrelevant to the conversation about RAG.
Very clear. Very clear. .
It reminds me that just the way you explained that 1 terabyte of information. Anybody here remember in-memory databases and how it was a thing. And there are some people here. You will just not admit that you're old, but in memory databases are going to wipe out because they had the context windows. It run transactions in memory, but then we had reawakening.
We realize that data is actually way more than can fit into memory. And I don't think this is the thing, right? So I think the fact is that RAG or retrieval augmented generation, the way we thought about RAG 2 years ago was pretty naive. Now when you look at RAG, there's way more in it than what we used to think about 2 years ago. Having said that, RAG is never going away. Retrieval in real-time is always going to be critical because your data is constantly changing. And if you want to ground LLM in the right information, you have to do it in real time. So you can't afford to ship terabytes of data to an LLM. You have to do it contextually, you're to find the right thing and accuracy is going to matter more than feeds and speeds. And so that's -- when we talk to customers, who are now bidding these modern apps, Hey, look, if -- if it's a ChatGPT style application and it gives you the wrong answer, you're fine. If it's an agent that you are depending on to book tickets for you, you want to make sure it's booking a ticket on an airline and a flight that actually exists, right? If it makes hallucinations and get that wrong
You transfer...
It's the problem of these language models are amazing, the magical, but they act like human beings. If they don't have the right answer, they make it up. So an engineers don't do that, but everybody else
the middle of 19 seconds, we've talked a lot about search give us a state of the assessment in APM observability security, like..
Our focus is to really play -- continue to play in those areas where unstructured data is most important for the problem. So when it comes to observability, we lead with log analytics and we expand from that APM, infrastructure monitoring, et cetera. same with security. We lead with SIM because it's all unstructured log data and then we'll expand from there. Our AR functionality cash is helping us massively differentiate in these areas. So you look at our attack discovery functionality. You look at the the AI SoC engine that we recently announced. All of these features or about how do we use the native AI stack to help you automate your SOC process to help you automate your SRE process. And that's how we intend to win in those spaces. And it just -- it feels like a very consistent way. And that's why I say we are a platform, not a portfolio, right? And that platform approach gives us massive leverage that we feel will allow us to continue to both grow the top line but also grow profitability for many years to come.
Got it. On that note, I wish you a successful journey in the years ahead. And thank you once again for your support. So good to see you part of the team here. Let's get it around of applause for Ash and Navam
Thank you.
Elastic NV — Citi’s 2025 Global Technology
1. Question Answer
Hello everyone. Good afternoon. Tyler Radke, I co-head Citi's software sector. Welcome to the afternoon track of a busy day 2 at the Citi conference. We got the Elastic team here with us for a great discussion, Ash Kulkarni to my left, the CEO; and the recently appointed CFO, Navam Welihinda. I'm sorry if I got it right?
You got it.
Okay. So gentlemen, thanks for making the appearance. For folks in the room that maybe are less familiar with Elastic, could you just give a quick overview on the company and how kind of the evolution of AI has impacted the business?
Sure. So Elastic fundamentally as a company was founded on an open source project, Elasticsearch,; which was written by our co-founders. And the best way to think about it is it's a search platform. It's a technology that's designed for bringing in any and all kinds of messy unstructured information and then making all of it searchable. So through that, you can then analyze that data in all kinds of ways. And over the years, we started in that sort of basic search area, but then grew into observability, specifically starting with log analytics because logs tend to be extremely messy. They're voluminous. They're hard to analyze. And then getting into observability over time, we got into security as well, into cybersecurity, specifically starting with SIEM and in the security, event management and monitoring space, that became the cornerstone, but then we also expanded into other areas in security, specifically endpoint security and so on.
As AI has become more and more prevalent in terms of how people are not only using AI for doing -- building conversational apps and so on, but also for building agentic workflows that are being used to automate more and more business processes. What is very obvious is these large language models, which truly are, in my opinion, like the operating system of the future, the way you program these large language models is using English, but these large language models only know what they've been trained on. And all of that is what is publicly available out there.
So these large language models have no context about your private information. So if you're using a large language model, if you're building these kinds of agents within your company, you need to somehow provide context to these large language models. And that whole process of what's called context engineering or data retrieval for context engineering, that is how our product is being increasingly used today. So our vector database and everything else surrounding it, that is what gets used in building these agents, these kinds of applications. And that has also benefited us in security and observability because increasingly for those processes, whether it's a SOC analyst or a site reliability engineer, we, through our AI stack, are able to make their jobs easier through automation of those systems as well.
Great. It's a good overview. And I guess double-clicking on the AI opportunity, just for -- again, for those unfamiliar, like how do you -- there's a lot of different software companies talking about AI. You have application companies, some other infrastructure companies. Like how do you monetize AI today? How should investors kind of think about how AI impacts the numbers side of the equation?
So the biggest impact for us is on our search business because when we think about our search business, that encapsulates any time you're building any kind of custom application on top of our core platform. And this data retrieval, this context engineering that I talked about, that is all effectively a search problem. You're trying to find just the right set of data within your overall environment that is relevant to answer that particular question. And so we are seeing an expansion of our search opportunity, and that's resulting in search effectively becoming the fastest-growing part of our business.
When you think about search, observability and security, these 3 areas, search has become the fastest-growing part of our business, and it's because of the tailwinds of AI that we have seen. For observability and security, it's helping us compete better. So we lead in, in the case of security, we have launched capabilities about a year ago, we unveiled something called Attack Discovery that instead of just showing you alerts, in your SIEM now looks at those alerts and is able to using AI, identify the cybersecurity attacks, the attack patterns that are happening within your data.
So it's effectively doing a lot of the job that a SOC analyst does. So it's helping automate a lot of that work. It's helping simplify and actually acts as an aid, an accelerant for that SOC analyst. All of that is what our field teams tend to lead with because that's a big differentiator. That's something that we are able to do that others aren't able to replicate. And that's making our security business more and more competitive. It's making it easier for us to win. We're seeing that same thing also play out on the observability side. And that's why we feel that it's going to help us increasingly in all 3 parts of our business as we go ahead.
Okay. Great. And I think one of the unique parts of the Elastic story is, I mean, it's -- the product can kind of be interchangeably used across all those 3 use cases, meaning you buy a subscription or consumption credits and you can use it across a wide range of use cases. I'm curious, I mean, how do you think about opportunities also to amplify the product's reach, meaning like, yes, this is -- it's a great developer platform, but there are other vendors, both in the search space, whether it's Glean on the AI side.
Obviously, you have a number of observability and cybersecurity vendors that offer something a little more packaged out of the box. And clearly, there's been a rise of Vibe coding start-ups that make developing software easier. So is there an opportunity to make this stuff easier to use and ultimately drive more consumption? Or just how do you think about that high level?
If I just step back and I look at the AI opportunity, what I'm seeing is more and more applications being built that take advantage of all of the unstructured data that we have sitting within our organizations and automating business processes that depend on that unstructured data, right? That's really what's happening. Because we've always had the ability to write applications that worked on structured data in deterministic ways, right? So CRM systems or ERP systems, they all dependent on very structured data, and they had very well-defined processes that you could automate on top of that structured data.
With LLMs, the big opportunity is to do that same kind of automation on unstructured data because that unstructured data, whether it's employee onboarding or it is customer support, there is a lot of stuff that you need to figure out on the fly. You need to reason on information that is not all structured. You're trying to respond to a customer that might have a particular problem. You need to look at so many different things. You need to look at what is the specific issue that they're facing. What do you know about the product and where you might have issues that might be known issues that exist in your product. You might want to look at other customer questions that might have come in to see, is there anything that we can learn from there.
All of these are unstructured sets of information. You need to be able to automate based on all of that. That's where LLMs are really, really good. But now you need to provide this context to those LLMs. So the opportunity that I see for Elastic is that as more and more business processes get built to automate using AI, I see the opportunity for Elastic to be embedded as the vector database as the platform for doing that context engineering in as many of those AI applications as possible. That is the real opportunity for us, which is why we are so keen and so excited about what AI represents for Elastic.
Okay. Great. And as you think about that AI opportunity, I think clearly, it's going to be a huge market, early days, but there seems to be the opportunity both with AI natives, right? We're seeing a lot of these -- obviously, you got the model providers, the vibe coding platforms, cogeneration start-ups. And then you have the enterprise building their own platform AI. Like how are you positioned in each of those segments?
So we look at both motions as being equally relevant to us, right? At the end of the day, whether it's a software vendor that's building the next vibe coding platform or the next ERP solution or the next HRMS solution that's evolving out there, each of them is looking for some way to build an AI native application that's going to make that application more and more interesting, more and more exciting for users to use. We see that as the ISV play, right? So we want to be embedded in as many of those applications as possible. We've publicly talked about existing customers, whether it's a DocuSign, whether it's a Seismic. There are various examples that we have given of customers that have already done that with us, right? These are companies that have -- and we also have DevOps companies that have used us as part of their agents within their coding platforms.
So we have lots of those examples. At the same time, we have enterprise customers that are using us for building applications, whether those are agents or just conversational chat style applications or implementing semantic search or what have you. In their environment where they're pulling data from different systems. So it's not -- it's a custom-built application that they are creating. It's for just their use case, it is not something that they're selling to customers. And that's perfectly fine, too. So we've seen banks. We've seen telcos. We've seen e-commerce companies. So lots of use cases.
Fundamentally, Tyler, the way I look at it is AI represents a very different way to build applications in the future. Today, if you ask any major organization, if I just look at your company, your bank, Citi, you probably have dozens of agents that you are building or have built within your organization. And you probably, over time, will build hundreds, if not thousands, of these agents and applications. We are still in the early days. For us, the trick is getting into as many of these as possible right in the early stage. So we are part of that core fabric. We are part of that core infrastructure layer as they're building these applications. And as you build more and more applications, we just grow with you. I think that's the real opportunity here.
Yes. Yes. I think we're still a ways away from using agents at a large bank business.
I'm sure somebody within your company because we already work with various other banks. I'm...
Yes, for sure. For sure. Maybe there'll be an agent up here asking you questions next year, so better watch out. But Navam, I thought we'd bring you into this.
As long as they use Elastic for data processing.
Okay. Navam, I thought we'd bring you into the discussion here, just fresh off results, I think kind of maybe your first full quarter as CFO. Pretty strong beat across the board across both cloud and self-managed. I know there was a lot of questions around the price impacts in the quarter as well. So maybe just frame for us kind of the key puts and takes on the quarter from your perspective now that we're almost a week past when you released.
Yes. It's been a great first quarter. Let me tell you that much. So from what you said, that's absolutely true. Q1 was a strong quarter across the board, and we beat the top line by $18 million, and we had a strong bottom line performance as well. The way I think about the health of the business is around 2 aspects, which is how are commitments going and how is consumption going, right? And both of those in Q1 were very strong. Commitments, if you think about what happened there, year-over-year, we saw growth. The growth was across all geos. It was balanced, no outliers. That's great news. On consumption, it was the same thing, year-over-year growth, no outliers and strong commitments across the board in Q4.
So overall, from a Q4 perspective, I thought it was a great quarter, and we were very happy with what we delivered. On your -- and the other thing is when you think about the underlying consumption level that we saw from Q4 to Q1, that increase was very strong. So we're happy with that consumption increase that we saw in Q4 to Q1 as well.
So moving on to your price comment, I think it's worthwhile parsing back a little bit and understand most software companies do price changes, and we're no different from any of those other software companies. And this isn't the first one we've done. We did a price change last year on the self-managed side. We did a cloud and self-managed price change a couple of years before that, and we just did one in May. So this is more of a history of us periodically looking at prices and making changes just like most other software companies do. So it's more of a matter of course of business for us, right? And the reason we are okay with changing prices and the reason we feel good about changing prices is because of the way we introduce functionality into our product.
So our customers, they don't get separate SKUs for new things that we deliver. We sell a platform and all the new product introductions go into that platform. So over time, what we're delivering is more value for money in that platform, which we capture periodically through price increases, right? So that's an important point to remember that this is no different from any other software company practice, and it's no different from the history of what we've been doing in the past.
The second point I want to make is that when you think about price changes, what matters is how does consumption change with the changes in price, right? And when you think about consumption, there are multiple puts and takes you need to understand. In any given quarter, people are optimizing their usage. So there's data coming in, which increases their consumption. They're also optimizing their usage, which puts downward pressure on consumption. So that's happening in any given quarter.
The second thing is we introduced feature functionality that is meant to drive more efficiency in our customers. Two specific examples of some things we've done in the past are searchable snapshots and Logsdb. If you adopted those 2 features, you're naturally going to be more efficient and consume less. So that's downward pressure on consumption. And then there's pricing, which adds upward pressure on consumption and also people react to price, there's elasticity and people change consumption.
So what matters to us in a consumption business is very different from a seat-based model, which is a simple P x Q math. What matters is how does consumption change in relation to all these changes that I talked about earlier? And is the net consumption growing? And that's the biggest thing we care about. And what we saw in Q1, right, so that's the main point I want to make about pricing. You can't really in consumption models, isolate one individual variable across the many variables that I talked about and then do simple math and say, well, absent this, it was X, Y Z, right? So that's a big misconception that I think we need to clear about as we consume how to think about pricing in consumption models.
Right, right. And some of those efficiency capabilities that you highlighted, the searchable snapshot and some of the login functionality, was there any like significant additions to the portfolio in Q1? Or was this kind of more of a comment on like...
No, no, no. Logsdb was introduced in Q4. So, yes, yes. So this was -- but again, like...
In conjunction with the...
Well, not in conjunction. We don't think about it necessarily in conjunction, Tyler. The best way to think about it is we introduced those kinds of features. Searchable snapshots was about 5, 6 years ago. Then another thing that we did some time ago was supporting some of the newer chipsets, ARM-based chipsets, Graviton chipsets from AWS. That made the system more efficient. So it brought down consumption. We introduced better compression, and we have done that in the past. That brings down consumption. The whole goal is to keep making the platform better and better.
So competitively, this looks like the absolute best choice for customers, and they keep bringing more and more workloads to us. And what we see is when we do that, for any given workload, we might see a near-term pressure, but very quickly in the mid- to long term, people bring more workloads and we see growth, right? Searchable snapshots when we introduced it 6 years ago, it immediately put pressure on existing workloads. But as people started retaining data longer, they started bringing other workloads. We started to see -- that was one of the features that drove more and more people to use us as compared to Splunk, even in those days. That pays off very nicely in the long run, right? And that's why we do these things. So to Navam's point, trying to disaggregate any one factor, is just meaningless.
Okay. Very clear. So you feel very good about the consumption growth in Q1. And I assume based on the raise of the year, you're expecting that -- those trends to continue.
Yes. We expect -- because of what we are seeing, both in commitments and in consumption, we feel really good about the strength of the business in the year.
Great. Great. No, super helpful. Speaking of sort of the changes between Q4 and Q1, I think you sounded a bit more upbeat on the macro environment, maybe upbeat, a little strong of a word, but obviously, the federal weakness that you saw in Q4 was pretty widespread across the software space. Like just remind us, what did you see get better in Q1 versus Q4, both in federal and across other industries?
Well, let me tell you about federal and then Navam can also add to it. In federal, so I spend a lot of time with customers. I'm generally out on the road a fair bit. Next week, I'm going to be at the Billington Cybersecurity Conference in D.C. On the federal side, the way I describe it is in Q1, it felt like the new administration has sort of settled in, right? So clearly, they have a greater focus on efficiency than we have seen from prior administrations. But like there is -- the fact that they are settled basically means that we are not seeing a lot of personnel changes on an ongoing basis, like things are just more settled, people are making decisions.
And even in that new normal, even though there might be a greater consideration and focus on efficiency, that's a world that's more stable, and we know how to operate in that world, right? It's a world where we know the strength of our product is going to continue to hold very, very well because, Tyler, as you know, when you look at value for price, like we've always had an outstanding value proposition. And so from a competitive standpoint, we feel really good. And now that people are making decisions, it is an environment that we feel really good about operating in. So from that perspective, like we said, like the public sector environment, especially in the U.S. felt stable, right? It felt good compared to the uncertainty that we were experiencing 90-ish days ago. But I don't know if I missed anything.
I would echo that. Going into the year, we had detailed out the headwinds we were -- or the pressure we were seeing and then assumptions on what could happen beyond the U.S. public sector. civilian ag, just to Ash's point, throughout the quarter, we saw that the U.S. pub sector was much more stable. We know how to operate and the teams are primed to operate in that environment now. Our products resonate in the administrations focused doing more with less, right? So we have a good footing in this new normal. That's number one.
And then clearly, we did not see the scenario play out where things spread across other geos and unrelated sectors to create more headwinds. It was a much more stable environment than what we had feared or guided to in Q1 and -- or in Q4. And the result is we had a great quarter. We feel good about the year, and we reflected that by raising the guide more than what we had beat. So at the bottom end of the guide, we beat by 18. The bottom end of the guide got -- we increased by $24 million and the midpoint by $22 million. That's to signify that we feel much better about how the year is going. And every quarter, we're going to go execute and go revisit that number again.
Right, right. But you would describe the guidance is still pretty prudent in terms of macro assumptions and everything.
That's right. I mean we -- I think I'd always aim to give a prudent guide, and this one is no different. And like I said, we feel good about the year, which is why we raised beyond what we delivered. And every quarter, it's going to be -- we're going to execute and go -- give you a new view of the year.
Got it. Got it. Ash, I'd love to just ask you about the competitive landscape. Obviously, there's a lot of different areas that the Elastic product touches everything from cybersecurity to observability and then search and AI with vector search. But yes, there's certainly been a lot of kind of consolidation pressures, if you will, in both the security and observability market, whether it's budget constraints or OpenTelemetry. How are you seeing that impact the Elastic business either positively or negatively?
So just in terms of where we see our competitive dynamics play in our favor, in security, we've always talked about security as being a data problem. And so anytime you have a situation where customers appreciate the need to bring in all the data and retain it for long periods of time because they understand that the cyber landscape is pretty complex, that plays to our strength. Anytime they need to use, they feel that it's in their benefit to use AI to drive more automation, that plays to our strengths. And lastly, when you look at security, if the customer has a desire to run that security workload on-prem in their own data centers, we are really one of only a couple of choices at scale that works because many security products are only available in the cloud.
So one of the reasons why you will continue to see us do very well in our self-managed business is for that reason. There is tremendous advantages that we have, not only as this data-oriented security player, but also because of our AI functionality and our ability to have a really strong offering in a self-managed mode. When it comes to observability, that -- it is a large growing market, but as you know, it's also a very busy market. Our core strength is when the data is messy. So that's why we lead with logs because when it comes to logs, especially application logs, the messier the information, the harder it is to query, the more you need a product like ours, a platform like ours that's inherently designed for unstructured messy data.
If the data is structured, if you're dealing with metrics and so on, there are other players that naturally have been in the market for longer, and we see that competition obviously is there. But when it comes to logs, we have a true differentiation. And the work that we're doing in terms of both driving more efficiency into the platform, but also using AI more effectively there is a continued strength for us. And then on the search side, you saw this movement where there were a lot of attempts at trying to define vector databases as a separate market. I think it is becoming more and more clear to people that vector databases are feature as opposed to a category in and of themselves.
For us, our focus is always -- our center of gravity is always going to be on unstructured data. You can absolutely put structured data into Elastic, but what we do uniquely well is when it comes to unstructured data, the ability to query that to be able to search and do all kinds of analytics against it, we are very, very good at that.
What I expect is going to happen, and we're starting to see that is you're going to start to see centers of gravity continue to strengthen on platforms for different types of data. So if you are structured, you're going to end up with certain kinds of platforms that are really good at analytics. If you are unstructured, you're going to tend to see companies like us. And I would expect our competition to be primarily the hyperscalers in that area. And we know how to compete very well with them. We've been doing it our entire existence.
Right. Right, right. And I guess just as you think about sort of how to drive the durable growth of Elastic and this goal to be the embedded kind of platform within these emerging AI applications, obviously, top of funnel, developer affinity, those are important things for the next generation. You did make the return to open source AGPL, I think, over a year ago, if I'm not mistaken. Give us an update on how that's gone? Like what are some of the metrics you also look at to measure this top-of-funnel momentum?
Yes. So the reason why we adopted the AGPL license -- before that, we had the SSPL license that we supported and the Elastic V2 license. Elastic V2 is very, very permissive, but neither SSPL nor Elastic License were OSI compliant. So AGPL is an OSI compliant, so you get the official stamp of being open source. The reason why that was important for us is in the community of open source developers as people are looking at open source alternatives, they basically look at what's OSI compliant. And where this matters most is in the area of vector databases. That's the evolving space, right? That's the area where you are still -- we are still very, very early in the overall AI market. And given how early we are, that's the land grab right now.
So it matters to us on how we are -- where we are seen, how people find our technology, download it, use it. And to me, it's less relevant whether they start by being a paid customer to begin with because these developers are going to just play around with open source technology. And over time, as what they're building becomes more meaningful, they're going to look to a commercial vendor and they're going to stay on that platform.
So what we look at in terms of metrics, we look at how we show up in various open source forums. We look at the number of downloads of our product. Those are things that we track. We obviously look at the number of trials that are happening on our products. So there are various metrics. The AGPL license is something that we cared about because we wanted to have that top-of-funnel activity. And everything that we are seeing gives us a sense that it's really been the right decision.
Okay. Okay. Great. And then, Navam, on your end, we have an Analyst Day coming up in a little over a month. Obviously, you're still putting together the plans in terms of what you're going to share. But how are you just thinking about targets, both on growth and profitability? I know it's something the company has guided to in the past. You may have a different philosophy, but how should we be thinking about how you think about long term about the business, obviously, without giving away too much ahead of Investor Day?
Yes, I don't want to give the punchline, then you won't show up. So I encourage you all to attend Analyst Day, it's going to happen in about a month. It's happening in conjunction with one of our user conferences, ElasticON. We have a few of them. This one is in New York. So Analyst Day will be in parallel with that. If you do attend, you'll get to see the keynotes as well as some of the demo booths and our users in full swing. So that's a worthwhile experience.
On the Analyst Day side, which is parallel to ElasticON, you get to meet our team, talk about things in a broader context. So the product side, you see Ken and our GMs, one of whom is with us here, Steve, talk more about the broader vision on product along with Ash and the GTM side, Mark will talk about all the changes he's done to GTM and think about that as well and get some information on that as well. In finance, yes, one of the sections we're going to have is the medium-term model for the business and how we balance growth and profitability and what you should be thinking about in terms of our growth algorithm. So I don't want to give it away because then you won't show up. But that would be what I'd expect to see in Analyst Day.
Okay. Okay. Great. And I think I guess just go-to-market, I know we only have a couple of minutes left, but a little over a year ago, you did make some changes there that proved to be more disruptive in the Q1 a year ago, but it seemed like you kind of bounced back from there. So just remind us like what were those changes? And have you started to kind of see the returns on some of those investments or changes that you made?
Yes. So for the last 4 quarters, if you look at our sales-led subscription revenue, right? I mean you just have to go and see Navam's script. We have shown consistent and very strong execution, and that was possible because of those changes that we made. So the changes that we made 5 quarters ago, they did two things. One is they created greater focus on enterprise and mid-market accounts where fewer accounts per rep meant that our reps were able to go deeper and broader into those accounts. As you can imagine, that leads to greater focus that results in higher quality deals, larger deals. We've seen the benefit of that in the last 4 quarters. And in the greenfield territories that we created, we created more of a dedicated hunter motion. And that has also been paying off.
So if you look at the number of net new million dollar deals that we've been adding the $100,000 deals, like we are seeing the benefit in all of those metrics. And the best metric to me is sales-led subscription revenue, right? It doesn't matter if it's self-managed or cloud, but that is what we focus on. That is what we drive. And you just need to look at the data to see that it's been really strong execution throughout these last 4 quarters. So we're excited.
Great. Well, let's wrap it up there. I think we're out of time. Thank you both for the discussion, and look forward to seeing you at the Investor Day in November.
Thank you, Tyler. Thank you very much, folks.
Thank you.
Thank you.
Elastic NV — Q1 2026 Earnings Call
1. Management Discussion
Good day, and welcome to the Elastic N.V. First Quarter Fiscal 2026 Earnings Results Conference Call. [Operator Instructions]. Please note, this event is being recorded.
I would now like to turn the conference over to Eric Prengel, Global Vice President of Finance. Please go ahead.
Good afternoon, and thank you for joining us on today's conference call to discuss Elastic's first quarter fiscal 2026 Financial Results. My name is Eric Prengel, Global Vice President of Finance.
On the call, Ashutosh Kulkarni, Chief Executive Officer; and Navam Welihinda, Chief Financial Officer. Following their prepared remarks, we will take questions.
Our press release was issued today after market close and is posted on our website. slides, which are supplemental to the call can also be found on the Elastic Investor Relations website at ir.elastic.co. Our discussion will include forward-looking statements, which may include predictions, estimates or expectations regarding the demand for our products and solutions and our future revenue and other prediction.
These forward-looking statements are based on factors currently known to us, speak only as of the date of this call and are subject to risks and uncertainties that could cause actual results to differ materially. We disclaim any obligation to update or revise these forward-looking statements unless required by law. Please refer to the risks and uncertainties included in the press release that we issued earlier today included in the slides posted on the Investor Relations website and those more fully described in our filings with the Securities and Exchange Commission.
We will also discuss certain non-GAAP financial measures. Disclosures regarding non-GAAP measures, including reconciliations with the most comparable GAAP measures in the slides unless specifically noted otherwise, all results and comparisons are on a fiscal year-over-year basis. The webcast replay of this call will be available on our company website under the Investor Relations link.
Our second quarter fiscal 2026 quiet period begins at the close of business on Friday -- we will be participating in Citi's Global TMT Conference on September 4, the Goldman Sachs Communacopia and Technology Conference on September 8 and the Piper Sandler Growth Frontiers conference on September 11. Finally, Elastic will host a Financial Analyst Day in combination with our New York City Elasticon event on October 9, and we hope many of you will join us in person.
With that, I'll turn it over to Ash.
Thank you, Eric, and thank you all for joining us today. Elastic had an excellent Q1 and a strong start to the fiscal year, delivering 20% revenue growth for the first quarter, surpassing the high end of our guidance. Sales related subscription revenue calculated as subscription revenue, excluding monthly Elastic Cloud grew by 22% and was driven by strength in both our cloud and set offerings. Our growth was supported by the ongoing demand for a highly differentiated search AI platform and our sales team's solid execution, the inherent leverage in our business model and our -- execution continues to fuel our profitability, resulting in a non-GAAP operating margin of 16%. We ended the quarter with more than 1,500 customers spending over $100,000 as enterprises continue to choose Elastic for their search, observability and security needs.
Amid today's rapidly changing landscape and with AI now clearly shaping technology decisions, our Q1 performance directly demonstrates the value Elastic search AI platform delivers to customers. Market demand for our solution has strengthened, contributing to our overall performance this quarter. Our strong market position is further deepened by the operational strength of our sales team with the territory changes we made now for our execution. Our go-to-market momentum is building across the board.
In the U.S. public sector, we are seeing signs of stabilization. In one U.S. public sector win from the core, an intelligence agency adopted Elastic surgerability for their AI-powered enterprise services, consolidating onto Elastic due to our reputation as a trusted mission partner and owing to our AI capabilities, our strategic agreement with the U.S. General Services Administration or GSA which we signed in Q1, an ongoing progress on FedRAMP high certification for Elastic Cloud are helping build positive momentum. Both initiatives are boosting interest among U.S. civilian and defense agencies who aim to modernize all productive and efficient -- with our sales team fully primed for this environment, we are well positioned to execute and capitalize the federal government's efforts to digitally its form an advanced infrastructure with innovative platform.
A year ago, we met our sales segmentation model to build for the future, focusing our team on expanding enterprise accounts and landing high potential mid-marker, measures are proving very effective today. This tactical alignment continues to drive progress in our strategic segment, where we enable generative AI application development and consolidation for our largest customer. For example, global professional services organization expanded their commitment -- migrate to Elastic Cloud in Q1. They rely on Elastic search as their record data to power 40 different internal and client-facing applications. The transition to cloud will enable them to achieve greater open efficiencies and seamlessly access our more research features.
Critically, as they advance their gen AI initiatives for our clients, Elastic's advanced search technology will be instrumental, blocking insights from unstructured data at scale. In Q1, significant activity around AI with many customers choosing Elastic as a runtime platform for building GAI applications, using to database, embedding and reranking model MCP server and other platform capabilities for conversational AI and agenetic applications.
Now over 2,200 cloud customers are using Elastic for Gen AI use cases, over 330 of these customers spending $100,000 or more annually. In Q1, we added more in dollar ACV Elastic Cloud customers using Elastic for gen AI use cases than the prior 2 quarters combined. We are also excited to witness AI-native business being built on Elastic to entirely new business models.
In Q1, an AI-native music company expanded their use of Elastic search upgrading from a monthly cloud subscription to an annual agreement as they see growing adoption of their apps they leverage Elastic to manage vast of song data supporting full text thematic search for millions of users as they continue to grow and launch products, the company chose our search technology for its from speed and ability to scale alongside their rapid growth, which in turn, drives their elastic consumption. Our customers' requirements for speed, scale and relevance drives our continued investment in product features to ensure the query happens in real time -- and reliability.
This quarter, we launched new capabilities to improve performance and cost efficiency of our vector database, now making our better binary quantization or BBQ and Acorn One, a smart filtering algorithm available to all users by default. BBQ and Vector search with Acorn One helped us land a 7-figure expansion deal with a global wholesale provider of machinery parts for Elastic Search and Observability. They rely on Elastic to drive their e-commerce platform, which consists of over 1 million stock items and a database of nearly 50 million SKUs. The retailer is implementing a hybrid search system, which required a platform capable of interpreting natural language queries and performing exact and semantic matches to deliver more accurate and relevant search results. They chose Elastic due to our extensive experience in retail search transformation and our customizable search functionalities, all within one platform.
AI is reshaping the software stack and LLMs are becoming the new operating system for defining business logic. In the past, most software relied on data and data platforms optimized for structured data. Today, LLM operate on all data and need a data platform optimized for all forms of data, structured and unstructured, text in spoken and programming languages, audio, graphs, vectors and more. Elastic is the world's leading vector database Crucially, our continued leadership stems from the foresight that what matters most is relevant in data retrieval irrespective of the language type and messiness of the data. When you get relevance right you provide accurate context to LLMs to do their job, and this accuracy matters even more as a Agentic AI for automating increasingly more complex business tasks. With Elastic Search relevance is our true competitive advantage, for tying a defensible moat around our business. As enterprises build more agents and develop software in new ways, the importance of getting context and search relevance right will only -- this is why we have invested for years in developing our own embedding models, rerank our model, data and strategies and more, all with the goal of being the abstract -- search relevance.
It is this innovation that gives us the confidence to be the leading data retriever and context engineering platform for the AI era. This also forms our asymmetric advantage in the other markets we play in, including observability and security, in anchoring our observability and security solutions in Elastic Search, we fuse the immense power of searching to both and automate the observability and security processes of our use with our AI capabilities like attack discovery, auto import and our AI assistance for observability and security. It is precisely the advanced capabilities that contributed to our security business achieving strong results this quarter.
As AI reshapes the SIM landscape, Elastic Security Unified SIM and XDR into a single AI-powered platform extending protection across customers' data infrastructure and eliminating the need for multiple stand-alone tools. In Q1, 1/3 of our new and expansion wins in security involved competitive displacements. In one such deal from the quarter, 1 of the largest integrated academic health systems in the U.S., selected Elastic security to replace its existing SIM solution.
This 7-figure expansion deal marks the customer making a strategic shift from an incumbent solution towards a more scalable AI-driven security approach, driven by their need for a flexible platform to unify data. Elastic stood out due to our ability to support a broad set of data sources and our market-leading AI features, including attack discovery, demonstrating our leadership in defining the future of SIM. Our consistent vision of solving security as a data problem while driving innovation in AI positions Elastic at the forefront of the market. In doing so, we are being rightly recognized by independent research and we are delighted that Elastic has been named a leader in the Forrester Wave Security Analytics platform in Q1. Our progress in security is further demonstrated by Elastic Security's 100% score in AV Comparatives business security test for endpoint security, where we were the sole participant among 17 vendors to achieve a perfect score in both the real-world protection and malware protection tests, impairing Elastic anti-malware prevention with our ransomware defense and leading SIM features we achieved world-class XDR. And our innovation has not stopped.
Earlier this month, we introduced the Elastic AI SoC Engine or EASE. Many SOC teams today rely on SIEM and endpoint detection and response or EDR solutions that generate valuable alerts but lack mature built-in AI capabilities to conduct investigations integrates with existing SIEM and EDR platforms to connect our advanced AR tools into their environment, allowing for AI-powered alert correlation with attack discovery and access to our AI assistant. Architected as an agentless integration on top of a customer's existing stack, ease is an on-ramp to Elastic Security.
This commitment to AI-driven innovation extends beyond security. Our AI capabilities and powerful analytics also earned us recognition as a leader in the 2025 Gartner Magic Quadrant for Observability platforms for the second year in a row. Elastic's leadership reflects how we are transforming observability from a reactive tool into a solution for real-time investigations through the power of our search AI platform. We are shipping new tools like ease and our recently announced Logs Essentials, a new low-price tier of elastic absorbability within Elastic Cloud services for customers wanting a fully managed offering. Serverless is now generally available on all 3 cloud hyperscalers, including on Microsoft Azure.
Cervalis is gaining traction with contribution surpassing our Q1 targets as more customers adopt this deployment. The Elastic Search platform meets customers where they are with deployment options for cloud, hosted and serverless and self-managed environments. This quarter, I visited India, Australia, Singapore and Japan to meet with customers across numerous industries despite vastly different businesses, every conversation I had revealed the common desire to do more with their data. Enterprises are all looking to leverage their information more effectively.
This consistent feedback reinforces the universal need for powerful data solutions like ours, especially one that is optimized to address the need for search relevance in context in an LLM centric world. In closing, Q1 was an outstanding quarter, fueled by focused execution and strong demand. Our platform is more differentiated than ever, providing us a competitive advantage in Gen AI and platform consolidation across all industries. We have the ability to win in every market where we are playing, and I'm excited to see our progress unfold. This quarter's performance highlights the talent and dedication of our team. Navam and I are truly grateful for the continuous hard work elasticians put in daily. Thank you as well to our customers, partners and investors for their ongoing support and trust.
I'll now turn it over to Navam to review our financial results in more detail.
Thank you, Ash. Q1 was an excellent quarter with solid execution across the business. We exceeded the revenue and profitability metrics we set out to achieve, and our go-to-market team is executing well on all fronts. Our Q1 results provided a promising start to the year. This performance positioned Elastic to enter Q2 and the remainder of fiscal 2026 from a position of strength. Our total revenue in the first quarter was $415 million. We grew 20% as reported and 18% on a constant currency basis. Our sales-led subscription revenue, calculated as subscription revenue, excluding monthly Elastic Cloud was $339 million. growing 22% as reported and 20% on a constant currency basis. Q1 '26 marked the fourth consecutive quarter of strong performance since we made the sales segmentation changes last year. Our sales-led subscription revenue grew 22% in Q2 '25, 18% in Q3 '25, 19% in Q4 '25 and now 22% quarter. These connect results demonstrate the durability -- teams execution.
The revenue performance we saw this quarter was broad-based across both our cloud and self-managed environments. We saw strong customer commitments with key wins across all our solution areas. Both AI and platform consolidation continue to be powerful tailwinds benefiting search, observability and security. As Ash mentioned, we saw competes in security with 1/3 of new and expansion deals in security coming from replacing an incumbent solution. Our traction is further supported by new product releases, including our Elastic AI SoC Engine or EASE which uses AI to enhance -- as you heard from Ash, our team continued to operate effect in all areas, and we saw strength across all our geos. In the U.S. public sector, we're seeing stabilize in the team is fully primed even with ongoing shifts in select lean agencies, the last cost to value proposition remains a compelling incentive for our public sector customers to consider our products as they look to consolidate mission-critical tools and increase efficiency. Our current remaining price obligation, or CRPO, which is the portion of RPO that we expect to recognize in the next 12 months remain solid.
In the end of Q1, CRPO was approximately $156 million and grew 18% year-over-year and 17% in constant currency. CRPO is a useful supplemental measure of commitments when evaluated in conjunction with sales-led subscription revenue. During the quarter, a $100,000 annual contract value term account grew approximately 13% year-over-year. representing approximately 180 net new customers over the past 4 quarters. Quarter-over-quarter, we added approximately 40 new customers and continue to see strong expansion from our existing customer base. Our total customer count reached approximately 21,550 at the end of July. Approximately 80% of our annual recurring revenue from [ 100,000 ] contract value customers.
Moving forward, we will only disclose our total of account annually as this metric does not fully represent our quarterly total revenue performance. On the consumption front, we are happy to see that consumption remains strong. In May, we increased prices on our cloud and self-managed environment and demand for our solutions remain high as we continue to deliver more value to our customers through -- features and functionality.
Now turning to Q1 margins and ability, I will discuss all measures on a non-GAAP basis. We delivered strong profitability across the board with a budget of 79% and an operating margin of [ 16% ].
In Q1, we recognized a onetime credit of approximately $4 million related to our cloud infrastructure costs. The credit caused a onetime gross margin benefit of 1%. Additional margin expansion is representative of the inherent leverage in our model. Our disciplined approach to costs, combined with increasing revenue underpins our strong profitability, further supported by our cash generation.
In Q1, we achieved an adjusted free cash flow margin of 28%. Historically, we experienced quarter-over-quarter seasonality related to the magnitude of the prior quarter's bookings and the collection of those bookings. Keeping these fluctuations in mind, we expect Q2 to follow normal seasonal patterns, representing a sequential decline in FCF. We manage and view adjusted free cash flow on a full year basis. and believe we have the potential to maintain and expand our free cash flow margin over time.
Now for our outlook for the second quarter and the remainder of fiscal 2026. We are pleased with our strong execution in the quarter and the momentum we've built heading into the balance of fiscal 2026. While we continue to operate in a complex macro environment, conditions did not deteriorate to the degree we had factored into our guidance in May. As such, we are raising our fiscal 2026 revenue guidance.
Note that our Q2 2026 assumptions factor in benefit from our price increase, which I discussed earlier. We do not formally guide to adjusted free cash flow. Still for fiscal 2026, we expect to sustain the level of adjusted free cash flow margins that we achieved in fiscal 2025. With these assumptions in mind, for the second quarter of fiscal 2026, we expect total revenue in the range of $415 million to $417 million, representing 14% growth at the midpoint or 14% constant currency growth at the midpoint. We expect non-GAAP operating margin to be approximately 16%. We expect non-GAAP diluted earnings per share in the range of $0.56 to $0.58, and using between $108.5 million and $109.5 million diluted weighted average ordinary shares outstanding.
For fiscal 2026, we are raising our total revenue which improves our expected non-GAAP diluted EPS. We expect total revenue in the range of $1.679 billion to $1.689 billion, representing approximately 14% growth at the midpoint or 13% constant currency growth at the midpoint. We expect non-GAAP operating margin for the full fiscal 2026 to be approximately 16%. We expect non-GAAP diluted earnings per share in the range of $2.29 to $2.35, using between $109 million and $111 million diluted weighted average ordinary shares outstanding. We will continue to provide updates as we move throughout the year. This quarter's performance is a testament to the dedication of our team. Ash and I are thankful for the hard work of our employees to deliver these strong results.
As a reminder, we are hosting our Financial Analyst Day on October 9 in New York City, where we will showcase the power of the Elastic Search AI platform and the business opportunity ahead.
With that, I'll open it up for Q&A.
[Operator Instructions]. The first question from Matt Hedberg with RBC Capital Markets.
2. Question Answer
Congrats on the results, really, really good to see early in the fiscal year. I guess maybe the first one for you, Ash. It's really good to hear about AI relevancy with Elastic Cloud and even the progress on -- thus far. I guess I'm wondering, is there a way to think about what customers -- the uplift of customer spend is when they start to think about growing usage of Elastic to support AI, it really does feel like you guys are becoming a bit of a centrality for that. But a way to kind of think about what this is doing to customer spend usage and maybe it becomes even more evident with serverless.
Matt, to the question. And like you said, our gen AI momentum is something that we feel really, really good about. The customer adoption has been strong. 200 customers in Elastic Cloud now using us for gen AI use cases. What we are seeing is, as customers start to use us for all of these AI applications, these workloads tend to be more compute intensive, and that obviously means that the growth sort of helps. And when we've described it as a tailwind, that's really what it is.
Now the extent to which that growth manifests its workload cost depends upon the kind of data, it depends upon the kind of use case, but these AI competitions tend to take up more CPU, tend to take up more memory and as you know, our consumption -- bias towards that. So it's hard to give a precise number, but what we can say is that there is definitely an improvement in sort of the overall consumption that we see as customers use us for AI.
Now let me repeat that fundamentally, we are still early in the AI journey. So we are seeing some contribution from but we are very early, and I see a long path here by being the core foundation for AI for our customers as they are making multiyear decisions here. This is going to be a tailwind for us for many years to come.
Really here. And then maybe just a quick one for Navam. You mentioned the price -- the May which is noteworthy in the guide. Is there any way that you could help us think about how that's benefiting the year? Just any sort of quantification that would be helpful.
Sure. So first of all, just starting with Q1, you look at the performance, it was based overperformance across consumption and across commitments from both our cloud customers and our self-managed customers. When you think about our normal course of this from time to time, we do price increases, and we've done one last year for self-managed. We did one this year for self-managed Cloud. The increase in Q1 was mostly related to consumption performance and the goodness of our business. But have a benefit from the price increase. And the way you should think about it is a price increase lifts the floor year over. So you benefit year-over-year as you think about the growth from year-over-year, but the majority comes from performance other than price increase.
And then quarter-over-quarter, you more muted effect prices as you've now got a floor that you will grow from. So that's how I think about the price increase. Overall, Q1 was like I said, broad from a performance perspective and macro was in a much better spot than where we had originally assumed. So feeling good about the year.
Next question comes from Koji Ikeda with Bank of America Securities.
This is George on for Koji. I really appreciate it. I have been I wanted to ask on the mix. Just understanding there's a lot of momentum with Gen AI in search. But if you could maybe stack rank or give us a framework to think about how growth across the business is kind of playing out in observability and security as well?
Yes, George, thanks for the question. So this was a really strong quarter with a very broad performance strength that we saw across all solution areas search driven by gen AI continues to be a very strong tailwind for us. But this quarter, we also saw security and the platform consolidation motion that we've been describing work very, very nicely for us. I think one of the stats that I talked about was the fact that 1/3 of the business in security this quarter from competitive displacements, and these deals take some time to do, but we are starting to see that momentum. And this primarily because customers have looked to consolidate on to platforms that tend to see security and observability as a data problem. And we've always done that incredibly well. And it's the amount of data, the complexity of data is growing and it's becoming more and more important to use AI techniques to try and have automation. Even in security and observability, we are seeing our ability to compete and take share really improve, and that's something that we see as a very exciting thing in the future.
Appreciate it. And if I could ask another question here. Navan, since you joined, how would you describe maybe the predictability of the model today versus when you joined? Has it changed much? And if so, why?
Yes. Now I'm about 2 quarters in since I joined. I think the big learning for me is on the sales-led subscription side. And I think I mentioned this during my prepared remarks, the execution and the durability of execution was very strong, right? We had 22% growth a year ago 18%, 19% and 22% again this year. This is a testament to the consistency of growth we're seeing from our sales-led motion across both cloud and self-managed. So I'd say that the underlying execution from the team remains very good and very -- and predictable on the sales-led side, we're a consumption business and that's the place where there is a little bit of unpredictability on what could happen on a quarter-over-quarter basis. Overall, we had a good quarter in Q1, given what we expected. So I feel like we have more data now than we did a quarter ago.
Next question comes from Rob Owens with Piper Sandler.
Great. Really want to drill down on the success that you're seeing on the security front. I think you said 1/3 of it was coming from competitive displacements. And obviously, we're seeing a lot of success, I think, across the board from vendors that are competing for this next-generation SIEM opportunities. So I guess relative to the unlocks that happened this quarter, was there anything in particular that drove that mote? Was it more just how the pipeline set up? As we look forward, maybe what are some of the different key ingredients to for unlock customers that have been with some of those legacy vendors for some time.
Yes, that's a great question. And what's driving that unlock is really a greater and greater appreciation for the fact that City really is a data problem. In the modern landscape today with attacks getting more and more sophisticated, it is becoming incredibly important to make sure that you are bringing in all of the security-related signals analyzing all of them, correlating across all of them and then using AI automation to really try and make it easier for the SOC analyst to identify what the issues might be. And the way we think about it is you miss 100% of the threats and attacks in the data that you don't see. And for that reason, we've always had this mentality of security from a data perspective. Our back end is designed for that. Our AI capabilities are designed for that. And as customers are appreciating this, we are seeing them make multiyear decisions to consolidate onto our platform and that's driving the momentum and win in.
So one of the announcements you made, the Elastic see, the AI SoC engine or ease, as we call, -- what it lets you do is even if you're using a different SIEM solution, it allows you to take all of the alert might be generated in that -- and then use our AI capabilities to identify attacks within alert data, which is incredibly powerful because what that means you don't have to change your current infrastructure you can use Elastic on top of it to get significantly more incremental value, and that becomes a stepping stone sort of an on-ramp times to then eventually displace -- completely take out existing incumbent and move completely to our solution. So it's things like that, that we've been working on that gives a lot of confidence on how this is going to progress in theirs.
Our next question comes from Raimo Lenschow with Barclays.
It's nice to see the cloud reacceleration, but the bigger upside on my model was actually on self-service. Can you speak to the factors there that drove that reacceleration of growth? And what drove that with that like -- you mentioned several times as I take broad-based, but like still there was a very decent step up on the growth rate there.
I'll take that. Just a reiteration that this is the second quarter now where we had very strong self-managed growth and the combination of self-managed growth and cloud growth is what we are going for to reinforce our subscription -- sales-led subscription revenue, right? That's the core piece that the company is focused on to drive growth. So the growth managed this quarter was truly, as I mentioned, broad-based. When you think about where it came from geographically? Where it came from the solutions. It pretty much most of the -- all the geographies and solutions contributed to the self-managed solid cloud. And that's sort of the main benefits of it.
Sorry, I don't know if you were also referring to self-service cloud or our monthly cloud business, I think -- that -- as you know, it's generally been trending around the same way. But to Navam's point, focus really is on the sales-led subscription revenue, which we're very excited about.
Yes. Okay. And then Ash, one follow-up is like all the other vendor, like a lot of the other vendors struggling around AI with kind of how to price it properly, et cetera, but you guys have been on consumption for a long time. Like how does that help you at the moment in customer conversations and driving that AI message from you guys forward?
So the reason why consumption as a metric works incredibly well in AI is fundamentally because it makes it very easy for customers to sort of connect the dots between their usage of our platform and the value that they're getting out of it. So as opposed to a per user price or something that's a flat fee, this really is completely dependent on how much of the AI functionality they use.
And from our experience, that's been something that customers really like. as their usage grows, as they get more value from the usage of the platform, they need to pay more and they're more than happy to pay more. And so we feel that we've got exactly the right mix when it comes to the pricing model and you can see some of that in terms of just the adoption and the growth that we are seeing.
Next question comes from Mike Cikos with Needham & Co.
Congrats on the strong quarter here. First question I wanted to ask is for Ash. And coming back again, I think people are hanging on the word of the new and expansion wins in security were competitive displacements. But if I could try to drive it that slightly differently, I think all of us are aware of the industry M&A that's out there. You're also talking about the sustained execution on the go-to-market front. So I wanted to ask what is the thought around how durable these competitive displacements are when thinking about what's taking place on the security front? I think about the amount of time that these deals might be sitting in your pipeline, they might mature. What is the durability for these continuing to come on a go-forward basis from where we sit today?
Yes, that's a great question. And generally, I'd say is that in the last few years, we've been seeing a constant drumbeat. And it's been growing of customers that are really looking for a change from their incumbent solutions. Most of the intents that have been around really thought about SIM as sort of just the dashboards and the alerts, they didn't think about the effort that is involved in automating the job of the SOCE analyst in things that need to be done to really get easier to the -- attach as to just -- for that reason, we are seeing sort of a secular shift in the migration on to what I would describe as the next generation of platforms and SIM technologies that tend to have a bias towards treating security as a data problem. So we are seeing more and more of these conversations happening.
That's the reason why we introduced capabilities like attack discovery, we introduced capabilities like automatic import which make it easier for people to migrate their workflows over on to Elastic. And most recently, we introduced our Elastic Security AI SOC engine, so you can get started by using our AI functionality on top of your existing SIEM and making that sort of an easy on-ramp to eventually replace your SIEM provider. We feel very good about this being a tailwind for us for many years to come. And I see this as a really good ongoing motion and our sales team is leaning into it.
Terrific. And for the follow-up here, just wanted to cycle back to the net expansion rate for a second. Great to hear in Q1 how you guys outperformed across both consumption and commitments, right? I guess, can you help us think about what's embedded in the guide today? For how that expansion is expected to play out over the rest of the year? Are we still assuming relatively stable net expansion? Or are we starting to get an inkling that this might actually begin picking up?
Yes. Thanks for the question, Mike. So look, we had a good start to the year, a great Q1 with going in macro was in a better position than what we thought in the beginning of the year when we issued our first guidance. Consumption was strong and the commitments were strong from our customers. So overall, as you think about where those commitments come from, a lot of it comes from existing customers as they expand usage from us, and that's driven by our net expansion rate. We don't guide to future net expansion, but as we think about the full year, what we've baked in is more visibility into the year and a better macro situation and also the quarter-over-quarter impacts of price as well as the year-over-year impacts of price have been baked into the guide. We felt good about performance, which is what led to the raise for the full year. And we'd expect net expansion to perform well over the next several quarters as well.
The next question comes from Sanjit Singh with Morgan Stanley.
Congrats on the strong start to the fiscal year. Ash, I wanted to get some help in terms of understanding the impact on some of your most exciting opportunities. And I want to sort of compare and contrast the sort of AI search opportunity, which you guys have been very clear, right, like we've come from POC initial applications into production and then you have to sort of get -- increase the penetration rate in terms of customers' overall application real estate to do that long multiyear journey. You guys have been very clear about that.
When it comes to the SIEM opportunity, though, is the right way to think about it because it's a more established category because there's a lot of brownfield replacement opportunities. Can that be a more immediate impact on growth in self-managed and cloud growth. I just would love to get your comments on doing the comparing contrast between those 2 specific opportunities.
Thanks for the question, Sanjit. So the way to think about displacements that happen, whether it's in security or absorbability, whenever somebody consolidates onto our platform, the first thing to keep in mind is that they have to migrate those workflows over. So typically, that takes a little bit of time. The fastest migrations that we've seen happen within a quarter the longest that we've seen take multiple quarters just because there's actual engineering work involved in moving all of those data streams over. But like you said, these are better understood techniques and these are better understood templates for that. So we have invested a bit both from the product side. I talked about -- import, but also from our services team that has experience in doing these kind of migrations.
The most important thing to think about though is we are seeing ourselves as a beneficiary of this wave of migration and sort of moving to the next-gen SIEM that's happening within the broad market. And our goal is to take as of that share as possible -- and so I don't see this as just a onetime thing, but this is, I believe, something that we should benefit from for not just several quarters but several years to come.
That's great color. On just the federal business, and that was a sort of a weakness last quarter. It sounds like things are stabilizing. As Fed comes into its fiscal year-end, what are some of the assumptions that you're baking in for fiscal Q2 and the government's fiscal year and coming up next quarter.
Maybe let me just touch upon that and then I'll ask Navam to add to it. The first thing I'd say is we are definitely seeing sort of stabilization in the U.S. public sector. 6 months ago, what we saw was with the new administration settling in with Dodge and everything, like there was a lot of movement, the environment was very dynamic. That has settled. It's a much more stable environment. And our sales team knows how to execute very well within that environment, especially given that the value that we offer for our platform is incredibly high, and it's very well received by our customers in the public sector. So we are really excited about that.
I will say that Q2 has typically like we, even in past years, have not seen like a big federal flush or anything of that sort. So from a public sector standpoint, Q2 hasn't necessarily been sort of outlying quarter for us. So just keep that in mind. But let me -- I don't know if Navam, you have anything else to add to that.
I think Ash got most of my points, but when we gave our initial guide in May, there was a lot of uncertainty around what would happen with the U.S. public sector, specifically the civilian agencies -- did expand to more of the public -- and of the rest of sort of the geos. It clearly did not occur. -- and the U.S. public sector, while there is some ongoing impacts have mostly stabilized and as said, our team is executing well there. And our products are a good fit for what they're to achieve. So we've factored that into our second quarter guide. And as Ash mentioned, there's no real flush that we're factoring in there, and that's not something we'd expect.
Next question comes from Kash Rangan with Goldman Sachs.
I'll add my congrats on the quarter. It looks like everything is coming back together for you guys, just the way you would like it. Pardon me, as this feels like a redact from a few years ago, but I would ask you this that listen to the call, there is an AI search aspect to it. There's a security aspect to it. There's an observed with the aspect to it. What is it that makes Elastic to the end of the day? What is the message to your customer base, what is the unifying thread that makes this machine a predictable growth machine that is ready for the next 4 to 5 years?
That's a great question, Kash, and that's the kind of redacts question that I always appreciate Fundamentally, we think of ourselves as a search AI company. And like I've described in our script saw is our ability to take in all kinds of data, especially messy unstructured data and really gets you the most -- the most relevant information out of it.
And as we've described in the context of AI, as you think about companies, prices, government agencies, what have you building a genetic applications in the criticality of getting the context right is so high, especially as you are building more and more sophisticated agents and that search relevance is absolutely critical. And we are seeing that across the board. And it's not just about having a vector database. It's about so much more than that.
So the way we think about our role in this ecosystem is to be that data retriever context engineering platform, making it possible to get exactly the context in real-time to these large language models. That's helping us in our search business. But if you then think about purity and you think about observability, you really recognize that these are fundamentally at the end of the day, data problems. You're dealing with complex logs, you're dealing with -- application logs incredibly messy. And if you have to analyze them at scale in real time using AI, we have the best platform for that. So for us, that core search AI is the secret sauce, that's what's going to continue to drive our progress and our growth. And that's why I'm very confident in the long-term growth and strength of our business.
Next question comes from Howard Ma with Guggenheim Securities.
I guess building on Kash's question on use cases. When you analyze your quarterly performance by use case growth in Search continued to accelerate. I believe that's been the trend. And part 2 is, as gen AI use cases become more mature, they also require more data to be monitored. So is that leading to more observability cross-sell or not necessarily?
Yes. So that's a question. So what I'd say is that our search business continues to be incredibly strong because of the gen AI tailwinds. And that's what's so exciting about what's happening here. Like I said, this quarter, we also saw a lot of platform consolidation and in security, I gave some of the examples because at the end of the day, our strength in AI is helping compete better and take more share in observability and security. And that's the nice part of it. So fundamentally, AI expands the TAM for our search business. And in the other areas, it allows us to compete better.
Now to your point about what's happening overall in the market, we absolutely see that more and more applications, especially these AI-centric applications are being built. But we are still in the early days. You take any enterprise, you're talking about a handful or at most dozens of applications and you compare that to the total application landscape that exists in any organization, it's in the hundreds of thousands. So we are still in the early days. AI has a lot of legs ahead of it. I think this is a multiyear journey where there's a lot of excitement for the future. And the fact that we are getting baked in into the platform, into the infrastructure where our customers are using us as this core context engine just makes me feel very good about the long-term prospects for our business.
Great. And as a follow-up, you've made some significant go-to-market improvements over the last year. It's a question for Navam. Sinova, you were not at elastic this time last year, obviously. But when you look at your data on key metrics like sales capacity and productivity and coverage ratios, the number of large deals in the pipeline. So things like that, I'm curious how you would characterize your optimism for the rest of the year versus the stellar quarter you just posted.
Yes. Thanks for the question, Howard. So like I said, I feel good about the year. And the reason I feel good about the year is about the durability of our team's execution. And that is reinforced by the underlying data we're seeing in terms of how the sales team has been being able to perform from a subscription revenue less -- sorry, a sales-led subscription revenue perspective. And the reason they're able to do that is they've had strong performance from a productivity perspective and our capacity additions are working. So that's sort of the underlying drivers as to why our sales-led growth has been durable. And we've had a great start of the year, and I feel optimistic about the rest of the year.
The next question comes from Tyler Radke with Citi.
Yes. You saw pretty good current RPO bookings this quarter, and you also talked about some pretty impressive million-dollar customer adds on AI. Can you just talk about the use cases you're seeing and sort of what drove that step-up versus the last couple of quarters?
Yes. Fundamentally, what we are seeing is that our customers are making meaningful commitments to our styler, I think that sales-led motion, as Navam mentioned, has been continuing to do well. On the AI side, it's an area that we've been focused on to make sure that our largest customers our highest propensity to grow customers are really adopting our AI technology. And as we've been driving that, you're seeing some of this momentum. So from my perspective, like my goal is to make sure that every single one of our customers, existing customers and new customers, we lead with our AI functionality. We are getting better and better at it. And my belief is that as more of our customers adopt as they build more complex applications these complex applications don't have just one call to a vector database, but they have like multiple different interactions there are multiple moments that they have to do retrieval and context engineering. And each of those drives consumption, as you know. So for our consumption-based model, the more we are embedded into every one of their AI applications the better the traction that we see, and that's what we are focused on. That's what we are starting to see.
Great. And a follow-up on the side. I think based on the list that we saw out there, it looked like the monthly cloud price went up by about 5%. Was that similar across the business. I think there was price increases on the annual as well as the self-managed side of the equation.
Yes. So we did a price increase at the beginning of the year. Tyler, as you know, our business model is such that we don't sell discrete products. So for us, the way as we add more and more functionality from time to time, we will increase our prices. Just to remind you, we did something similar for our self-managed products last year. We had talked about it at the beginning of last year, and we also did a price increase at the beginning of this year, like you mentioned. So for us, is just the normal core business to do these from time to time, but it was across both cloud and manage.
Next question comes from Brian Essex with JPMorgan.
Congratulations from me on the strong results. Maybe one for you, Ash. With hearing, particularly on the security side, the focus on and leveraging enhanced visibility, real conduction on streaming data, which I think you addressed but would love to -- what we're also hearing is a focus on more efficient data -- leverage AI and storage of more efficient storage data. And I'm wondering, are you seeing that at all competitively and how you might be positioned to address that need?
Yes. I mean we have been driving that for many years, right? So one of our greatest strengths is our ability to a massive amount of data at scale and then store that data incredibly efficiently. So several years ago, we introduced capabilities that allow us to take advantage of object storage, really, really cheap storage and through life cycle management, sort of manage how much data you retain on disk versus how much you store in object storage and really bring down the costs of both data storage and data analysis.
That's been one of the biggest drivers for customers to move on to our platform because they see that kind of efficiency gain and that efficiency improvement, even 2 quarters ago, we introduced a capability called Logs DB that allows you to do even more aggressive get a compression and management log data to store -- bring down the cost of what it takes to store log data. And these kinds of capability -- constant stream innovations from us. So it's been a reason why we keep winning. And we don't stop on there. My firm belief is that given the rate at which data grows continuing to drive these kinds of innovations is going to be a reason why we'll continue to win.
The next question come from Jake Roberge with William Blair.
I just wanted to follow up on the go-to-market front. You talked about execution improving and the change is starting to bear more fruit. Just in terms of -- where do you see the largest opportunities remaining? And what inning do you feel like we're in with that overall transition?
Yes. I mean, maybe I'll address this and then I want to add to it. From our perspective, there is so much opportunity in the enterprise and mid-market segment where our -- focused changes in territory alignment that we made -- decision that we made a little over a year ago what they were all out was to have our teams more focused on the Anderson strategic segment and then to go after greenfield territories more effectively. And we are really starting to see the benefits of that. Those are the kinds of changes that are really, really important as you get from $1 million into $2 million and $3 million and on. And now we are starting to see the benefits. So we've got a long ways to go. Like I grew up in India, so not much of a baseball player. But what I'd say is that we have the ability to build a true generational company here, keep driving strong growth for many years to come. And our current sales model, our current sales segmentation gives us the ability to continue to do that.
Yes. And I would add to that. I mean we are playing in exceptionally large TAM markets in observability, security and search. And we're just starting to see AI tailwinds that are taking root in those markets, right? So to Ash's point, to put an inning on it, but it is early days in the journey.
Okay. That's helpful. And then I know it's still early, but can you talk about the early feedback you've gotten for the new serverless solutions and just how that migration process has been progressing this year?
Yes. So we obviously have internal milestones that we set for ourselves, and we have been running ahead of those milestones. So that makes me feel really good. The early feedback in terms of the product itself has been really good. Now where we are is, I'll remind everybody still pretty early in the overall movement here when it comes to serverless. We are now GA in all 3 hyperscalers, but the total data center footprint that we have for serverless is still relatively small compared to our cloud -- elastic cloud hosted footprint.
And our goal through this fiscal year is to do the build-out of our serverless make it available in all the data centers and the majority of the data center where we do cloud business today. So as we do that, you will -- we continue -- we expect to continue to see more and more adoption of serverless because customers prefer to have their data in local data centers, if you will. And in the coming years, I'm very corn that serverless is going to be the prime way in which our customers use Elastic Cloud.
The next question comes from Brent Thill with Jefferies.
Navam, just on the guide, 20% growth in Q1 and guiding the below mid-teens growth or mid-teen growth for the year, I guess that drop off in the growth, I guess what are you dream in? Is it -- are there other factors that you're on unclear about that you're not putting in or more is, just trying to bridge the great start to the tail off on the growth throughout the year.
Yes, Brent, here's how I would consume the guide was a great start to the year. We had -- into the year we laid out the assumptions around the dynamics of macro that we baked into the guide, which led to the low end and the high end of the guide that we gave the last quarter. We are in a much more stable macro environment. While it -- while there's still a complex environment out there, is it feels much more stable than we anticipated compared to Q1. And you add to that, that there was a broad-based good execution led Q1 number that came to us this last quarter. So overall, we beat the Q1 number by a good amount and we raised the full year and that raise is meant to signify the better position we're in and the more confidence that we have in the year.
Okay. Great. And Ash, maybe I'm mistaken this, you seem to be pretty excited about the security business. You mentioned it many times. I guess was there something in the quarter that triggered in terms of breadth of transactions, some big deals. Was there something that maybe or maybe I'm misreading this and reading into the number of times you mentioned security too much. But just curious if you could pull that thread.
I wouldn't call out -- obviously, in any given quarter, there are -- the deal flow, there might be more deals in 1 solution area versus another that kind of happens from quarter-to-quarter. What I'd say is that my enthusiasm in security has been high for a while now. We've been seeing a lot of traction with customers moving onto our platform, consolidating onto our platform. We've been doing competitive displacements for some time. One of the things to be aware of is displacements like these deals take time. It's not a 1- to 2-quarter motion. It typically takes several quarters.
But that's also why we've been investing in capabilities like automatic import. We recently announced our AI SoC engine that can be used on top of other SIEM products. So we're doing a lot to make it easier for customers to make that migration journey as easy as possible. So I expect that the momentum that we are seeing on the security side is one that will continue to build over time. and I feel really, really good about it. And if there was just a higher count this quarter, it was just because I'm truly, truly excited about the business across the board.
Our last question comes from Patrick Colville with Scotiabank.
I guess I just want to circle back to the price increase because in our field work heading into the quarter, what we were picking up as it was about a 5% price increase across cloud and self-managed. And so I guess, is that quantum roughly right does it apply to all customers? And if we like exclude the price increase, is that like to work out an underlying number, is that logic correct? Or should we not be thinking about the business that way.
Yes. I'd start off by sort of thinking about the business slightly differently, which is, from time to time, the business increases prices. This is something we did last year, and it's somewhat ordinary course of business as we add more features to our product. And to Ash's point earlier, we don't have distinct SKUs. We just add more functionality to the product, and that leads to a more valuable product to our customers. And we reflect that by -- from time to time evaluating prices and increasing as necessary. There's discounting that factors in as well. So you can't really say, hey, it was an x percent increase across the board on every customer.
But roughly, that quantum would be on the rough order of magnitude accurate as you portrayed it. Now how it relates to the performance as you think about it is price increases offer a durable baseline that you grow from. So as you go from one year to the next, you're almost -- you're lifting that baseline that you grow from there. So you'll see a year-over-year benefit. But quarter-over-quarter, you're just going to see a normal benefit and not something that's related to prices. So that's how you should think about price increases, the Q1 performance, like I said, was broad-based. So while we did have benefits to price increase and price increase is something we do from time to time, a lot of the performance. In fact, the majority of the performance came from good solid execution and good consumption from our customers.
Crystal clear. Thank you, Navam, and thank you, Ash, and congrats on a strong start to fiscal first quarter.
This concludes our question-and-answer session. I would like to turn the conference back over to Ash Kulkarni for any closing remarks. Please go ahead.
Thank you, and thank you all for joining us today. I'm extremely proud of our excellent results and more excited than ever about the opportunity ahead as we build a generational company. Thank you.
The conference has now concluded. Thank you for attending today's presentation. You may now disconnect.
Elastic NV — Q1 2026 Earnings Call
Financial data from Elastic NV
Revenue
Revenue is the sum of all sales generated by a company, e.g. for its products or services.
Revenue (TTM) metric explainedDirect Costs
Direct costs are the costs incurred directly in connection with the manufacture of the product or service.
Gross Profit
Gross Profit indicates how much of the revenue remains in the company after deducting direct production costs. If the percentage share of sales is calculated, this is referred to as the gross margin.
Gross Profit metric explainedSelling and Administrative Expenses
Selling, general and administrative expenses (SG&A) include all expenses for marketing and sales as well as the general administration of the company.
Research and Development Expense
Research and development costs (R&D) provide information on how much the company invests in the research and development of its products. The costs are particularly interesting as a percentage of revenue and in comparison to direct competitors.
EBITDA
EBITDA (Earnings Before Interest, Taxes, Depreciation and Amortization) is the company's earnings before interest, taxes, depreciation and amortization. The EBITDA margin is calculated as a percentage of sales.
Depreciation and Amortization
Depreciation represents reductions in the value of the company's assets (e.g. due to wear and tear on machinery).
EBIT (Operating Income)
EBIT (Earnings Before Interest and Taxes) is the company's profit before interest and taxes, also known as the operating income. The EBIT Margin is calculated as a percentage of sales at
.
Net Profit
Net Profit represents the profit or loss after deduction of all costs.
Net Profit metric explainedStocksGuide Premium
| Jul '26 |
+/-
%
|
||
| Revenue | 1,802 1,802 |
16%
16%
100%
|
|
| - Direct Costs | 441 441 |
15%
15%
24%
|
|
| Gross Profit | 1,361 1,361 |
17%
17%
76%
|
|
| - Selling and Administrative Expenses | 814 814 |
15%
15%
45%
|
|
| - Research and Development Expense | 455 455 |
18%
18%
25%
|
|
| EBITDA | -12 -12 |
35%
35%
-1%
|
|
| - Depreciation and Amortization | 13 13 |
23%
23%
1%
|
|
| EBIT (Operating Income) EBIT | -25 -25 |
15%
15%
-1%
|
|
| Net Profit | 376 376 |
552%
552%
21%
|
|
In millions USD.
Don't miss a Thing! We will send you all news about Elastic NV directly to your mailbox free of charge.
If you wish, we will send you an e-mail every morning with news on stocks of your portfolios.
Elastic NV Stock News
Company Profile
Elastic NV engages in the provision of open source search and analytics engine services. It offers Elastic Stack, which is a set of software products that ingest and store data from any source, in any format, and perform search, analysis, and visualization. The company was founded by Shay Banon, Uri Boness, Steven Schuurman, and Simon Willnauer on February 9, 2012 and is headquartered in Mountain View, CA.
StocksGuide Premium
| Head office | Netherlands |
| CEO | Mr. Kulkarni |
| Employees | 3,921 |
| Founded | 2012 |
| Website | www.elastic.co |


