Definition ยท Open Ports & Services

What is Elasticsearch Exposure?

Elasticsearch is a search and analytics engine controlled entirely through an HTTP API, normally on port 9200, with an inter-node transport channel on 9300. Because the API is HTTP and returns JSON, an exposed cluster needs no special tooling to explore: a browser or a single request can list indices and retrieve documents.

Why exposed clusters are so consequential

Elasticsearch is usually a secondary store rather than the system of record, which means it tends to hold denormalised copies of whatever is searchable โ€” customer records, order history, log and telemetry data, support tickets. The data is often broader than the owning team expects, and log indices in particular accumulate tokens, session identifiers and personal data nobody intended to retain.

Older major versions shipped without authentication enabled in the free distribution, so securing a cluster was an extra step that was frequently skipped; later versions enable security features by default. The result is a long tail of legacy clusters where GET /_cat/indices from the internet returns the full picture.

What to check

Externally, look for an HTTP service on 9200 that responds to an unauthenticated request with cluster information, and for a Kibana interface โ€” commonly on 5601 โ€” reachable without a login, since Kibana is a full query and visualisation front end to the same data. Exposed clusters have also been targeted for extortion, where indices are wiped and a ransom note left behind as a document.

Securing it

Bind to an internal interface, enable authentication and role-based access, require TLS for both the HTTP and transport layers, restrict source addresses, and keep the version current. Treat Kibana and any other front end as part of the same boundary, and apply least privilege to the API keys applications use.

See database exposure for the wider pattern and its port list, S3 bucket exposure for the object storage equivalent, and security misconfiguration. SurfaceLoop flags services like this during open port discovery.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.