OpenSearch
OpenSearch is an open source search and analytics engine you can self-host — an Apache 2.0 Elasticsearch fork with a REST API for full-text search, log analytics, and vector search, plus OpenSearch Dashboards for visualization.
OpenSearch is an open source search and analytics engine you can self-host — a distributed, REST-based platform for full-text search, log and observability analytics, security analytics, and vector search. It began as an Apache 2.0 fork of Elasticsearch 7.10.2 and now runs under the Linux Foundation.
What is OpenSearch?
OpenSearch is a distributed search and analytics engine that indexes documents and answers queries over a REST API. AWS forked it from Elasticsearch 7.10.2 in 2021 after Elastic dropped the Apache 2.0 license, and governance moved to the OpenSearch Software Foundation (Linux Foundation) in September 2024. It ships with OpenSearch Dashboards for visualization and exploration.
What is OpenSearch best for?
OpenSearch fits teams that need search or log analytics at scale without proprietary licensing. It is a strong choice for centralized log and observability pipelines, application and site search, security analytics (SIEM-style threat detection), and AI-powered vector or hybrid search — especially if you want to self-host and keep data on your own infrastructure.
What can OpenSearch do?
- Full-text search over structured and unstructured data with a rich query DSL and REST API.
- Log and observability analytics — ingest, search, and alert on machine data at scale, the classic ELK-style use case.
- Vector and hybrid search — k-NN vector fields and semantic search for AI and RAG applications.
- Security analytics — real-time threat detection with event correlation and prebuilt detection rules.
- Anomaly detection and alerting — built-in ML jobs and a monitoring/alerting plugin, all in the free distribution.
- OpenSearch Dashboards — visualizations, dashboards, and data exploration (the Kibana counterpart).
- SQL and Piped Processing Language (PPL) query interfaces alongside the native DSL.
Where does OpenSearch fall short?
- Feature drift from Elasticsearch. Because the two projects diverged in 2021, query syntax, APIs, and clients are no longer drop-in compatible. Migrating from newer Elasticsearch versions — or comparing benchmarks — requires care, and some Elastic features have no exact OpenSearch equivalent.
- Heavy JVM resource appetite. OpenSearch is a Java application that runs on the JVM and expects generous heap and memory; a serious cluster needs careful sizing, dedicated master/data node roles, and ongoing tuning to stay stable.
- Operational complexity at scale. Sharding, replication, index lifecycle management, and version upgrades are genuinely involved. For simple site search, a lighter engine may be less to run.
Is OpenSearch free?
Yes — OpenSearch is fully free and open source under the Apache 2.0 license, with security, alerting, SQL, anomaly detection, and vector search all in the free distribution (no paid tier gating features). You only pay if you choose a managed host such as Amazon OpenSearch Service, where you pay the provider for the underlying compute and storage.
What does OpenSearch replace?
OpenSearch is an open source Elastic Cloud alternative and a self-hosted stand-in for managed Elasticsearch. Its log-analytics and security-analytics features make it a credible Splunk alternative for teams put off by volume-based licensing, and its search API and vector search can replace hosted Algolia for site and application search when you want to own the infrastructure.
FAQ
Is OpenSearch open source? Yes. OpenSearch is licensed under Apache 2.0 — a permissive, OSI-approved license — and is governed by the OpenSearch Software Foundation under the Linux Foundation, with steering members including AWS, SAP, and Uber.
Is OpenSearch the same as Elasticsearch? No. OpenSearch forked from Elasticsearch 7.10.2 in 2021, so they share heritage but have diverged. Elasticsearch is now dual-licensed (AGPLv3 / Elastic License / SSPL) with some features behind paid subscriptions; OpenSearch keeps everything Apache 2.0 and free.
Can I self-host OpenSearch for free? Yes. You can run OpenSearch and OpenSearch Dashboards on your own servers at no license cost. You provide the hardware — plan for adequate RAM and JVM heap since it is a Java-based distributed engine.
What do I need to run OpenSearch? A Java runtime (bundled in the distribution) and a Linux host with enough memory for the JVM heap; Docker images and tarballs are provided. Production clusters typically run multiple nodes with dedicated roles for resilience.