Elasticsearch
ExplainedDatabase
Also known as: ES
Distributed search and analytics engine, at the core of the ELK stack for log analysis.
Elasticsearch, explained
Written by EduVerseWhat it is
Elasticsearch is a distributed search and analytics engine that stores JSON documents and indexes the words inside them. You talk to it through a REST API, and it returns the best-matching results for a text search quickly, even across large amounts of data. It’s the E in the ELK stack, next to Logstash and Kibana.
Why teams use it
SQL searches with LIKE get slow on big tables and can’t tell which result fits best. Elasticsearch can handle typos, word variants and ranking by relevance, which is why shops use it for search boxes and teams use it to search logs. It usually sits beside the main database rather than replacing it.
An example from work
Something broke in production, and a colleague sends you a link to Kibana. You type the order id into the search bar, narrow the time range to the last hour, and within seconds see every log line from every service that mentions that order. Behind that screen, Elasticsearch does the searching.
Our own explanation, not a quote from the book.
In the book
Sentences from The Software Realm, Decoded that mention Elasticsearch, exactly as printed.
1 more passages about Elasticsearch in the full book
Read every conversation where Elasticsearch comes up, with the interactive slides and demos.
Where it fits
Full-text search, log aggregation, analytics
Coverage in the book
Explained and compared with alternatives, so you know where and why it’s used.