.png)
Elasticsearch Integration Guide
Connect Elasticsearch with enterprise applications through REST APIs, bulk indexing, scheduled workflows, controlled search APIs, and selected Watcher webhook actions.
Elasticsearch integration options at a glance
Elasticsearch is primarily integrated through HTTP REST APIs for indexing, document updates, searches, aggregations, index administration, aliases, mappings, and cluster operations. The _bulk API supports batch indexing, updates, and deletes, while asynchronous search supports longer-running queries. Elasticsearch also provides SQL and ES|QL interfaces for query and analytics use cases. Watcher can invoke outbound webhook actions for selected configured conditions, but it is not a universal event stream. Martini can consume these endpoints in workflows, map source data into Elasticsearch documents, expose controlled search APIs, and apply scheduling, validation, retries, and secure credential management.
Common Elasticsearch integration patterns
Common Elasticsearch data objects used in integrations
Authentication and security considerations
Use scoped credentials
Elasticsearch supports API keys, Basic Authentication, bearer or service-account tokens, TLS client authentication, and configured federated identity options. For machine integrations, use the least-privileged API key or service credential required for the target indices and operations.
Protect credentials and transport
Store Elasticsearch endpoints and credentials in Martini secure environment configuration rather than workflow mappings. Use TLS and restrict access to only the required indices, aliases, data streams, and API operations.
Control exposed search access
If Martini exposes a search API, validate fields, operators, sorting, aggregations, and page sizes before constructing Elasticsearch requests. Do not pass unrestricted user-provided query DSL directly to Elasticsearch.
Operational considerations for Elasticsearch integrations
Capacity and request volume
Cluster capacity, shard count, thread pools, request size, and deployment configuration affect safe throughput. Use bounded concurrency, controlled payload sizes, throttling, and exponential backoff rather than assuming a fixed client rate limit.
Bulk responses and retries
Inspect both the HTTP response and every item returned by the _bulk API. Classify authentication failures, mapping errors, rejected requests, timeouts, and transient cluster pressure separately, and retry only eligible failures.
Pagination and checkpoints
For large result sets, prefer point-in-time searches with search_after or an appropriate scroll strategy. Persist checkpoints only after successful downstream processing, and define how source deletions and synchronization gaps are reconciled.
Mappings and refresh behavior
Mapping changes can require versioned indices and reindexing rather than in-place modification. Newly indexed documents may not be immediately searchable, so workflows should account for refresh timing without forcing refreshes unnecessarily.
Version and test compatibility
Confirm the Elasticsearch version, deployment model, endpoint paths, authentication scheme, mapping behavior, and client compatibility before deployment. Test malformed queries, per-item bulk failures, retries, duplicates, timeouts, and schema changes.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration beyond a script
Martini provides a maintainable workflow layer for retrieving source data, transforming documents, applying business rules, calling Elasticsearch, and delivering results to other systems. This keeps integration behavior visible and reusable as requirements change.
Controlled APIs and access
Martini can expose a constrained search or indexing API instead of giving every client direct Elasticsearch access. Validation, authorization, response shaping, and query limits can be applied consistently at the integration boundary.
Reliable synchronization
Scheduled workflows can manage pagination, checkpoints, deterministic document IDs, bounded bulk requests, per-item error handling, and retry decisions. This is more resilient than an isolated script that treats every response as success or failure at the request level.
Reusable enterprise integration assets
Martini separates secure configuration, API calls, mappings, workflow orchestration, and error handling so the same integration patterns can be reused across indices, data streams, source applications, and deployment environments.