Executive Summary
For site reliability engineering (SRE) and IT teams, every minute of unresolved downtime carries a cost, whether in revenue, customer trust, or the operational bandwidth consumed by reactive issue resolution. As AI workloads and tool sprawl drive telemetry volumes from thousands to hundreds of millions of signals, SRE and IT teams face mounting pressure to maintain uptime, accelerate mean time to resolve (MTTR), and manage increasingly complex distributed systems all while the cost and complexity of doing so grow exponentially. SRE and IT leaders need a unified platform for agentic observability that autonomously detects, investigates, and resolves incidents with logs at the center of every investigation and signals correlated in real time, without the cost compromise. By unifying telemetry and enabling AI to reason in real time, teams can drive faster resolution at a fraction of the cost.
Elastic Observability is an end-to-end observability and search platform covering log analytics, infrastructure monitoring, application performance monitoring (APM) and distributed tracing, digital experience monitoring, metrics monitoring, and LLM observability through a single pane of glass. With more than 550 integrations across clouds, CI/CD, databases, and native OpenTelemetry support, Elastic Observability can ingest high-volume telemetry from any source. Root cause analysis uses agentic AI, ML-based anomaly detection, and log categorization for investigations. Available across various environments, it can accelerate problem resolution, automate noise suppression, and optimize storage economics through columnar storage, smart compression, and flexible lifecycle and tiering strategies. Elastic Observability can help SRE teams identify and prevent incidents before they impact the business, which can lead to gains in operational efficiency and system performance.
Elastic commissioned Forrester Consulting to conduct a Total Economic Impact™ (TEI) study and examine the potential return on investment (ROI) enterprises may realize by deploying Elastic Observability.1 The purpose of this study is to provide readers with a framework to evaluate the potential financial impact of Elastic Observability on their organizations.
Key Statistics
362%
Return on investment (ROI)
$28.1M
Benefits PV
$22.0M
Net present value (NPV)
To better understand the benefits, costs, and risks associated with this investment, Forrester interviewed five decision-makers with experience using Elastic Observability. For the purposes of this study, Forrester aggregated the experiences of the interviewees and combined the results into a single composite organization, which is an industry-agnostic consumer-facing organization with 25 million customers and $10 billion in annual revenue.
Interviewees said that before using Elastic Observability, their organizations operated a fragmented monitoring landscape of different tools with siloed telemetry across logs, metrics, events, and traces, which slowed incident triage and extended MTTR for major incidents. These limitations resulted in high costs associated with legacy platforms and telemetry storage, operational silos, and mostly reactive incident management.
After the investment in Elastic Observability, interviewees eliminated fragmented tools and gained centralized, full-stack observability. Using AI-driven analysis, their teams could take a proactive stance on prevention and remediation efforts. Key results from the investment include reduced mean time to detect (MTTD) and MTTR — helping their organizations proactively mitigate downtime events that previously impacted customers — and reduced costs associated with legacy tools and prior vendors. As such, interviewees improved transparency and control and scaled to meet the observability needs of rapidly expanding hybrid cloud and microservice environments without taxing internal operations or technology budgets.
Key Findings
Quantified benefits. Quantified benefits for the composite organization include:
-
Up to a 75% reduction in system downtime. Adopting APM and AI functionality and bringing infrastructure and cloud monitoring together proactively mitigate the impact and reduce the volume of system downtime events, especially those that previously impacted organizational revenue. Protecting contractual SLAs by preventing outages that impact customers enable the composite to reduce system downtime. This improves the composite organization’s business resilience by $15.2 million over three years.
-
Up to a 95% reduction in time spent monitoring and resolving incidents for SREs. Reducing system downtime events by 65% to 75% annually helps the composite avoid revenue loss. The included tools, such as native AIOps, machine learning, agentic AI, and automation tools, also provide efficiencies for the teams previously responsible for monitoring dashboards and telemetry data, improving issue resolution timelines. A team of 15 SREs achieve 95% time savings, supporting the reallocation of more than $1.8 million of funds for the organization by Year 2 of the investment. In total, shifting SRE bandwidth from reactive issue resolution to strategic initiatives further improves business resilience worth $3.5 million to the composite over three years.
-
Up to a 55% reduction in time spent on application deployment. Application developers responsible for testing, deploying, and debugging applications in the prior environment experience a shift with Elastic Observability as it enables them to embed insights from telemetry data within the application development lifecycle. As a result, developers build incident prevention measures into development cycles earlier to further reduce incident volumes and associated remediation efforts on an ongoing basis. Additionally, more proactive remediation and prevention from the SRE team results in fewer incidents overall and therefore less time spent by application developers on related efforts. The team of 339 developers experiences up to 55% time savings, resulting in 116,000 hours redirected to more value-add activities, such as innovation efforts, by Year 3. Over three years, total developer hours saved are worth $6.6 million to the composite organization.
-
Up to a 70% reduction in observability infrastructure costs. In the prior environment, use of multiple vendors led to a fragmented tool set, causing infrastructure costs to soar for log storage and tool licensing. With Elastic Observability, the composite organization receives increased transparency and insights as well as data tiering to make better-informed log storage decisions and reduce overall storage costs by up to 70% in Year 3. Additionally, the composite organization eliminates four observability tools by Year 3. The total infrastructure optimization savings are worth $848,000 to the organization over three years.
-
Up to a 0.6% improvement to customer retention rates. The composite organization prioritizes onboarding customer-facing and critical systems to Elastic Observability for observability from Year 1. Consequently, its customers benefit from improved application performance and improved time to value for application go to market. In return, the composite organization sees an improvement in customer retention attributable to Elastic Observability. The organization retains up to 120,000 additional customers with Elastic Observability by Year 3. With each customer averaging $100 in revenue for the organization, the increased customer retention is worth $1.9 million over three years.
Unquantified benefits. Benefits that provide value for the composite organization but are not quantified for this study include:
-
Including LLMs in observability. The organization seeks to extend observability to LLM components within its environments. Elastic Observability provides observability coverage for AI models as part of the product. By adopting these capabilities, the organization benefits from performance and efficiency improvements across more of its environment.
-
Establishing more consistent and predictable observability costs. The organization benefits from more transparency into development cycles and log usage, allowing it to better control log storage tiers and volumes as well as the associated costs.
-
Improving customer service. In addition to customer retention, the organization qualitatively finds that customer service levels improve. Customers experience fewer incidents, and the organization meets customer queries with more relevance and data to help solve problems efficiently, leading to improved customer service levels and further driving customer retention and stickiness.
-
Complying with governance and regulatory requirements. The organization must adhere to strict governance and regulatory requirements related to system performance and data retention. The transparency enabled with Elastic Observability ensures that the composite can meet these requirements effectively by facilitating reporting workflows during audits to save time.
Quantified costs. Quantified costs for the composite organization include:
-
Platform licensing. The organization pays a subscription fee based on data ingestion volume and platform usage rather than per-user licensing. These costs total a three-year present value of $4.3 million.
-
Deployment and training. The organization incurs internal labor costs to support initial deployment, integration, and enablement across observability, application, and infrastructure teams. The labor investment has a present value of $639,000.
-
Optimization and administration. A portion of engineering resources are dedicated to managing and optimizing the Elastic Observability environment on an ongoing basis. This commitment has a total present value of $1.1 million.
The financial analysis that is based on the interviews found that a composite organization experiences benefits of $28.1 million over three years versus costs of $6.1 million, adding up to a net present value (NPV) of $22.0 million and an ROI of 362%.
75%
Reduction in system downtime with Elastic Observability by Year 3
Benefits (Three-Year)
The Elastic Observability Customer Journey
Drivers leading to the Elastic Observability investment
Interviews
| Role | Industry | Region | Elastic Observability Users | Elastic Coverage |
|---|---|---|---|---|
| Senior director, application operations | Fintech | North America | ~438 users across application operations, infrastructure, development, and support teams | 75% of 120 applications on full APM with remaining in maintenance mode |
| AI for IT operations (AIOps) leader | Financial services | Asia | ~27 users across SRE, AIOps, and monitoring teams |
20% of 400 total applications use the AI capabilities Log tool covers all OpenShift workloads and some monolithic systems (2 to 3 TB of data) |
| Director of software engineering | Telecommunications | North America | 70 to 80 data scientists |
20 to 30 PB annually of stored logs 35% of logs ingested from 3,000 to 4,000 applications |
| Executive VP and head of technology | Media | Asia | 130 to 140 developers |
5 to 6 TB annually of stored logs 250+ applications |
| Observability director | Consumer products manufacturer | North America | Not specified |
13.7 TB of telemetry data stored per month 60 applications |
Key Challenges
Forrester interviewed decision-makers who have experience using Elastic Observability at their organizations. Interviewees cited complex and large-scale infrastructure and application environments that included hybrid cloud deployments and microservices that further contributed to common challenges related to observability, including:
-
Fragmented and siloed observability tools. Before Elastic Observability, interviewees’ organizations relied on different monitoring and observability tools across applications, infrastructure, and platforms. Telemetry data was distributed across multiple systems, making it difficult for teams to correlate logs, metrics, events, and traces during incidents. This fragmentation increased investigation time and limited end-to-end visibility into system behavior. The senior director of application operations at a fintech organization said: “The reason we put Elastic in place was because there was a gap in our tools and environments. Identifying logs [and] finding the right logs to troubleshoot a problem took a very long time, which extended MTTR.” Additionally, prior tools were difficult to use, which blocked nontechnical resources from accessing the associated data and analysis. The senior director of application operations at a fintech organization said, “[With our prior observability tool], you needed to know how to write queries in order to conduct any analysis using the observability data.” This restricted the value of such analysis to the teams directly responsible for incident prevention and remediation.
-
Difficulty scaling due to the cost of tools and data. As organizational application footprints and telemetry volumes continued to grow, expanding observability coverage required adding more tools, infrastructure, and licenses. Additionally, some organizations were growing by acquisitions, where they inherited additional fragmented legacy systems that increased the complexity of the environment. Consequently, spiraling costs and manageability constraints made it difficult to efficiently scale to meet monitoring needs. High data storage costs also encouraged organizations to drop historical content, which created additional visibility gaps.
-
Reactive incident management. Before Elastic Observability, interviewees’ organizations primarily identified incidents after they had already impacted the business, resulting in a reactive response model. Major incidents often required large, cross-functional bridge calls and took longer to resolve. Limited correlation across tools made it difficult to quickly identify root causes and reduce the duration of outages. The AIOps leader at a financial services organization indicated that before Elastic Observability, their organization only had traditional alerting tools in place, which left them in a reactive position to events and incidents.
-
Customer attrition. For organizations in customer-facing industries or with customer-facing technologies as part of their observability environment, incidents and events often impacted end-customer experiences. Some interviewees felt the pressure from customer SLAs and feared customer attrition if they did not meet those requirements. Other organizations faced industry regulations that served up penalties and other repercussions for downtime. The AIOps leader at a financial services organization said, “We are in a highly regulated industry; we cannot have more than 4 hours of downtime in a year.” Damages from regulators impacted brand and reputation, which also contributed to customer attrition.
Investment Objectives
The interviewees’ organizations searched for a solution that could:
-
Unify logs, metrics, events, and traces in a single platform.
-
Cost-effectively scale observability coverage.
-
Provide easy access to dashboards and portals for nontechnical users.
-
Benefit from a progressive product roadmap that includes AI components and agentic AI.
-
Reduce MTTR and enable proactive incident detection.
Composite Organization
Based on the interviews, Forrester constructed a TEI framework, a composite company, and an ROI analysis that illustrates the areas financially affected. The composite organization is representative of the interviewees’ organizations, and it is used to present the aggregate financial analysis in the next section. The composite organization has the following characteristics:
-
Description of composite. The global, multibillion-dollar B2C organization services a large customer base of 25 million and has 50,000 employees. The average revenue per retained customer is $100.
-
Deployment characteristics. The composite organization has a large microservices environment with 1,000 applications that include critical systems, customer-facing applications, and internal applications. The organization begins using the solution in Year 1 following a six-month implementation period and migrates 50% of the applications to Elastic Observability for observability. Implementation scales over the three-year investment to reach 75% of applications by Year 2 and 90% by Year 3.
KEY ASSUMPTIONS
-
$10 billion revenue
-
50,000 employees
-
25 million customers
-
40 TB of telemetry data stored annually
-
1,000 applications across environment
-
90% of applications onboarded to Elastic Observability by Year 3
Analysis Of Benefits
Quantified benefit data as applied to the composite
Total Benefits
| Ref. | Benefit | Year 1 | Year 2 | Year 3 | Total | Present Value |
|---|---|---|---|---|---|---|
| Atr | Improved business resilience from fewer revenue-impacting incidents | $5,698,633 | $6,136,989 | $6,575,346 | $18,410,967 | $15,192,621 |
| Btr | Faster problem-solving from SRE productivity | $1,374,797 | $1,451,174 | $1,451,174 | $4,277,146 | $3,539,422 |
| Ctr | Application development and deployment efficiency | $1,883,482 | $2,663,769 | $3,583,426 | $8,130,677 | $6,605,999 |
| Dtr | Infrastructure optimization | $261,000 | $346,500 | $432,000 | $1,039,500 | $848,204 |
| Etr | Increased customer retention (Greater business outcomes through growth in customer base) | $560,000 | $800,000 | $960,000 | $2,320,000 | $1,891,510 |
| Total benefits (risk-adjusted) | $9,777,911 | $11,398,432 | $13,001,946 | $34,178,290 | $28,077,756 |
Improved Business Resilience From Fewer Revenue-Impacting Incidents
Evidence and data. Before Elastic Observability, interviewees experienced the real-time impacts of poor application performance, which contributed to revenue loss. They said that with Elastic Observability, APM traces and anomaly detection proactively prevented performance degradation or remediated the impacts, thus reducing MTTD and MTTR, improving overall business resilience, and avoiding revenue loss.
-
The senior director of application operations at a fintech organization attributed the improvement in business resilience to proactive preparation for known disruptive events, such as traffic spikes, that previously led to system downtime. They said: “With APM, you can see when, for example, online ordering has spiked. Additionally, if you go down the stack, you can see which system or platform is causing the problem. Once we’ve identified where the problem originated, we can get tickets open and start resolving the issue. I think the ease of access to logs in APM are really the area that we focused on implementing with Elastic Observability and that have driven success for us.”
-
The executive VP and head of technology at a media organization indicated that their organization saw a 20% reduction in overall incidents, but 60% fewer customer-impacting incidents — including fewer service level 2 and 3 incidents — after implementing Elastic Observability.
-
The senior director of application operations at a fintech organization said that their organization saw 70% to 80% fewer cloud incidents with Elastic Observability, which helped improve system performance and provide better business resilience. They noted: “I would say in the cloud, our recovery time has reduced significantly. Elastic has helped us steady the cloud and get more resilient by identifying single points of failures along the journey. It has all been reactive, but it helps us pull data to understand where our scaling wasn’t appropriate and where the scaling was causing consistent problems. I’m going to say about 75% of the problems we have currently have shifted to our in-store devices versus any of our cloud applications as they were previously.”
-
The director of software engineering at a telecommunications organization said: “Being more proactive and prescriptive means fewer incidents because we are avoiding the incident altogether. I would say that in the first year alone [with Elastic Observability], we avoided 250 catastrophic incidents, and I estimate we avoided losses of $1 billion to $2 billion if even four of those incidents had come through to fruition. Additionally, we avoided 1,000 smaller events that could have been application, network, or call center related.”
-
The same interviewee also cited challenges in their prior observability practices that inhibited tracing and prolonged mitigation efforts. They said, “In our prior observability process, we either were not collecting logs, in which case we couldn’t do any trace or debugging and would have to create a newer version of an application or an update that does collect logs, or we were collecting logs, but we did not have a lot of dimensions. The coverage was not there, so we had blind spots. Now, with Elastic Observability, we have anomaly detection techniques where an agent captures as much information as possible, including going through the checklist of the different issues, as well as some basic dashboard of automatic alerts that guide us to detection and remediation more efficiently.”
-
The director of software engineering at a telecommunications organization cited value in improved root cause analysis with Elastic Observability: “We can do root cause analysis and log searches to reduce detection and resolution times by 30% to 35%. With Elastic, we have templates and a relationship with Elastic where we can learn from what they’ve seen from other clients, and that also helps us detect issues right away based on learned patterns.”
-
The observability director at a consumer products manufacturer reported reducing false-positive alerts by 79% after implementing the correlation, categorization, and anomaly detection capabilities of Elasticsearch (Elastic’s open source search, analytics, and AI platform), which reduced the engineering time spent triaging nonactionable alerts. With Elastic Observability’s ML-driven log categorization and anomaly detection, their command center suppressed more than 25,000 false-positive alerts annually, reducing noise and alert fatigue and enabling the team to recoup time to focus on meaningful incidents.
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
Previous system downtime stemmed from major incidents that impacted customers and totaled 96 hours annually.
-
With Elastic Observability, the organization reduces such system downtime events by 65% in Year 1, increasing to 75% by Year 3. With an annual revenue of $10 billion and an operating margin of 10%, the risk-adjusted impact of the system downtime in terms of revenue loss avoidance totals $5.7 million in Year 1, which grows to $6.6 million by Year 3.
Risks. The scale of this benefit may vary by organization based on:
-
The size and industry of an organization (e.g., annual revenue and operating margin).
-
The status of downtime in an organization’s prior state (e.g., the hours of downtime that impact customer-facing applications and supporting infrastructure).
Results. To account for these risks, Forrester adjusted this benefit downward by 20%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $15.2 million.
Up to 75%
Reduction in system downtime with Elastic Observability
Improved Business Resilience From Fewer Revenue-Impacting Incidents
| Ref. | Metric | Source | Year 1 | Year 2 | Year 3 | |
|---|---|---|---|---|---|---|
| A1 | Previous system downtime (hours) | Composite | 96 | 96 | 96 | |
| A2 | Reduction in system downtime with Elastic Observability | Interviews | 65% | 70% | 75% | |
| A3 | Total annual revenue | Composite | $10,000,000,000 | $10,000,000,000 | $10,000,000,000 | |
| A4 | Revenue loss per hour of system downtime | A3/(365*24) | $1,141,553 | $1,141,553 | $1,141,553 | |
| A5 | Operating margin | Composite | 10% | 10% | 10% | |
| At | Improved business resilience from fewer revenue-impacting incidents | A1*A2*A4*A5 | $7,123,291 | $7,671,236 | $8,219,182 | |
| Risk adjustment | ↓20% | |||||
| Atr | Improved business resilience from fewer revenue-impacting incidents (risk-adjusted) | $5,698,633 | $6,136,989 | $6,575,346 | ||
| Three-year total: $18,410,967 | Three-year present value: $15,192,621 | |||||
Faster Problem-Solving From SRE Productivity
Evidence and data. Before Elastic Observability, interviewees experienced inefficiencies among the teams previously responsible for monitoring dashboards and telemetry to detect incidents. With Elastic Observability, those teams benefited from a unified platform for log analytics, infrastructure monitoring, APM, and agentic AI. Zero-configuration anomaly detection across logs, metrics, and traces enabled teams to proactively take action to prevent incidents or remediate the impacts, thus reducing MTTD and MTTR while improving overall business resilience.
-
The director of software engineering at a telecommunications organization previously had 70 to 80 data scientists dedicated to SRE-type responsibilities such as detecting and mitigating incidents. The interviewee indicated that the data scientist resources reclaimed 95% of their time with Elastic Observability. Now, the organization has 10 to 15 data scientists who remain on monitoring, and it reallocated the rest to more value-added work.
-
The executive VP and head of technology at a media organization saw an 18% to 20% reduction in SRE headcount specifically from automating more of the root cause analysis and detection processes.
-
The AIOps leader at a financial services organization indicated that with Elastic Observability, SREs resolve incidents 5 to 10 minutes faster specifically due to APM traces.
-
Interviewees also indicated that reducing MTTD and MTTR contributed to system downtime mitigation and SRE productivity. The AIOps leader at a financial services organization estimated that with Elastic Observability, MTTD decreased from 6 minutes to 1 minute, which is about an 85% improvement. They said, “Some of our applications are better than others; three to four of them are close to 1 minute for detect.”
-
The executive VP and head of technology at a media organization corroborated that sentiment and noted that MTTD decreased from between 40 and 45 minutes to less than 8 minutes with Elastic Observability, which is an 80% improvement. The same interviewee said their organization improved MTTR by 15% to 20% as well.
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
Before Elastic Observability, the composite had a team of 15 SREs who dedicated 85% of their time to monitoring applications and identifying and resolving incidents.
-
With Elastic Observability, the organization reduces SRE team time spent by 90% in Year 1, increasing to 95% by Year 3. With an average fully burdened hourly rate of $90 per SRE resource and a recapture rate of 80%, SRE team productivity is worth a risk-adjusted $1.4 million in Year 1, growing to $1.5 million by Year 3.
Risks. The scale of this benefit may vary by organization based on:
-
The team size and resource types involved in monitoring and resolving incidents before Elastic Observability.
-
The functionality rolled out to these teams that create efficiencies, such as APM, root cause analysis, and anomaly detection.
Results. To account for these risks, Forrester adjusted this benefit downward by 20%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $3.5 million.
95%
Reduction in SRE time spent monitoring and resolving incidents
Faster Problem-Solving From SRE Productivity
| Ref. | Metric | Source | Year 1 | Year 2 | Year 3 | |
|---|---|---|---|---|---|---|
| B1 | Site reliability engineers in prior environment | Composite | 15 | 15 | 15 | |
| B2 | SRE time on monitoring applications and identifying and resolving incidents in prior environment (hours) | B1*2,080 hours*85% of time spent | 26,520 | 26,520 | 26,520 | |
| B3 | Reduction in time spent monitoring and resolving incidents with Elastic Observability | Interviews | 90% | 95% | 95% | |
| B4 | SRE time saved (hours) | B2*B3 | 23,868 | 25,194 | 25,194 | |
| B5 | Average fully burdened hourly rate for an SRE | Composite | $90 | $90 | $90 | |
| B6 | Recapture rate on saved time | TEI methodology | 80% | 80% | 80% | |
| Bt | Faster problem-solving from SRE productivity | B4*B5*B6 | $1,718,496 | $1,813,968 | $1,813,968 | |
| Risk adjustment | ↓20% | |||||
| Btr | Faster problem-solving from SRE productivity (risk-adjusted) | $1,374,797 | $1,451,174 | $1,451,174 | ||
| Three-year total: $4,277,146 | Three-year present value: $3,539,422 | |||||
Application Development And Deployment Efficiency
Evidence and data. Interviewees focused on the impact of improved observability to development timelines, as developers were often already involved in incident remediation processes. Forrester describes this approach as creating observability-driven deployment, which means shifting left and bringing observability into planning and design. It also means fostering a culture where preventative fixes are seen as investments, not distractions. By building observability data into development earlier in the process, developers benefit from early insights into how changes will behave in production and can be warned about abnormalities before they implode; therefore, they can prevent organizational damage.2 With Elastic Observability, interviewees said they benefited from more visibility into deployment pipelines, faster troubleshooting, and real-time user monitoring and digital experience monitoring. As a result, their organizations further reduced incident volumes where developers were previously required to help test, deploy, and debug fixes.
-
The senior director of application operations at a fintech organization indicated that they lacked an SRE team before Elastic Observability, which put more pressure on development resources to assist in incident troubleshooting and remediation: “We have this gap in SREs, so whenever we have an outage, it’s developers who are doing the troubleshooting, before Elastic identifies it. We get billions of logs a day and digging through those logs to identify where a problem was before we could even put a fix in place would sometimes take us days.” With Elastic Observability, the 30% of time previously spent on troubleshooting for developers was now closer to 20%. The time savings for developers were redirected to pushing out better quality reworks, which helped improve MTTR.
-
The director of software engineering at a telecommunications organization tied MTTR improvements to accelerated development work as well, saying, “The 15% to 20% reduction in MTTR workflows and the 30% to 35% reduction in remediation timelines included developer work.”
-
This interviewee also said that developers used the time savings to focus on more innovation work for the organization: “[After implementing Elastic Observability], developers started focusing on more industry-specific analysis. When they create a new bundle of products, the developers will look to see how customers are responding to that new bundle or how it is contributing to a new line of business versus focusing on the application health and application-related analysis. Developers then start looking at revenue increasing or churn decreasing analysis to restrict friction points and improve usability or omnichannel flows.”
-
Forrester corroborates the connection between observability-driven deployment, stating that it gives developers the power to innovate more comfortably because they have the context they need to make smart and informed decisions. It reduces accumulation of technical debt because issues are caught early, before they transform from unrecognizable behavioral changes into outages. An added benefit is that connecting engineering decisions directly to business outcomes transforms software releases from a gamble into a strategic advantage.3
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
The team of application developers who work on applications covered with Elastic Observability grows from 280 in Year 1 to 339 by Year 3, following the trajectory of onboarded application volumes.
-
The team of developers previously dedicated 30% of their time to testing, deploying, and debugging applications. With Elastic Observability, the team sees a 35% reduction in time spent on these activities in Year 1, which increases to 55% by Year 3.
-
With a fully burdened hourly rate of $77 for a developer and a recapture rate of 50%, the risk-adjusted application development and deployment efficiencies grow from $1.9 million in Year 1 to $3.6 million in Year 3.
Risks. The scale of this benefit may vary by organization based on:
-
The size of the application environment and the associated team of developers responsible for testing, deploying, and debugging applications in the prior environment.
-
The observability functionality implemented and the rate at which applications are onboarded to the platform, which drives the reduction in time spent on such activities and the associated impact to developers.
Results. To account for these risks, Forrester adjusted this benefit downward by 20%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $6.6 million.
263,983 total hours
Time saved for developers in application deployment over three years
Application Development And Deployment Efficiency
| Ref. | Metric | Source | Year 1 | Year 2 | Year 3 | |
|---|---|---|---|---|---|---|
| C1 | Application developers working on apps covered by Elastic Observability | Composite | 280 | 308 | 339 | |
| C2 | Developer time spent testing, deploying, and debugging applications in prior environment (hours) | C1*2,080 hours*30% of time spent | 174,720 | 192,192 | 211,536 | |
| C3 | Reduction in time spent on application deployment with Elastic Observability | Interviews | 35% | 45% | 55% | |
| C4 | Application developer time saved with Elastic Observability (hours) | C2*C3 | 61,152 | 86,486 | 116,345 | |
| C5 | Average fully burdened hourly rate for a developer | Composite | $77 | $77 | $77 | |
| C6 | Recapture rate on saved time | TEI methodology | 50% | 50% | 50% | |
| Ct | Application development and deployment efficiency | C4*C5*C6 | $2,354,352 | $3,329,711 | $4,479,283 | |
| Risk adjustment | ↓20% | |||||
| Ctr | Application development and deployment efficiency (risk-adjusted) | $1,883,482 | $2,663,769 | $3,583,426 | ||
| Three-year total: $8,130,677 | Three-year present value: $6,605,999 | |||||
Infrastructure Optimization
Evidence and data. Interviewees noted that before Elastic Observability, their organizations implemented many different observability tools to cover all aspects of the observability data, including traces and logs. However, these tools were not built to help their organizations face the large-scale volumes of log and telemetry data. As environments continued to expand, prohibitive storage costs became the primary inhibiting factor, forcing teams to cap ingestion and leave critical systems unmonitored. By consolidating siloed tools onto the Elasticsearch platform, interviewees said that their organizations gained unified visibility across their observability operation, eliminating the overhead from managing disparate solutions. They also noted that Elastic Observability’s tiered data storage model gave their organizations control over where data lives based on access frequency and cost, and features like logsdb index mode, searchable snapshots, advanced data compression, and efficient indexing supported increased transparency and reduced infrastructure and storage costs — without sacrificing performance or data retention.
-
The director of software engineering at a telecommunications organization indicated that their organization reduced log storage costs by 70% with Elastic Observability: “A lot of vendors force you to do indexing, which is expensive. Elastic gives you all the templates to analyze your logs so you can better decide if you want to index or not. You can choose to keep the logs open file format and have the super speed search enabled. It reduces proprietary log saving. It helps reduce spend on other expensive log storage providers.”
-
The executive VP and head of technology at a media organization corroborated the log storage cost savings and estimated, “Total cost savings is a few million a month but includes business disruption cost savings in addition to technology consolidation cost savings.”
-
The observability director at a consumer products manufacturer saw $4.9 million in cost savings from reducing observability tools. The organization went from roughly 55 tools to about 20 by standardizing on the Elasticsearch AI platform, eliminating overlapping licenses and integrations. Over three years, the organization reduced its number of observability tools by more than 60%, reducing costs and providing full-stack visibility to teams.
-
This interviewee also estimated that their organization saved up to 38% in hardware costs related to observability infrastructure from data tiering and compression. This enabled it to move infrequently accessed data to lower-cost tiers without compromising performance, reducing node counts and infrastructure spend while sustaining telemetry growth. The organization also used Elastic Observability’s logsdb compression capabilities to reduce the size of log data, creating meaningful storage efficiencies as monthly ingestion volumes reached 13.7 TB.
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
Observability infrastructure costs were primarily driven by storage costs before Elastic Observability, and the organization spent $200,000 annually on log storage in the prior environment.
-
With Elastic Observability, the composite utilizes data tiering to improve its log storage decisions, reducing annual spend by 60% in Year 1 and 70% by Year 3.
-
The composite previously had six tools related to observability before Elastic Observability. It consolidates four of them to the Elastic Observability platform by Year 3 and saves on the associated licensing costs.
Risks. The scale of this benefit may vary by organization based on:
-
The size of an organization.
-
Its associated observability environment in terms of legacy tools and log ingestion and storage volumes.
Results. To account for these risks, Forrester adjusted this benefit downward by 10%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $848,000.
70%
Reduction in observability infrastructure costs from consolidating and retiring previous tools
Infrastructure Optimization
| Ref. | Metric | Source | Year 1 | Year 2 | Year 3 | |
|---|---|---|---|---|---|---|
| D1 | Observability infrastructure costs driven by storage before Elastic Observability | Composite | $200,000 | $200,000 | $200,000 | |
| D2 | Reduction in observability infrastructure costs driven by efficient storage and data tiering | Interviews | 60% | 65% | 70% | |
| D3 | Subtotal: Hardware cost savings from efficient storage | D1*D2 | $120,000 | $130,000 | $140,000 | |
| D4 | Observability tools licensed before Elastic Observability | Composite | 6 | 6 | 6 | |
| D5 | Observability tools licensed while using Elastic Observability | Composite | 4 | 3 | 2 | |
| D6 | Reduction in observability tools needed when using Elastic Observability | D4-D5 | 2 | 3 | 4 | |
| D7 | Average licensing costs saved per observability tool | Interviews | $85,000 | $85,000 | $85,000 | |
| D8 | Subtotal: Software cost savings from tool consolidation | D6*D7 | $170,000 | $255,000 | $340,000 | |
| Dt | Infrastructure optimization | D3+D8 | $290,000 | $385,000 | $480,000 | |
| Risk adjustment | ↓10% | |||||
| Dtr | Infrastructure optimization (risk-adjusted) | $261,000 | $346,500 | $432,000 | ||
| Three-year total: $1,039,500 | Three-year present value: $848,204 | |||||
Increased Customer Retention
Evidence and data. Interviewees shared that poor system and application performance previously impacted customer experiences. With Elastic Observability, their organizations saw improved customer experiences that helped avoid high churn rates. Interviewees cited how AI capabilities within the Elastic Observability platform, specifically anomaly detection and root cause analysis, mitigated the impact of application performance outages and degradation on customers to drive improved customer retention.
-
The senior director of application operations at a fintech organization said they lost large customer contracts with their prior infrastructure performance: “On the sales side, when we lose an enterprise customer, we don’t lose them very often, but it’s significant. One of the big ones that we did lose was due to system downtime events that we were experiencing in our prior state.”
-
The director of software engineering at a telecommunications organization said: “With Elastic, if our churn is currently at 2%, Elastic contributed to a 15% to 20% reduction from our prior churn to help get us here. Practically, that means prior downtime events impacted the business. For example, if our app is not working, we could lose orders. Some prospects might try to place the order again 2 hours later, but many will not come back at all and will just go to another vendor. That is something we look at — whether the order loss is a permanent loss or a frustration factor that just reduces Net Promoter Score℠ (NPS).”4
-
The executive VP and head of technology at a media organization indicated that better customer service and satisfaction, even qualitatively, contributed to reduced customer churn. They said, “With Elastic, we saw call volumes in the call center drop by almost 60% and saw NPS improve in the areas of system reliability. We think the AI functionality that improves anomaly detection made our organization more proactive, which meant that we could resolve issues before customers even reported them.”
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
The composite organization has a large customer base of 25 million and previously experienced a customer retention rate of 80%.
-
With Elastic Observability, the organization improves the customer retention rate and attributes 0.35% of that improvement to the Elastic Observability platform in Year 1. That attribution grows to 0.6% by Year 3 due to the implementation of more AI capabilities that stop downtime events from impacting more customers.
-
As the impact is to retained customers and not net new customers, the average revenue impact per customer is $100, which represents a smaller portion of average order value than that associated with onboarding a new customer.
Risks. The scale of this benefit may vary by organization based on:
-
The size of an organization and the volume of customers impacted.
-
The customer retention rate before Elastic Observability and the improvement experienced with the Elastic Observability platform in place.
Results. To account for these risks, Forrester adjusted this benefit downward by 20%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $1.9 million.
0.60%
Customer retention improvement attributed to Elastic Observability by Year 3
Increased Customer Retention
| Ref. | Metric | Source | Year 1 | Year 2 | Year 3 | |
|---|---|---|---|---|---|---|
| E1 | Customers in prior environment | Composite | 25,000,000 | 25,000,000 | 25,000,000 | |
| E2 | Previous customer retention rate | Composite | 80% | 80% | 80% | |
| E3 | Improvement to customer retention attributed to Elastic Observability | Interviews | 0.35% | 0.50% | 0.60% | |
| E4 | Additional customers retained attributed to Elastic Observability | E1*E2*E3 | 70,000 | 100,000 | 120,000 | |
| E5 | Average revenue per retained customer | Composite | $100 | $100 | $100 | |
| E6 | Operating margin | A5 | 10% | 10% | 10% | |
| Et | Increased customer retention | E4*E5*E6 | $700,000 | $1,000,000 | $1,200,000 | |
| Risk adjustment | ↓20% | |||||
| Etr | Increased customer retention (risk-adjusted) | $560,000 | $800,000 | $960,000 | ||
| Three-year total: $2,320,000 | Three-year present value: $1,891,510 | |||||
Unquantified Benefits
Benefits that provide value for interviewees’ organizations but are not quantified for this study include:
-
Expansion of observability with LLMs to help scale coverage and meet market demands. Interviewees invested in Elastic Observability to meet current and future observability needs. The senior director of application operations at a fintech organization said: “We currently use anomaly detection. We find that this AI functionality augments our small team and functions like an SRE resource, which we did not have before. Now we are able to proactively build the dashboards and the thresholds that we need.” The same interviewee noted that they will work with Elastic Observability to plan for further AI adoption, including monitoring AI models, from their current, early pilot stages. The executive VP and head of technology at a media organization said they intended to build in “intelligence-driven anomaly detection beyond infrastructure observability to cover more applications to impact user experiences with the goal of identifying issues before they impact customers.”
-
Improvement to observability cost consistency and predictability. Interviewees’ organizations benefited from more transparency, which allowed them to control log volumes and associated costs. The senior director of application operations at a fintech organization explained that developers often inadvertently contribute to higher log volumes and therefore increase logging costs: “We have dashboards that do analysis of what logs we’re ingesting, where they’re coming from and where we have spikes. The tools that Elastic Observability provides to be able to just see where we’re spending our money has helped us control costs. In that way, we can put pressure on development teams to reduce their logging or fix bugs that are just spamming us unnecessarily.”
-
Compliance with governance and regulatory requirements. In heavily regulated industries, collecting and storing data regarding downtime incidents and events was paramount to better meet strict governance requirements. As an example, the senior director of application operations at a fintech organization said: “We have two PCI in-scope apps. We don’t hold card data, but we do payment transmission. So we use those logs to satisfy some of the PCI controls. We’re also SOC 1 Type 2 compliant as well. So again, we can provide logs to the auditors there as well.”
-
Improvement in customer service levels, especially in IoT. The senior director of application operations at a fintech organization noted that Elastic Observability enabled more flexible management and monitoring for end-customer POS devices within their environments. They said: “Enterprise customers are incredibly picky about their POS experience. Elastic has helped us because we are able to identify a specific site, store, and device, and pull the configuration of that device out of our tools and be able to then apply that to a lab, do the testing, and then validate what’s going on.” In some cases, Elastic Observability enabled efficiencies for those end customers through this transparency and analysis effort as well. The same interviewee provided an example of this use case, stating: “One of our customers is a stadium in North America that we provide all of the menu boards, POS, and technology for at all of their concession stands. As part of that agreement, we also gave them access to Elastic dashboards to be able to track their devices. Prior to us coming on board, they would have somebody walk around every single POS device in the stadium leading up to an event to make sure it was online and turn it off and turn it on, which would take hours because there’s almost 3,000 devices in a stadium. With access to Elastic dashboards, they can essentially just with one glance say, ‘Okay, these are the ones offline. Somebody go deal with those and get it done.’”
Flexibility
The value of flexibility is unique to each customer. There are multiple scenarios in which a customer might implement Elastic Observability and later realize additional uses and business opportunities, including:
-
Further reduce incidents by expanding platform capabilities. Interviewees described additional uses for Elastic Observability across AI, Streams, and self-service:
- AI. The senior director of application operations at a fintech organization indicated the desire to adopt more AI functionality to reduce incident volumes and incident severity: “I would like to see full adoption of AI across code pipelines, across monitoring tools, across security tools. So there’s a lot more we can do. This team is specifically coming in to help implement additional tools to essentially stop our outages. If we can go for a year and only have a couple of P3s, P4s, then we’re in a much better position than the P1s we used to have. Anomaly detection is going to be a big part of it. We haven’t dug into the rest of the Elastic capabilities and what else they offer, the agentic AI that is available in [our cloud provider] and Elastic and a lot of tools now.” So what is in store for organizations that incorporate more AI, and specifically agentic AI, into their observability practices? According to Forrester, the goal of the agents is not just to fix what’s broken. Fueled with observability data and analytics, the agents can anticipate what’s next, turning retrospectives into design intents and preemptive solutions. The result is fewer antipatterns, stronger security, faster iterations, more resilient operations, and a development culture that experiments with less fear and makes more of an impact.5
- Streams. Interviewees shared that one of the reasons they elected to unify their observability environments to the Elastic Observability platform was trust in Elastic’s product roadmap. Consequently, they are looking forward to enrolling in new functionality and taking advantage of new features such as Streams to build on the gains they have already experienced. Streams uses AI to automatically parse, partition, and structure log data, which can simplify ingestion pipelines and accelerate incident detection. It also enables schema-agnostic ingestion and storage of any data in its native format, including OpenTelemetry, Prometheus, Beats, and others, and can reduce the effort or information loss of schema translation.
- Self-service. The senior director of application operations at a fintech organization had already enabled self-service access to the Elastic Observability dashboards for some end customers to improve their own workflows for devices. The interviewee wanted to double-down on this effort for more end customers, not only to improve customer satisfaction but also to give customers more control of their devices and cut down on the tickets that land back with the organization: “It is to the point where some of our customers are asking how they can get a direct feed into Elastic to get live-stream logs, but it is significantly expensive just to export these logs. But to start giving a customer a way to just pull those is something we need to understand and discuss, and it’s a conversation we were thinking of having with Elastic to say, ‘Hey, how would you do this? You have APIs, what would be the impact? Do we need additional clusters to be able to support that?’ So that’s something we’re looking to do but could be complicated and costly.”
Flexibility would also be quantified when evaluated as part of a specific project (described in more detail in Total Economic Impact Approach).
Analysis Of Costs
Quantified cost data as applied to the composite
Total Costs
| Ref. | Cost | Initial | Year 1 | Year 2 | Year 3 | Total | Present Value |
|---|---|---|---|---|---|---|---|
| Ftr | Elastic Observability costs | $60,000 | $1,272,000 | $1,684,800 | $2,274,480 | $5,291,280 | $4,317,611 |
| Gtr | Implementation and training labor | $56,160 | $339,180 | $236,592 | $105,552 | $737,484 | $639,339 |
| Htr | Optimization and management labor | $0 | $449,280 | $449,280 | $449,280 | $1,347,840 | $1,117,293 |
| Total costs (risk-adjusted) | $116,160 | $2,060,460 | $2,370,672 | $2,829,312 | $7,376,604 | $6,074,243 |
Elastic Observability Costs
Evidence and data. Interviewees said that they paid Elastic for use of the Observability platform based on data ingest volumes. For many interviewees, Elastic Observability data tiering and storage functionality was viewed as an enabler of scale. Data tiering and compression allowed these organizations to move infrequently accessed data to lower-cost tiers without compromising performance, reducing node counts and infrastructure spending while sustaining telemetry growth. Therefore, the interviewees noted that the cost of the platform, while it grew over time, did not scale proportionally to the size of the various organizations’ expanding environments and log storage needs. The cost-to-scale dynamic underscores why interviewees viewed Elastic Observability as a strategic platform capable of supporting long-term growth. Additionally, many of the interviewees took advantage of Elastic professional services to assist with the rollout strategy and to implement some of the newer product capabilities effectively. Pricing may vary. Contact Elastic for additional details.
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
The composite organization pays Elastic $1.04 million in Year 1 in licensing costs to support 10 TB/day ingest. The annual fees paid to Elastic scale by 35% each year of the investment to reach $1.9 million by Year 3. Although the subscription fees grow each year, they do not scale in parallel to the use of the platform given Elastic Observability’s data tiering and storage capabilities that encourage organizations to bring more of their environments onto the platform for observability.
-
The organization pays Elastic for professional services and training to kick off the implementation project, which continue throughout Year 1 of the investment.
Risks. The impact of this cost may vary by organization depending on the following:
-
The data ingest volumes, storage regions, and requirements of an organization.
-
The need for Elastic professional services and training support.
Results. To account for these risks, Forrester adjusted this cost upward by 20%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $4.3 million.
Elastic Observability Costs
| Ref. | Metric | Source | Initial | Year 1 | Year 2 | Year 3 |
|---|---|---|---|---|---|---|
| F1 | Subscription cost of Elastic Observability including compute and storage | Interviews | $0 | $1,040,000 | $1,404,000 | $1,895,400 |
| F2 | Training and professional services costs related to Elastic Observability | Interviews | $50,000 | $20,000 | $0 | $0 |
| Ft | Elastic Observability costs | F1+F2 | $50,000 | $1,060,000 | $1,404,000 | $1,895,400 |
| Risk adjustment | ↑20% | |||||
| Ftr | Elastic Observability costs (risk-adjusted) | $60,000 | $1,272,000 | $1,684,800 | $2,274,480 | |
| Three-year total: $5,291,280 | Three-year present value: $4,317,611 | |||||
Implementation And Training Labor
Evidence and data. Implementing the most basic Elastic Observability functionality took the interviewees’ organizations around one month on average. To realize maximum value from the enterprise solution, employees spent time learning the solution’s functionality and capabilities after implementation.
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
Six FTEs spend two weeks setting up and implementing an initial, bare-bones Elastic Observability setup as a managed cloud service.
-
After the initial implementation period, the composite requires one FTE for integration and expansion in Years 1, 2, and 3. The employees continue this work throughout Years 1 and 2 and for the first five months of Year 3 to complete rollout and cover 90% of the organization’s 300 applications.
-
Fifteen engineers spend an average of 50 hours learning Elastic Observability, while developers and data analysts who use Elastic Observability undergo 5 hours of training. Although these users do not need ongoing refreshers, new hires on these teams require training to effectively use Elastic Observability.
-
The average fully burdened hourly rate for a trained employee is $83.
Risks. These costs will vary between organizations depending on the following factors:
-
The size and complexity of an organization’s IT operations and infrastructure and the effort needed for change management.
-
The prioritization, speed, and breadth of an organization’s Elastic Observability integration.
-
An organization’s level of internal investment in learning how to best utilize Elastic Observability’s capabilities and efforts to optimize use and value from the solution.
-
The expertise, skill sets, and salaries of an organization’s existing employees who participate in Elastic Observability implementation and training.
-
Whether an organization pays for customer service and training from Elastic or a third party.
Results. To account for these risks, Forrester adjusted this cost upward by 20%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $639,000.
Implementation And Training Labor
| Ref. | Metric | Source | Initial | Year 1 | Year 2 | Year 3 |
|---|---|---|---|---|---|---|
| G1 | Time spent on Elastic Observability implementation and expansion (months) | Interviews | 0.5 | 12 | 12 | 5 |
| G2 | FTEs needed for implementation and expansion | Interviews | 6 | 1 | 1 | 1 |
| G3 | Average fully burdened annual salary for an engineer | B5*2,080 hours | $187,200 | $187,200 | $187,200 | $187,200 |
| G4 | Subtotal: Implementation and expansion labor costs | G1*G2*G3/12 | $46,800 | $187,200 | $187,200 | $78,000 |
| G5 | Engineers dedicating learning time to Elastic Observability | Composite | 15 | 2 | 2 | |
| G6 | Average time spent learning Elastic Observability (hours) | Interviews | 50 | 50 | 50 | |
| G7 | Additional employees dedicating learning time to Elastic Observability | Composite | 80 | 4 | 4 | |
| G8 | Average time spent learning Elastic Observability (hours) | Interviews | 5 | 5 | 5 | |
| G9 | Average fully burdened hourly salary for a trained employee | Composite | $83 | $83 | $83 | |
| G10 | Subtotal: Training labor costs | (G5*G6+G7*G8)*G9 | $95,450 | $9,960 | $9,960 | |
| Gt | Implementation and training labor | G4+G10 | $46,800 | $282,650 | $197,160 | $87,960 |
| Risk adjustment | ↑20% | |||||
| Gtr | Implementation and training labor (risk-adjusted) | $56,160 | $339,180 | $236,592 | $105,552 | |
| Three-year total: $737,484 | Three-year present value: $639,339 | |||||
Optimization And Management Labor
Evidence and data. For interviewees’ organizations, ongoing management labor associated with Elastic Observability included oversight of their Elastic relationships and subscriptions. It also included time spent learning about and training others on new Elastic capabilities, facilitating change management, coordinating internal integrations for new applications and data, and troubleshooting and resolving issues.
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
One FTE is dedicated to employee optimization efforts in Year 1 of the investment, with their time dropping off by about 10% in each subsequent year.
-
One FTE is dedicated to employee management in Year 1 of the investment, with additional time from other resources added in each subsequent year.
-
The resources required for these activities are pulled from the engineering team. Engineers have an average fully burdened annual salary of $187,200.
Risks. These costs will vary between organizations depending on the following factors:
-
The size and complexity of an organization’s IT operations and infrastructure.
-
The extent and rate at which an organization integrates Elastic Observability with existing and new systems.
-
The number, skill sets, compensation amounts, and compensation structures of an organization’s existing technical resources who participate in ongoing management work.
Results. To account for these risks, Forrester adjusted this cost upward by 20%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $1.1 million.
Optimization And Management Labor
| Ref. | Metric | Source | Initial | Year 1 | Year 2 | Year 3 |
|---|---|---|---|---|---|---|
| H1 | FTE employee optimization labor | Interviews | 0.0 | 1.0 | 0.9 | 0.8 |
| H2 | FTE employee management labor | Interviews | 0.0 | 1.0 | 1.1 | 1.2 |
| H3 | Average fully burdened annual salary for an engineer | B5*2,080 hours | $187,200 | $187,200 | $187,200 | $187,200 |
| Ht | Optimization and management labor | (H1+H2)*H3 | $0 | $374,400 | $374,400 | $374,400 |
| Risk adjustment | ↑20% | |||||
| Htr | Optimization and management labor (risk-adjusted) | $0 | $449,280 | $449,280 | $449,280 | |
| Three-year total: $1,347,840 | Three-year present value: $1,117,293 | |||||
Financial Summary
Consolidated Three-Year, Risk-Adjusted Metrics
Cash Flow Chart (Risk-Adjusted)
Cash Flow Analysis (Risk-Adjusted)
| Initial | Year 1 | Year 2 | Year 3 | Total | Present Value | |
|---|---|---|---|---|---|---|
| Total costs | ($116,160) | ($2,060,460) | ($2,370,672) | ($2,829,312) | ($7,376,604) | ($6,074,243) |
| Total benefits | $0 | $9,777,911 | $11,398,432 | $13,001,946 | $34,178,290 | $28,077,756 |
| Net benefits | ($116,160) | $7,717,451 | $9,027,760 | $10,172,634 | $26,801,686 | $22,003,513 |
| ROI | 362% | |||||
| Payback | <6 months |
Please Note
The financial results calculated in the Benefits and Costs sections can be used to determine the ROI, NPV, and payback period for the composite organization’s investment. Forrester assumes a yearly discount rate of 10% for this analysis.
These risk-adjusted ROI, NPV, and payback period values are determined by applying risk-adjustment factors to the unadjusted results in each Benefit and Cost section.
The initial investment column contains costs incurred at “time 0” or at the beginning of Year 1 that are not discounted. All other cash flows are discounted using the discount rate at the end of the year. PV calculations are calculated for each total cost and benefit estimate. NPV calculations in the summary tables are the sum of the initial investment and the discounted cash flows in each year. Sums and present value calculations of the Total Benefits, Total Costs, and Cash Flow tables may not exactly add up, as some rounding may occur.
From the information provided in the interviews, Forrester constructed a Total Economic Impact™ framework for those organizations considering an investment in Elastic Observability.
The objective of the framework is to identify the cost, benefit, flexibility, and risk factors that affect the investment decision. Forrester took a multistep approach to evaluate the impact that Elastic Observability can have on an organization.
Due Diligence
Interviewed Elastic stakeholders and Forrester analysts to gather data relative to Elastic Observability.
Interviews
Interviewed five decision-makers at organizations using Elastic Observability to obtain data about costs, benefits, and risks.
Composite Organization
Designed a composite organization based on characteristics of the interviewees’ organizations.
Financial Model Framework
Constructed a financial model representative of the interviews using the TEI methodology and risk-adjusted the financial model based on issues and concerns of the interviewees.
Case Study
Employed four fundamental elements of TEI in modeling the investment impact: benefits, costs, flexibility, and risks. Given the increasing sophistication of ROI analyses related to IT investments, Forrester’s TEI methodology provides a complete picture of the total economic impact of purchase decisions. Please see Appendix A for additional information on the TEI methodology.
Total Economic Impact Approach
Benefits
Benefits represent the value the solution delivers to the business. The TEI methodology places equal weight on the measure of benefits and costs, allowing for a full examination of the solution’s effect on the entire organization.
Costs
Costs comprise all expenses necessary to deliver the proposed value, or benefits, of the solution. The methodology captures implementation and ongoing costs associated with the solution.
Flexibility
Flexibility represents the strategic value that can be obtained for some future additional investment building on top of the initial investment already made. The ability to capture that benefit has a PV that can be estimated.
Risks
Risks measure the uncertainty of benefit and cost estimates given: 1) the likelihood that estimates will meet original projections and 2) the likelihood that estimates will be tracked over time. TEI risk factors are based on “triangular distribution.”
Financial Terminology
Present value (PV)
The present or current value of (discounted) cost and benefit estimates given at an interest rate (the discount rate). The PVs of costs and benefits feed into the total NPV of cash flows.
Net present value (NPV)
The present or current value of (discounted) future net cash flows given an interest rate (the discount rate). A positive project NPV normally indicates that the investment should be made unless other projects have higher NPVs.
Return on investment (ROI)
A project’s expected return in percentage terms. ROI is calculated by dividing net benefits (benefits less costs) by costs.
Discount rate
The interest rate used in cash flow analysis to take into account the time value of money. Organizations typically use discount rates between 8% and 16%.
Payback
The breakeven point for an investment. This is the point in time at which net benefits (benefits minus costs) equal initial investment or cost.
Appendix A
Total Economic Impact
Total Economic Impact is a methodology developed by Forrester Research that enhances a company’s technology decision-making processes and assists solution providers in communicating their value proposition to clients. The TEI methodology helps companies demonstrate, justify, and realize the tangible value of business and technology initiatives to both senior management and other key stakeholders.
Appendix B
Supplemental Material
Related Forrester Research
Harness Contextual Observability To Drive Scalable Innovation And System Resilience, Forrester Research, Inc., October 31, 2025.
Appendix C
Endnotes
1 Total Economic Impact is a methodology developed by Forrester Research that enhances a company’s technology decision-making processes and assists solution providers in communicating their value proposition to clients. The TEI methodology helps companies demonstrate, justify, and realize the tangible value of business and technology initiatives to both senior management and other key stakeholders.
2 Source: Harness Contextual Observability To Drive Scalable Innovation And System Resilience, Forrester Research, Inc., October 31, 2025.
3 Ibid.
4 Net Promoter and NPS are registered service marks, and Net Promoter Score is a service mark, of Bain & Company, Inc., Satmetrix Systems, Inc., and Fred Reichheld.
5 Source: Harness Contextual Observability To Drive Scalable Innovation And System Resilience, Forrester Research, Inc., October 31, 2025.
Disclosures
Readers should be aware of the following:
This study is commissioned by Elastic and delivered by Forrester Consulting. It is not meant to be used as a competitive analysis.
Forrester makes no assumptions as to the potential ROI that other organizations will receive. Forrester strongly advises that readers use their own estimates within the framework provided in the study to determine the appropriateness of an investment in Elastic Observability. For any interactive functionality, the intent is for the questions to solicit inputs specific to a prospect’s business. Forrester believes that this analysis is representative of what companies may achieve with Elastic Observability based on the inputs provided and any assumptions made. Forrester does not endorse Elastic or its offerings. Although great care has been taken to ensure the accuracy and completeness of this model, Elastic and Forrester Research are unable to accept any legal responsibility for any actions taken on the basis of the information contained herein. The interactive tool is provided ‘AS IS,’ and Forrester and Elastic make no warranties of any kind.
Elastic reviewed and provided feedback to Forrester, but Forrester maintains editorial control over the study and its findings and does not accept changes to the study that contradict Forrester’s findings or obscure the meaning of the study.
Elastic provided the customer names for the interviews but did not participate in the interviews.
Consulting Team:
Casey Sirotnak
Published
September 2026