# What Can I Do with Elastic SIEM Free Tier? (Capabilities and Limitations)

**URL:** https://discuss.elastic.co/t/what-can-i-do-with-elastic-siem-free-tier-capabilities-and-limitations/383103
**Category:** SIEM
**Tags:** license
**Created:** [October 30, 2025, 1:54pm UTC](https://discuss.elastic.co/t/what-can-i-do-with-elastic-siem-free-tier-capabilities-and-limitations/383103 "2025-10-30T13:54:25Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![cyberfury](https://avatars.discourse-cdn.com/v4/letter/c/a5b964/32.png) [@cyberfury](https://discuss.elastic.co/u/cyberfury)
#### Post date: [October 30, 2025, 1:54pm UTC](https://discuss.elastic.co/t/what-can-i-do-with-elastic-siem-free-tier-capabilities-and-limitations/383103/1 "2025-10-30T13:54:25Z")

</div>

Hi everyone,

I’ve successfully installed on premises **Elasticsearch, Logstash, Kibana, and Elastic Agent/Fleet Server** on my Ubuntu server. I’m now exploring the **SIEM features** in the **Elastic Stack free tier** , but I’m a bit unclear about what capabilities are available and what’s limited compared to the paid (Standard/Enterprise) licenses.

Specifically, I’d like to know:

- What core SIEM functionalities are included in the free tier?

- Which features (like detections, cases, threat intelligence, or rule automation) are restricted?

- Are there any practical use cases I can still implement using the free tier for learning or small-scale monitoring?

Any insights or official documentation links would be really helpful. Thanks in advance!

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [October 30, 2025, 2:01pm UTC](https://discuss.elastic.co/t/what-can-i-do-with-elastic-siem-free-tier-capabilities-and-limitations/383103/2 "2025-10-30T14:01:42Z")

</div>

It is better to start with the subscription page where you have a list of features that are available with the free license and the ones that requires a paid license.

> **[Subscriptions | Elastic Stack Products & Support | Elastic](https://www.elastic.co/subscriptions)**
>
> See subscription levels, pricing, and tiered features for on-prem deployments of the Elastic Stack (Elasticsearch Kibana, Beats, and Logstash), Elastic Cloud, and Elastic Cloud Enterprise....

You can do a lot with the free license, but some of the main limitations is that you cannot send your alerts elsewhere, all Kibana Connectors that send alerts to email, webhook or other external destinations requires a paid license.

But there are workarounds, you can use logstash to read your alerts index and send it to any place you want for example.

Also, AI and machine learning tools requires a Platinum and some cases an Enterprise license.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 27, 2025, 2:02pm UTC](https://discuss.elastic.co/t/what-can-i-do-with-elastic-siem-free-tier-capabilities-and-limitations/383103/3 "2025-11-27T14:02:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
