Elastic Announces General Availability of Cross-Project Search for Querying Across Serverless Projects Without Moving Data

via Business Wire
ⓘ This article is third-party content and does not represent the views of this site. We make no guarantees regarding its accuracy or completeness.

Security analysts, SREs and app engineers can search across serverless projects, regions and cloud providers

Elastic (NYSE: ESTC) today announced the general availability of cross-project search (CPS) for Elastic Cloud Serverless, enabling teams to query across multiple serverless projects without moving or duplicating data. Security analysts, SREs and app engineers get a unified search experience across regions, cloud providers and project types, without the operational overhead of centralizing data.

Organizations keep data in separate projects for good reasons, such as data residency, compliance, tenant data isolation and organizational structure. But that separation can make it harder to work across the data.

SOC teams may need to move data between regional projects to investigate a threat, while SREs may need to correlate signals across different environments. While centralizing the data can solve the visibility problem, it requires teams to move and store data twice and manage the operational complexity of maintaining version compatibility. Existing solutions either require customers to accept single-cloud lock-in, or take on the operational burden of version coordination and server setup just to run a federated query.

Cross-project search helps break down data silos across distributed architectures without compromising data isolation, residency, or boundaries that systems rely on, at minimal cost. Teams link projects directly in the Elastic Cloud UI in a few clicks, with authentication handled at the organization level by Elastic's control plane and role-based access controls maintaining complete security scope across linked projects. Once linked, teams can query across those projects without moving the underlying data.

Cross-cluster search (CCS), a similar capability available in Elastic Cloud Hosted, is already used by more than 80% of large ECH customers with complex architectures. CPS delivers similar federated search capabilities to Elastic Cloud Serverless without requiring individual remote cluster connections.

"We relied heavily on cross-cluster search to investigate alerts, hunt threats and run detection rules across multiple environments. Elastic’s cross-project search gives us the same capability across our serverless infrastructure, but it's easier to configure. It also lets us safely segregate customer and workload data, with dedicated deployments for each customer or use case, such as separate security and observability environments,” said Callum Brown, head of Security Engineering, Acumen Cyber. “We get independent scaling, permissions, and resilience, without mixing data, and our engineers spend less time managing infrastructure and more time focused on security, while still querying everything from a single interface."

With general availability, CPS introduces new features:

  • Scale: CPS supports up to 100 linked projects by default across Search, Observability, Security, and Vector Database workloads. Customers that need to connect more than 100 projects can work with Elastic to provision a higher limit.
  • Enhanced Machine Learning and AI capabilities: ML anomaly detection jobs and data transforms can run seamlessly across linked projects. Alongside Agent Builder, which can also retrieve context from multiple linked projects in a single query, CPS acts as a foundational building block for production agents operating on distributed data.
  • Complete Access Control: A user's access to data across linked projects is based on their permissions for each project, regardless of where the query originates. Users see only the data they are authorized to access.
  • Reduced costs: Because data stays where it is, customers pay for the queries they run, not for storing and moving the same bytes twice.
  • Full Project Routing: Teams can control which projects a query targets using predefined tags for region, cloud provider, and project alias, as well as custom tags to target any subset of linked projects with precision.
  • Programmatic Access: A new user role enables users beyond organization owners to generate Cloud API keys for cross-project search queries, making it easier for teams to build pipelines and applications on CPS.

"Building a global SOC or a borderless observability practice used to mean choosing between operational simplicity and data control," said Ajay Nair, general manager, Elasticsearch and Platform, Elastic. "Teams either paid to centralize everything, or they lived with fragmented visibility. With CPS, teams don't have to make these difficult trade-offs. The data stays in the project where it belongs, while teams can query it from a single interface, without involving the compliance team every time someone needs to run a query."

Availability

Cross-project search is generally available in Elastic Cloud Serverless.

If you are already running Elastic Cloud Serverless, CPS is available in your project settings today. Link your projects, open Discover, and run your first cross-project query. If you are a new user, get started here.

Additional Materials

Blog: Elastic announces GA of cross-project search on Serverless, enabling teams to query across all linked projects without moving a byte

About Elastic

Elastic (NYSE: ESTC) integrates its deep expertise in search technology with artificial intelligence to help everyone transform all of their data into answers, actions, and outcomes. The Elasticsearch Platform, which is the foundation for its search, observability, and security solutions, is used by thousands of companies, including more than 75% of the Fortune 100. Learn more at elastic.co.

Elastic and associated marks are trademarks or registered trademarks of elasticsearch B.V. and its subsidiaries. All other company and product names may be trademarks of their respective owners.

Contacts

Report this content

If you believe this article contains misleading, harmful, or spam content, please let us know.

Report this article