Skip to main content

Elastic Announces Elasticsearch Logsdb Index Mode to Reduce Log Data Storage Footprint by Up to 65%

Security and observability teams now benefit from reduced storage expenses and longer log retention to support their threat hunting, incident response, and compliance requirements

Elastic announced the general availability of Elasticsearch logsdb index mode.

This latest innovation in log management reduces the storage footprint of log data by up to 65% compared to recent versions of Elasticsearch without logsdb index mode. Now, security and observability teams have increased visibility while keeping all data immediately accessible for analysis.

“Logs are critical for detection and remediation, but the growing log volume generated by infrastructure and applications is driving up costs and forcing compromises that hinder analysis,” said Ken Exner, chief product officer at Elastic. “Logsdb index mode reduces the disk footprint and overall cost of storing log data with features including smart index sorting, synthetic source and advanced compression.”

Logsdb index mode optimizes data ordering, eliminates duplication by reconstructing non-stored field values with synthetic _source, and improves compression with advanced algorithms and codecs. Key benefits include:

- Reduced costs: enables organizations to reduce storage expenses while retaining more data, saving costs across all storage tiers.

- Preservation of valuable data: retains all log data using features like synthetic _source, improving operational efficiency without relying on extra tools or filters.

- Expanded visibility: provides access to all data on one platform without separate silos for various data, accelerating problem resolution, investigation, and remediation for site reliability engineers (SREs) and security operations center (SOC) teams.

- Streamlined access to data: retains actionable data efficiently, enabling troubleshooting, trending and analysis for SRE teams, and allows SOC teams to swiftly search all of their data for investigation and threat hunting.

Logsdb index mode is generally available for Cloud Hosted and Self-Managed customers starting in version 8.17 and is enabled by default for logs in Elastic Cloud Serverless.

Basic logsdb index mode capabilities are available to organizations with Standard, Gold, and Platinum licenses. Complete logsdb index mode capabilities are available to Serverless customers as well as organizations with an Enterprise license.

The Latest

Artificial intelligence (AI) has become the dominant force shaping enterprise data strategies. Boards expect progress. Executives expect returns. And data leaders are under pressure to prove that their organizations are "AI-ready" ...

Agentic AI is a major buzzword for 2026. Many tech companies are making bold promises about this technology, but many aren't grounded in reality, at least not yet. This coming year will likely be shaped by reality checks for IT teams, and progress will only come from a focus on strong foundations and disciplined execution ...

AI systems are still prone to hallucinations and misjudgments ... To build the trust needed for adoption, AI must be paired with human-in-the-loop (HITL) oversight, or checkpoints where humans verify, guide, and decide what actions are taken. The balance between autonomy and accountability is what will allow AI to deliver on its promise without sacrificing human trust ...

More data center leaders are reducing their reliance on utility grids by investing in onsite power for rapidly scaling data centers, according to the Data Center Power Report from Bloom Energy ...

In MEAN TIME TO INSIGHT Episode 21, Shamus McGillicuddy, VP of Research, Network Infrastructure and Operations, at EMA discusses AI-driven NetOps ... 

Enterprise IT has become increasingly complex and fragmented. Organizations are juggling dozens — sometimes hundreds — of different tools for endpoint management, security, app delivery, and employee experience. Each one needs its own license, its own maintenance, and its own integration. The result is a patchwork of overlapping tools, data stuck in silos, security vulnerabilities, and IT teams are spending more time managing software than actually getting work done ...

2025 was the year everybody finally saw the cracks in the foundation. If you were running production workloads, you probably lived through at least one outage you could not explain to your executives without pulling up a diagram and a whiteboard ...

Data has never been more central to a greater portion of enterprise operations than it is today. From software development to marketing strategy, data has become an essential component for success. But as data use cases multiply, so too does the diversity of the data itself. This shift is pushing organizations toward increasingly complex data infrastructure ...

Enterprises are not stalling because they doubt AI, but because they cannot yet govern, validate, or safely scale autonomous systems, according to The Pulse of Agentic AI 2026, a new report from Dynatrace ...

For most of the cloud era, site reliability engineers (SREs) were measured by their ability to protect availability, maintain performance, and reduce the operational risk of change. Cost management was someone else's responsibility, typically finance, procurement, or a dedicated FinOps team. That separation of duties made sense when infrastructure was relatively static and cloud bills grew in predictable ways. But modern cloud-native systems don't behave that way ...

Elastic Announces Elasticsearch Logsdb Index Mode to Reduce Log Data Storage Footprint by Up to 65%

Security and observability teams now benefit from reduced storage expenses and longer log retention to support their threat hunting, incident response, and compliance requirements

Elastic announced the general availability of Elasticsearch logsdb index mode.

This latest innovation in log management reduces the storage footprint of log data by up to 65% compared to recent versions of Elasticsearch without logsdb index mode. Now, security and observability teams have increased visibility while keeping all data immediately accessible for analysis.

“Logs are critical for detection and remediation, but the growing log volume generated by infrastructure and applications is driving up costs and forcing compromises that hinder analysis,” said Ken Exner, chief product officer at Elastic. “Logsdb index mode reduces the disk footprint and overall cost of storing log data with features including smart index sorting, synthetic source and advanced compression.”

Logsdb index mode optimizes data ordering, eliminates duplication by reconstructing non-stored field values with synthetic _source, and improves compression with advanced algorithms and codecs. Key benefits include:

- Reduced costs: enables organizations to reduce storage expenses while retaining more data, saving costs across all storage tiers.

- Preservation of valuable data: retains all log data using features like synthetic _source, improving operational efficiency without relying on extra tools or filters.

- Expanded visibility: provides access to all data on one platform without separate silos for various data, accelerating problem resolution, investigation, and remediation for site reliability engineers (SREs) and security operations center (SOC) teams.

- Streamlined access to data: retains actionable data efficiently, enabling troubleshooting, trending and analysis for SRE teams, and allows SOC teams to swiftly search all of their data for investigation and threat hunting.

Logsdb index mode is generally available for Cloud Hosted and Self-Managed customers starting in version 8.17 and is enabled by default for logs in Elastic Cloud Serverless.

Basic logsdb index mode capabilities are available to organizations with Standard, Gold, and Platinum licenses. Complete logsdb index mode capabilities are available to Serverless customers as well as organizations with an Enterprise license.

The Latest

Artificial intelligence (AI) has become the dominant force shaping enterprise data strategies. Boards expect progress. Executives expect returns. And data leaders are under pressure to prove that their organizations are "AI-ready" ...

Agentic AI is a major buzzword for 2026. Many tech companies are making bold promises about this technology, but many aren't grounded in reality, at least not yet. This coming year will likely be shaped by reality checks for IT teams, and progress will only come from a focus on strong foundations and disciplined execution ...

AI systems are still prone to hallucinations and misjudgments ... To build the trust needed for adoption, AI must be paired with human-in-the-loop (HITL) oversight, or checkpoints where humans verify, guide, and decide what actions are taken. The balance between autonomy and accountability is what will allow AI to deliver on its promise without sacrificing human trust ...

More data center leaders are reducing their reliance on utility grids by investing in onsite power for rapidly scaling data centers, according to the Data Center Power Report from Bloom Energy ...

In MEAN TIME TO INSIGHT Episode 21, Shamus McGillicuddy, VP of Research, Network Infrastructure and Operations, at EMA discusses AI-driven NetOps ... 

Enterprise IT has become increasingly complex and fragmented. Organizations are juggling dozens — sometimes hundreds — of different tools for endpoint management, security, app delivery, and employee experience. Each one needs its own license, its own maintenance, and its own integration. The result is a patchwork of overlapping tools, data stuck in silos, security vulnerabilities, and IT teams are spending more time managing software than actually getting work done ...

2025 was the year everybody finally saw the cracks in the foundation. If you were running production workloads, you probably lived through at least one outage you could not explain to your executives without pulling up a diagram and a whiteboard ...

Data has never been more central to a greater portion of enterprise operations than it is today. From software development to marketing strategy, data has become an essential component for success. But as data use cases multiply, so too does the diversity of the data itself. This shift is pushing organizations toward increasingly complex data infrastructure ...

Enterprises are not stalling because they doubt AI, but because they cannot yet govern, validate, or safely scale autonomous systems, according to The Pulse of Agentic AI 2026, a new report from Dynatrace ...

For most of the cloud era, site reliability engineers (SREs) were measured by their ability to protect availability, maintain performance, and reduce the operational risk of change. Cost management was someone else's responsibility, typically finance, procurement, or a dedicated FinOps team. That separation of duties made sense when infrastructure was relatively static and cloud bills grew in predictable ways. But modern cloud-native systems don't behave that way ...