7.26.0 7.25.0 7.24.0 7.23.0 7.22.0 7.21.0 7.20.0 7.19.0 7.18.0
7.26.0 7.25.0 7.24.0 7.23.0 7.22.0 7.21.0 7.20.0 7.19.0 7.18.0

Data Indexer Elasticsearch to OpenSearch Upgrades

This page is only relevant for users upgrading to LogRhythm SIEM version 7.26.0 or later. As of the 7.26.0 release, LogRhythm SIEM has migrated its search functionality from ElasticSearch to OpenSearch. This page provides a high-level overview of the changes and how they impact your LogRhythm platform.

LogRhythm version 7.26 introduced OpenSearch 2 as the Data Indexer backend, replacing the previous Elasticsearch 7 which was shipped between versions 7.18 and 7.25. OpenSearch 2 offers improved performance, better memory management, improved security, and a roadmap of long-term feature introduction in the Data Indexer.

Index/Data Compatibility

OpenSearch 2 is built on Lucene 9, which maintains backwards compatibility up to one major version (N-1), this means that OpenSearch 2 can read/write to indexes that were created in Lucene 8 (ES7) or Lucene 9 only. Indexes that were created in Lucene 7 (ES6) cannot be read by OpenSearch 2.

LogRhythm upgraded to Elasticsearch 7 in version 7.18; this means that indexes created in any LogRhythm version prior to 7.18 are not compatible with OpenSearch 2 in LogRhythm version 7.26+. This includes all index types (Hot, Warm, Ultra-Warm and Archive Restore (logsar-*). As part of the upgrade process to LogRhythm 7.26, the DX Upgrade Checker will validate if your cluster contains any incompatible indexes and remove them so the cluster can start after the upgrade is completed.

This process may result in data loss for any indexes/data created prior to LogRhythm SIEM version 7.18.

Example Scenarios

The following scenarios may help in understanding the upgrade process, when it is needed, and potential data loss situations.

Upgrade Date & Version

Index Description

Data Loss on Upgrade?

Upgraded to LogRhythm 7.18 in December 2024.

DX Cluster has 90 Days Hot + 90 Days Warm = 180 Days total, with 646 days since your last upgrade.

No data loss on upgrade.

Upgraded to LogRhythm 7.19 in February 2025, then again to LogRhythm 7.23 in February 2026.

DX Cluster has 90 Days Hot + 180 Days Warm = 270 Days total with 584 days since your upgrade to a version above LogRhythm SIEM 7.18.

No data loss on Upgrade.

Upgraded from LogRhythm 7.17 to LogRhythm 7.23 in February 2026.

DX Cluster has 90 Days Hot + 180 Days Warm = 270 Days total, with 242 days since your upgrade to a version above LogRhythm SIEM 7.18.

Upgrade will result in the deletion of 38 Days of indexes in Warm Tier.

Upgraded to LogRhythm 7.19 in February 2025, then again to LogRhythm 7.23 in February 2026.

DX Cluster has 90 Days Hot + 180 Days Warm + 200 Archive Restore indexes dating back to January 2025.

Archive Restore indexes pre-date the LR 7.18+ upgrade and will be deleted.

If you are concerned your cluster may contain incompatible indexes, before upgrading to OpenSearch, you can confirm the version of each index and its compatibility with the scripts below.

Indexes removed during the upgrade can be restored only through Archive restoration. Bulk Archive Restorations should be handled through the SecondLook API for optimal performance. For more information on historical index compatibility with LogRhythm versions, refer to Upgrade FAQ and Determining the Correct Upgrade Path.

Linux Script

Bash
curl -s "localhost:9200/_all/_settings/index.version.created?expand_wildcards=all" | \
jq -r 'to_entries[] | "\(.key) \(.value.settings.index.version.created)"' | \
while read -r index version; do
  case "$version" in
    6*) status="INCOMPATIBLE" ;;
    7*) status="COMPATIBLE" ;;
    *) status="UNKNOWN" ;;
  esac
  echo "$index $version $status"
done

Windows Script

# Query settings from local Elasticsearch
$uri = "http://localhost:9200/_all/_settings/index.version.created?expand_wildcards=all"
try {
    $settings = Invoke-RestMethod -Uri $uri -Method Get
} catch {
    Write-Error "Failed to connect to Elasticsearch: $_"
    return
}

# Iterate through each index and evaluate compatibility
foreach ($index in $settings.PSObject.Properties) {
    $indexName = $index.Name
    $version = $index.Value.settings.index.version.created

    # Determine compatibility based on leading digit of the index version
    $status = "UNKNOWN"
    if ($version) {
        if ($version.StartsWith("6")) {
            $status = "INCOMPATIBLE"
        } elseif ($version.StartsWith("7")) {
            $status = "COMPATIBLE"
        }
    }

    # Print the output in the same format
    Write-Host "$indexName $version $status"
}

Kibana Users

LogRhythm does not provide official support for Kibana or OpenSearch Dashboards; however, there are a significant number of deployments leveraging Kibana alongside LogRhythm 7.x. With the migration to OpenSearch 2, Kibana will no longer function. Customers using Kibana must migrate to OpenSearch Dashboards. For single-cluster deployments, scripts have been bundled with LogRhythm SIEM 7.26.0 to aid in the migration process; however, if you have a more complex Kibana deployment (such as multiple clusters), the migration is much more complex and not covered under LogRhythm Support.

If you wish to retain your existing Kibana custom configurations (dashboards, visualizations, etc.) and port them over to OpenSearch Dashboards, you must backup your Kibana Dashboards prior to the upgrade.

OpenSearch 2 introduces native security features which were not available in Elasticsearch 7, including enforced encryption and authentication in order to access data in the cluster. Your OpenSearch Dashboards configuration will need to take this into account. Customers with existing multi-cluster Kibana configurations are strongly encouraged to remove their Cross-Cluster Search (CCS) configurations and migrate to Multiple Data Sources (MDS) as this will offer a much simpler deployment.