Amazon Elasticsearch Service: Is it as Good as a Standalone Installation?

Perhaps surprisingly, Amazon Elasticsearch is hardly overwhelming, coming with a very basic tool kit and an outdated release version. And it’s expensive.

Just a month ago, AWS launched their Amazon Elasticsearch Service. Elasticsearch itself is an open source scalable, distributed, real-time search and analytics engine from Elastic, the creators of Logstash, Beats, and Kibana. Elasticsearch makes an excellent alternative to Splunk.
According to AWS Elasticsearch documentation:

“Amazon Elasticsearch Service (Amazon ES) is a managed service that makes it easy to deploy, operate, and scale Elasticsearch in the AWS cloud…You can set up and configure your Amazon Elasticsearch cluster in minutes from the AWS Management Console. Amazon ES provisions all the resources for your cluster and launches it…Amazon ES allows you to easily scale your cluster via a single API call or a few clicks in the AWS Management Console.”

Amazon Elasticsearch features

According to their documentation, the Amazon Elasticsearch Service provides the following features:

  • A full range of instance types from which to build your clusters.
  • Magnetic, General Purpose, and Provisioned IOPS EBS volumes.
  • Clusters spanning multiple regions and Availability Zones.
  • Security through IAM-based access control.
  • Dedicated master nodes to improve cluster stability.
  • Domain snapshots to back up and restore Elasticsearch domains and replicate domains across Availability Zones.
  • Kibana for data visualization.
  • Integration with Amazon CloudWatch for monitoring Elasticsearch domain metrics.
  • Integration with AWS CloudTrail for auditing configuration API calls to Elasticsearch domains.

Amazon Elasticsearch currently uses following package versions:

  • Elasticsearch 1.5.2
  • Kibana 4 (also Kibana 3 as a plugin).
  • Plugins: jetty, cloud-aws, kuromoji, and icu.
  • The following APIs:
/_alias, /_aliases, /_all, /_analyze, /_bulk, /_cat, /_cluster/health, /_cluster/settings, /_cluster/stats, /_count, /_flush, /_mapping, /_mget, /_msearch, /_nodes, /_plugin/kibana, /_plugin/kibana3, /_percolate, /_refresh, /_search, /_snapshot, /_stats, /status, /_template

Amazon Elasticsearch: limits

Amazon Elasticsearch has a few built-in limitations which you need to be aware of before you start:

Older version of Elasticsearch

Elasticsearch 1.5.2 – the version used by Amazon – is actually quite old when compared with the current stable version is (1.7.2). And Elasticsearch 2.0.0 beta, which is just around the corner, will address many more bugs. Since Amazon Elasticsearch is a managed service, there is no way for you to upgrade your clusters on your own. If you were to host Elasticsearch yourself, upgrades would be as simple as updating the jar files in ES_HOME/lib folder.

Elasticsearch 1.5.x and other versions have critical bugs

In the release notes to Elasticsearch 1.7.1, more than a dozen bugs are identified as fixed. Users are advised to upgrade their clusters as soon as possible. Here are just a couple of examples:

IP range aggregation issue:

ip_range aggregation with mask of gets treated as This was resolved with the 1.7.x release.

Data-loss issue:

Elasticsearch 1.7.x has addressed many problems from 1.5.2, including one which could result in the loss of an entire index if you suffer a multiple node failure while having idle shards. This might be a particularly serious concern with a cloud setup, where node failures due to Availability Zone outages are not uncommon. Although these are rare cases, Elasticsearch Support did send this email alert to their customers:

EBS volume size

You can attach a maximum of 512 GB of storage to a single I or R series node (i2.2xlarge, r3.8xlarge etc). For M series nodes, however, you are limited to a maximum of 100 GBs. Besides the fact that I and R series nodes are expensive, they only come as large, instance-store volumes. This is an obvious problem if you intend to shut down, and then reuse your Elasticsearch cluster at some future time.

Instance types

There are two major limitations with the instance types available for Amazon Elasticsearch. The first is that you can only run a maximum of ten instances per cluster. If you want more, you’ll have to submit a service request for an increase. The second problem concerns node memory. Here’s what Elasticsearch’s documentation says:

“A machine with 64 GB of RAM is the ideal sweet spot, but 32 GB and 16 GB machines are also common. Less than 8 GB tends to be counterproductive (you end up needing many, many small machines)”.

Seeing how AWS offers us r3.2xlarge instances (and higher) and i2.2xlarge, fits nicely with Elastic’s ideal for cluster nodes, but they will be very expensive. An EC2 r3.8xlarge on-demand RHEL instance costs $2.903 per hour, and the r3.8xlarge.elasticsearch will cost you $4.704 per hour!

No Shield, Watcher, and Marvel support

Elasticsearch has released many commercial products: Shield for security, Watcher for alerts and notifications, and Marvel for cluster monitoring. They are really useful and come out-of-box with Elasticsearch. There are many such plugins, like Sense, kopf, and river, that were developed for Elasticsearch administrators and developers. You can certainly use AWS’s IAM and Cloudwatch in place of Shield and Marvel, but choosing those will sometimes add extra costs and often new skills. If you already have Shield, Watcher, and Marvel licenses, and you’re just moving your existing Elasticsearch cluster to Amazon, then those licenses will be of no use.

No River Plugin support:

River plugins are helpful for supporting data migration from a source to an Elasticsearch cluster (like MongoDB River and jdbc River). Again, not all of those are available for Amazon Elasticsearch installations.


Perhaps surprisingly, Amazon Elasticsearch is hardly overwhelming. It certainly looks nice, but it comes with a very basic tool kit and, as we’ve seen, lacks access to some fairly critical features. In my opinion, Amazon Elasticsearch does deliver an agile offering with faster cluster set up and automated snapshot and restore process, but it is not yet cost-effective.
Setting up Elasticsearch on your own VM (including EC2 instances) is not at all difficult. You can decompress the zip or tar files and, with a minimum of administration knowledge, make the light modifications to the elasticsearch.yml file. You’ll have your cluster up and running in minutes. With your own setup, you have more control over your cluster. You can change the parameters and reconcile your cluster with releases from Elasticsearch.

However, this is Amazon, and this is just a 1.0 release. We can certainly expect to see something significantly more robust in the coming months.



Written by

Chandan Patra

Cloud Computing and Big Data professional with 10 years of experience in pre-sales, architecture, design, build and troubleshooting with best engineering practices.Specialities: Cloud Computing - AWS, DevOps(Chef), Hadoop Ecosystem, Storm & Kafka, ELK Stack, NoSQL, Java, Spring, Hibernate, Web Service

Related Posts

Sam Ghardashem
Sam Ghardashem
— May 15, 2019

Aviatrix Integration of a NextGen Firewall in AWS Transit Gateway

Learn how Aviatrix’s intelligent orchestration and control eliminates unwanted tradeoffs encountered when deploying Palo Alto Networks VM-Series Firewalls with AWS Transit Gateway.Deploying any next generation firewall in a public cloud environment is challenging, not because of the f...

Read more
  • AWS
Joe Nemer
Joe Nemer
— May 3, 2019

AWS Config Best Practices for Compliance

Use AWS Config the Right Way for Successful ComplianceIt’s well-known that AWS Config is a powerful service for monitoring all changes across your resources. As AWS Config has constantly evolved and improved over the years, it has transformed into a true powerhouse for monitoring your...

Read more
  • AWS
  • Compliance
Francesca Vigliani
— April 30, 2019

Cloud Academy is Coming to the AWS Summits in Atlanta, London, and Chicago

Cloud Academy is a proud sponsor of the 2019 AWS Summits in Atlanta, London, and Chicago. We hope you plan to attend these free events that bring the cloud computing community together to connect, collaborate, and learn about AWS. These events are all about learning. You can learn how t...

Read more
  • AWS
  • AWS Summits
Paul Hortop
Paul Hortop
— April 2, 2019

How to Monitor Your AWS Infrastructure

The AWS cloud platform has made it easier than ever to be flexible, efficient, and cost-effective. However, monitoring your AWS infrastructure is the key to getting all of these benefits. Realizing these benefits requires that you follow AWS best practices which constantly change as AWS...

Read more
  • AWS
  • Monitoring
Joe Nemer
Joe Nemer
— April 1, 2019

AWS EC2 Instance Types Explained

Amazon Web Services’ resource offerings are constantly changing, and staying on top of their evolution can be a challenge. Elastic Cloud Compute (EC2) instances are one of their core resource offerings, and they form the backbone of most cloud deployments. EC2 instances provide you with...

Read more
  • AWS
  • EC2
Nitheesh Poojary
— March 26, 2019

How DNS Works – the Domain Name System (Part One)

Before migrating domains to Amazon's Route53, we should first make sure we properly understand how DNS worksWhile we'll get to AWS's Route53 Domain Name System (DNS) service in the second part of this series, I thought it would be helpful to first make sure that we properly understand...

Read more
  • AWS
Stuart Scott
— March 14, 2019

Multiple AWS Account Management using AWS Organizations

As businesses expand their footprint on AWS and utilize more services to build and deploy their applications, it becomes apparent that multiple AWS accounts are required to manage the environment and infrastructure.  A multi-account strategy is beneficial for a number of reasons as ...

Read more
  • AWS
  • Identity Access Management
Sanket Dangi
— February 11, 2019

WaitCondition Controls the Pace of AWS CloudFormation Templates

AWS's WaitCondition can be used with CloudFormation templates to ensure required resources are running.As you may already be aware, AWS CloudFormation is used for infrastructure automation by allowing you to write JSON templates to automatically install, configure, and bootstrap your ...

Read more
  • AWS
  • CloudFormation
Badrinath Venkatachari
Badrinath Venkatachari
— February 1, 2019

10 Common AWS Mistakes & How to Avoid Them

Massive migration to the public cloud is changing architecture patterns, operating principles, and governance models. That means new approaches are vital to get a handle on soaring cloud spend. Because the cloud’s short-term billing cycles call for financial discipline, you must empower...

Read more
  • AWS
  • Operations
Andrew Larkin
— January 24, 2019

The 9 AWS Certifications: Which is Right for You and Your Team?

As companies increasingly shift workloads to the public cloud, cloud computing has moved from a nice-to-have to a core competency in the enterprise. This shift requires a new set of skills to design, deploy, and manage applications in cloud computing.As the market leader and most ma...

Read more
  • AWS
  • AWS Certifications
Andrew Larkin
— January 15, 2019

2018 Was a Big Year for Content at Cloud Academy

As Head of Content at Cloud Academy I work closely with our customers and my domain leads to prioritize quarterly content plans that will achieve the best outcomes for our customers.We started 2018 with two content objectives: To show customer teams how to use Cloud Services to solv...

Read more
  • AWS
  • Azure
  • Cloud Computing
  • Google Cloud Platform
Jeremy Cook
— November 29, 2018

Amazon Elastic Inference – GPU Acceleration for Faster Inferencing

“Add GPU acceleration to any Amazon EC2 instance for faster inference at much lower cost (up to 75% savings)”So you’ve just kicked off the training phase of your multilayered deep neural network. The training phase is leveraging Amazon EC2 P3 instances to keep the training time to a...

Read more
  • AWS
  • Elastic Inference
  • re:Invent 2018