Skip to content
EduVerse
Elasticsearch

Elasticsearch

Explained

Database

Also known as: ES

Distributed search and analytics engine, at the core of the ELK stack for log analysis.

Elasticsearch, explained

Written by EduVerse

What it is

Elasticsearch is a distributed search and analytics engine that stores JSON documents and indexes the words inside them. You talk to it through a REST API, and it returns the best-matching results for a text search quickly, even across large amounts of data. It’s the E in the ELK stack, next to Logstash and Kibana.

Why teams use it

SQL searches with LIKE get slow on big tables and can’t tell which result fits best. Elasticsearch can handle typos, word variants and ranking by relevance, which is why shops use it for search boxes and teams use it to search logs. It usually sits beside the main database rather than replacing it.

An example from work

Something broke in production, and a colleague sends you a link to Kibana. You type the order id into the search bar, narrow the time range to the last hour, and within seconds see every log line from every service that mentions that order. Behind that screen, Elasticsearch does the searching.

Our own explanation, not a quote from the book.

In the book

Sentences from The Software Realm, Decoded that mention Elasticsearch, exactly as printed.

    1 more passages about Elasticsearch in the full book

    Read every conversation where Elasticsearch comes up, with the interactive slides and demos.

    See the book

    Where it fits

    Full-text search, log aggregation, analytics

    Coverage in the book

    Explained

    Explained and compared with alternatives, so you know where and why it’s used.

    Appears in