← Back to all services
Search Engines

Elasticsearch Ports & Configuration

elasticsearch systemctl: elasticsearch

Distributed search and analytics engine. Part of Elastic Stack (ELK).

🔌 Default Ports

9200
tcp
HTTP REST API
9300
tcp
Node communication

📦 Installation Command

wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | gpg --dearmor -o /usr/share/keyrings/elastic.gpg && echo 'deb [signed-by=/usr/share/keyrings/elastic.gpg] https://artifacts.elastic.co/packages/8.x/apt stable main' > /etc/apt/sources.list.d/elastic-8.x.list && apt update && apt install elasticsearch

⚙️ Configuration Files

  • /etc/elasticsearch/elasticsearch.yml
  • /etc/elasticsearch/jvm.options
  • /etc/elasticsearch/log4j2.properties

📂 Default Directories

  • config: /etc/elasticsearch
  • data: /var/lib/elasticsearch
  • logs: /var/log/elasticsearch
  • plugins: /usr/share/elasticsearch/plugins

🔐 Default Credentials

Username:elastic
Password:Generated at install
💡 ES 8.x enables security by default. Password shown at install or reset with: /usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic

📌 Dependencies

openjdk-17-jdk

⚠️ Conflicts

opensearch (same ports) Port: opensearch

✅ Works With

kibanalogstashfilebeatmetricbeat

🛡️ Security Notes

Enable security (default in 8.x), use TLS, set proper JVM heap (50% RAM, max 32GB), never expose 9200 to internet without auth

❓ Frequently Asked Questions

What ports does Elasticsearch use?
Elasticsearch uses port 9200 for HTTP API and 9300 for inter-node transport.
Where is Elasticsearch config?
Config at /etc/elasticsearch/elasticsearch.yml.
How to secure Elasticsearch?
Enable X-Pack security, bind to localhost, use authentication and TLS.