Plugins and custom configuration files

Use plugins and custom configuration files to extend Elasticsearch's core functionality with additional analyzers, discovery providers, ingest processors, field types, scripting languages, and dictionaries.

There are two ways to extend Elasticsearch:

  • Plugins are packages installed in Elasticsearch. Use them to add capabilities such as language and phonetic analysis, ingest processors for attachments or geo-IP data, additional field types, cloud discovery providers, or scripting languages. Official core plugins are maintained with Elasticsearch and share its version number. Community and custom plugins are maintained separately and can cover the same kinds of extensions when a core plugin is not available. You can also build your own if no existing plugin covers what you need.

  • Custom configuration files are files that you supply and Elasticsearch reads at runtime, such as synonym dictionaries, SAML metadata, GeoIP databases, or certificates. The way these are installed depends on where you run Elasticsearch: on Elastic Cloud Hosted and Elastic Cloud Enterprise you package them as ZIP archives called bundles, on Elastic Cloud on Kubernetes you mount them from ConfigMaps or Secrets, and in self-managed clusters you place them in each node's configuration directory.

To change Elasticsearch or Kibana settings in files such as elasticsearch.yml and kibana.yml, refer to Elastic Stack settings instead.

Elastic Cloud Serverless support

This page applies to Elastic Cloud Hosted, Elastic Cloud Enterprise, Elastic Cloud on Kubernetes, and Elastic self-managed deployments only. Elastic Cloud Serverless projects do not support custom plugin or bundle uploads, including dictionary files used for synonyms, stop words, or language analyzers.

If you use Serverless and need to manage synonyms, use the synonyms APIs or refer to Search with synonyms. For how Elastic Cloud Hosted and Serverless differ on plugins, bundles, and dictionary options, see Compare Elastic Cloud Hosted and Serverless.

How you install plugins, and how you supply custom configuration files such as synonym dictionaries or SAML metadata, depends on your deployment type.

Deployment type Elasticsearch plugins Custom configuration files
Elastic Cloud Hosted Enable a provided plugin or upload your own, from the console or through the API Upload as a custom bundle
Elastic Cloud Enterprise Enable a provided plugin or add your own from a ZIP URL Add as a custom bundle
Self-managed Use the elasticsearch-plugin CLI, or a declarative configuration file with the Docker image Place in each node's configuration directory
Elastic Cloud on Kubernetes Build a custom container image, or install with init containers Mount with ConfigMaps or Secrets

On Elastic Cloud Hosted and Elastic Cloud Enterprise, plugins provided by the platform are upgraded with your deployment automatically, unless there are breaking changes. When you upgrade, plugins and custom configuration files that you supply must be updated to match the new Elasticsearch version: update your custom plugins and bundles on Elastic Cloud Hosted and Elastic Cloud Enterprise, rebuild your custom image on Elastic Cloud on Kubernetes, and reinstall plugins on each node of a self-managed cluster. Refer to Prepare to upgrade for the checks to run before you upgrade.

Kibana plugins add features to the Kibana UI. How you install them, and whether they are supported, depends on your deployment type: