What Is Amazon Elasticsearch Service?
Amazon Elasticsearch Service (Amazon ES) is a managed service that makes it easy to create a domain and deploy, operate, and scale Elasticsearch clusters in the AWS Cloud. Elasticsearch is a popular open-source search and analytics engine for use cases such as log analytics, real-time application monitoring, and clickstream analytics. With Amazon ES, you get direct access to Elasticsearch open-source APIs so that existing code and applications work seamlessly together. Currently, Amazon ES supports Elasticsearch versions 1.5 and 2.3. To learn more about Elasticsearch and its uses, see Getting Started in the Elasticsearch Reference.
Amazon ES provisions all the resources for your Elasticsearch cluster and launches it; automatically detects and replaces failed Elasticsearch nodes, reducing the overhead associated with self-managed infrastructures; and allows you to easily scale your cluster with a single API call or a few clicks in the console.
To get started using the service, you create an Amazon ES domain. An Amazon ES domain is an Elasticsearch cluster in the AWS Cloud that has the compute and storage resources that you specify. For example, you can specify the number of instances, instance types, and storage options.
Additionally, Amazon ES offers the following benefits of a managed service:
Cluster scaling options
Self-healing clusters
Replication for high availability
Data durability
Enhanced security
Node monitoring
You can use the Amazon ES console to set up and configure your domain in minutes. If you prefer programmatic access, you can use the AWS SDKs or the AWS CLI.
There are no upfront costs to set up clusters, and you pay only for the service resources that you use.
Features of Amazon Elasticsearch Service
Amazon ES provides the following features:
Multiple configurations of CPU, memory, and storage capacity, known as instance types
Storage volumes for your data using Amazon Elastic Block Store (Amazon EBS), known as Amazon EBS volumes
Multiple geographical locations for your resources, known as regions and Availability Zones
Cluster node allocation across two Availability Zones in the same region, known as zone awareness
Security with AWS Identity and Access Management (IAM) access control
Dedicated master nodes to improve cluster stability
Domain snapshots to back up and restore Amazon ES domains and replicate domains across Availability Zones
Kibana for data visualization
Integration with Amazon CloudWatch for monitoring Amazon ES domain metrics
Integration with AWS CloudTrail for auditing configuration API calls to Amazon ES domains
Integration with Amazon S3, Amazon Kinesis, and Amazon DynamoDB for loading streaming data into Amazon ES
How to Get Started with Amazon Elasticsearch Service
To get started, sign up for an AWS account if you don't already have one. For more information, see Signing Up for AWS.
After you are set up, complete the Getting Started tutorial for Amazon Elasticsearch Service. Consult the following introductory topics if you need more information while learning about the service.
Get Up and Running
Basics
Instance Types and Storage
Security
Signing Up for AWS
If you're not already an AWS customer, create an account. If you already have an AWS account, you are automatically signed up for Amazon ES. Your AWS account enables you to access Amazon ES and other services in the AWS platform, such as Amazon Simple Storage Service (Amazon S3) and Amazon Elastic Compute Cloud (Amazon EC2). There are no sign-up fees, and charges are not incurred until you create a domain. As with other AWS services, you pay only for the resources that you use.
You can use your AWS Identity and Access Management (IAM) user name and password to sign in to the AWS Management Console if you have an account with the IAM service. IAM allows you to securely control access to AWS and resources in your AWS account.
To create an AWS account
Go to https://aws.amazon.com, and then choose Sign In to the Console.
Follow the instructions to sign up. You will need to enter payment information before you can begin using Amazon ES.
Accessing Amazon Elasticsearch Service
You can access Amazon Elasticsearch Service through the Amazon Elasticsearch Service console, the AWS SDKs, or the AWS CLI.
The Amazon ES console enables you to easily create, configure, and monitor your domains, and also upload data. Using the console is the easiest way to get started with Amazon ES and provides a central command center for ongoing management of your domains.
The AWS SDKs support all of the Amazon Elasticsearch Service API operations, making it easy to manage and interact with your domains using your preferred technology. The SDKs automatically sign requests as needed using your AWS credentials.
The AWS CLI wraps all of the Amazon Elasticsearch Service API operations to provide a simple way to create and configure domains. The AWS CLI automatically signs requests as needed using your AWS credentials.
For information about Elasticsearch APIs and features, see the Elasticsearch documentation.
Regions and Endpoints for Amazon Elasticsearch Service
Amazon ES provides regional endpoints for accessing the configuration API and domain-specific endpoints for accessing the search API. You use the configuration service to create and manage your domains. The region-specific configuration service endpoints are of the following form:
es.region.amazonaws.com
For example, es.us-east-1.amazonaws.com. For a list of supported
regions, see Regions
and Endpoints in the AWS General Reference.
Amazon ES provides a single service endpoint for both search and data services:
http://search-domainname-domainid.us-east-1.es.amazonaws.com
A domain's search endpoint is used to upload data and submit search requests.
Scaling in Amazon Elasticsearch Service
A domain has one or more Elasticsearch instances, each with a finite amount of RAM, CPU, and storage resources for indexing data and processing requests. The number of Elasticsearch instances needed by a domain depends on the documents in your collection and the volume and complexity of your Elasticsearch requests. When you create a domain, you select an initial number of Elasticsearch instances and an instance type. However, these initial choices might not be adequate as the quantity and size of data increase and as Elasticsearch requests increase in number and complexity. You can accommodate the growth by scaling your Amazon ES domain using the guidelines in the following table.
| Domain Change | Scaling Guidelines |
|---|---|
| Increase in data quantity Increase in data size |
Use the following guidelines to scale for both increased data quantity and data size:
|
| Increase in traffic due to Elasticsearch request volume and complexity |
Use the following guidelines to scale for increased traffic:
Replica shards provide failover; a replica shard is promoted to a primary shard if a cluster node containing a primary shard fails. For more information about replica shards, see Shards and Replicas in the Elasticsearch documentation. |
Scaling for Increased Data
Each Amazon ES domain has one or more search indices. The index stores data in one or more shards distributed across the search instances in your cluster. Amazon ES will automatically migrate shards between search instances as your cluster grows. However, the number of primary shards is fixed when the index is created. The number of primary shards defines the maximum amount of data that can be stored in an index. For more information about indices and shards, see Add an Index in the Elasticsearch documentation.
If you choose to add instances, the index shards are distributed among the available search instances. For more information, see Scale Horizontally in the Elasticsearch documentation. Choosing a larger instance type provides larger local storage for your cluster. Use larger EBS volumes to accommodate larger indices.
Scaling for Increased Traffic
Search and document retrieval requests can be served by primary or replica shards. The more replica shards a cluster has, the more search requests the cluster can handle. Larger instance types have more hardware resources, such as RAM and CPU, which allow each shard to perform better. For more information, see Shards and Replicas in the Elasticsearch documentation.
Signing Service Requests
If you use a programming language for which AWS provides an SDK, we recommend that you use the SDK to submit HTTP requests to AWS. All of the AWS SDKs greatly simplify the process of signing requests, and save you a significant amount of time when compared to natively accessing the Elasticsearch APIs. The SDKs integrate easily with your development environment and provide easy access to related commands. You can also use the Amazon ES console and AWS CLI to submit signed requests with no additional effort.
If you choose to call the Elasticsearch APIs directly, you must sign your own requests. Configuration service requests must always be signed. All requests must be signed unless you configure anonymous access for those services. Use the following procedure to sign a request:
Calculate a digital signature using a cryptographic hash function. The input must include the text of your request and your secret access key.
The function returns a hash value based on your input.
Include the digital signature in the Authorization header of your request.
The service recalculates the signature using the same hash function and input that you used. If the resulting signature matches the signature in the request, the service processes the request. Otherwise, the service rejects the request.
Amazon ES supports authentication using AWS Signature Version 4. For more information, see Signature Version 4 Signing Process.
Choosing an Instance Type
An instance type defines the memory, CPU, storage capacity, and hourly cost for an instance, the Amazon Machine Image (AMI) that runs as a virtual server in the AWS Cloud. You should choose the instance type and the number of instances based on the anticipated size of the Elasticsearch indices, shards, and replicas that you intend to create on your cluster. Amazon ES supports the following instance types:
t2.micro.elasticsearch
t2.small.elasticsearch
t2.medium.elasticsearch
m3.medium.elasticsearch
m3.large.elasticsearch
m3.xlarge.elasticsearch
m3.2xlarge.elasticsearch
r3.large.elasticsearch
r3.xlarge.elasticsearch
r3.2xlarge.elasticsearch
r3.4xlarge.elasticsearch
r3.8xlarge.elasticsearch
i2.xlarge.elasticsearch
i2.2xlarge.elasticsearch
Note
The sa-east-1 and us-east-2 regions do not support r3 and i2 instance types.
The us-east-2, ap-northeast-2, and ap-south-1 regions support m4 instance types instead of m3 instance types.
For more information, see Instance Types in the Amazon EC2 documentation.
Using Amazon EBS Volumes for Storage
You have the option of configuring your Amazon ES domain to use an Amazon EBS volume for storing indices rather than the default storage provided by the instance. An Amazon EBS volume is a durable, block-level storage device that you can attach to a single instance. Amazon ES supports the following EBS volume types:
Magnetic
General Purpose (SSD)
Provisioned IOPS (SSD)
For more information, see Amazon EBS Volumes in the Amazon EC2 documentation.
Choosing an Elasticsearch Version
Amazon ES currently supports two Elasticsearch versions: 1.5 and 2.3. Compared to Elasticsearch version 1.5, version 2.3 offers improved performance, memory management, and security. It also offers several additional features, including the following:
Pipeline aggregations to perform advanced analytics, such as moving averages and derivatives
Enhancements to geospatial queries
Configurable store compression
For more information about the differences between Elasticsearch 1.5 and 2.3, see the Elasticsearch documentation. For information about the Elasticsearch APIs that Amazon ES supports for both 1.5 and 2.3, see Supported Elasticsearch Operations.
If you are starting a new Elasticsearch project, we strongly recommend that you choose version 2.3. If you have an existing 1.5 domain, you can choose to keep the domain or migrate your data to a new 2.3 domain. For more information, see Migrating Data in a Domain from Elasticsearch Version 1.5 to Version 2.3.
Related Services
Amazon ES is commonly used with the following services:
- AWS CloudTrail
Use AWS CloudTrail to get a history of the Amazon ES API calls and related events for your account. CloudTrail is a web service that records API calls from your accounts and delivers the resulting log files to your Amazon S3 bucket. You can also use CloudTrail to track changes that were made to your AWS resources. For more information, see Auditing Amazon Elasticsearch Service Domains with AWS CloudTrail.
- Amazon CloudWatch
An Amazon ES domain automatically sends metrics to Amazon CloudWatch so that you can gather and analyze performance statistics. You can monitor these metrics by using the AWS CLI or the AWS SDKs. For more information, see Monitoring Cluster Metrics and Statistics with Amazon CloudWatch (Console).
- Amazon Kinesis
Amazon Kinesis is a managed service that scales elastically for real-time processing of streaming data at a massive scale. Amazon ES provides Lambda sample code for integration with Amazon Kinesis. For more information, see Streaming Data to Amazon ES From Amazon Kinesis.
- Amazon S3
Amazon Simple Storage Service (Amazon S3) is storage for the Internet. You can use Amazon S3 to store and retrieve any amount of data at any time, from anywhere on the web. Amazon ES provides Lambda sample code for integration with S3. For more information, see Streaming Data to Amazon ES From Amazon S3.
- AWS IAM
AWS Identity and Access Management (IAM) is a web service that you can use to manage users and user permissions in AWS. Use IAM to create user-based access policies for your Amazon ES domains. See the IAM documentation for more information about using IAM to create user polices.
Amazon ES integrates with the following services to provide data ingestion:
- AWS Lambda
AWS Lambda is a zero-administration compute platform for back-end web developers that runs your code in the AWS Cloud and provides you with a fine-grained pricing structure. Amazon ES provides sample code to run on Lambda that integrates with Amazon Kinesis and Amazon S3. For more information, see Streaming Data to Amazon ES.
- Amazon DynamoDB
Amazon DynamoDB is a fully managed NoSQL database service that provides fast and predictable performance with seamless scalability. Amazon ES provides a Logstash plugin to support DynamoDB Streams and sign AWS service requests.
Pricing for Amazon Elasticsearch Service
With Amazon Web Services, you pay only for what you use. For Amazon ES, you pay for each hour of use of an EC2 instance. You also have the option of paying for additional storage based on the cumulative size of EBS volumes attached to the data nodes in your domain.
If you qualify for the AWS Free Tier, you receive up to 750 hours per month of use with the t2.micro.elasticsearch instance type, as well as up to 10 GB of magnetic or general provisioned EBS storage. For more information, see AWS Free Tier.



