> ## Documentation Index
> Fetch the complete documentation index at: https://opensre.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS Elasticsearch (AWS ES)

> Connect Amazon OpenSearch Service (AWS ES) so OpenSRE can search application logs

## Overview

OpenSRE queries Amazon OpenSearch Service (formerly Amazon Elasticsearch Service, AWS ES) over its REST API to pull error logs and application events into its answers. This page covers AWS ES specifically; for self-hosted OpenSearch or Elastic Cloud, see the [OpenSearch / Elasticsearch integration](/docs/integrations/databases/opensearch).

AWS ES runs the same integration as self-hosted OpenSearch: there's no separate "AWS ES" config, just an `OPENSEARCH_URL` pointed at your domain endpoint. Verify and setup use the **`opensearch`** service name.

## Prerequisites

* An Amazon OpenSearch Service (AWS ES) domain
* The domain endpoint URL (e.g. `https://search-mydomain-xxxxx.us-east-1.es.amazonaws.com`)
* Fine-grained access control enabled on the domain, with a dedicated internal user mapped to a read-only role (the built-in `readall` role works) rather than the master user

## Setup

### Option 1: CLI setup

```bash theme={null}
opensre integrations setup opensearch
```

Pick **OpenSearch / Elasticsearch**.

### Option 2: Environment variables

```bash theme={null}
OPENSEARCH_URL=https://search-mydomain-xxxxx.us-east-1.es.amazonaws.com
OPENSEARCH_USERNAME=opensre-reader
OPENSEARCH_PASSWORD=opensre-reader-password
```

| Variable              | Default | Description                                                   |
| --------------------- | ------- | ------------------------------------------------------------- |
| `OPENSEARCH_URL`      | —       | **Required.** Your AWS ES domain endpoint                     |
| `OPENSEARCH_USERNAME` | —       | Internal user mapped to a read-only role, not the master user |
| `OPENSEARCH_PASSWORD` | —       | Password for that internal user                               |

## Credentials

Create an internal user in fine-grained access control and map it to a read-only role (for example `readall`). Do **not** use the master user for OpenSRE.

## Tools

| Tool                       | What it returns                                                                                                                                               |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `query_elasticsearch_logs` | Log lines matching a query string within a time range, plus a filtered list of lines that look like errors (matches on `error`, `exception`, `timeout`, etc.) |

The tool becomes available once the `opensearch` integration is configured. Availability is gated on `sources["opensearch"]`.

## Verify

```bash theme={null}
opensre integrations verify opensearch
```

There is no separate `elasticsearch` verify target. For a local recipe (Docker container, seeded index, real tool output), see [OpenSearch / Elasticsearch → Quick local test with Docker](/docs/integrations/databases/opensearch#quick-local-test-with-docker).

## Troubleshooting

| Symptom                | Fix                                                                                                |
| ---------------------- | -------------------------------------------------------------------------------------------------- |
| **403 Forbidden**      | Enable fine-grained access control; unsigned IAM resource-policy domains reject anonymous requests |
| **API key auth fails** | AWS ES / OpenSearch security plugin does not natively issue API keys — use Basic Auth              |
| **Wrong service name** | Always use `opensearch` for setup/verify                                                           |

### Gotcha

This integration also supports an `OPENSEARCH_API_KEY` (used by Elastic Cloud), but AWS ES has no equivalent: the OpenSearch security plugin doesn't natively issue API keys ([opensearch-project/security#4009](https://github.com/opensearch-project/security/issues/4009)), so Basic Auth is the only option here. It does **not** sign requests with SigV4 either.

## Security

* Prefer a dedicated internal read-only user, not the master user.
* Store credentials out of source control.
