Elasticsearch là gì?
Elasticsearch là một distributed full-text search engine dựa trên Apache Lucene — cho phép tìm kiếm, phân tích dữ liệu phi cấu trúc với tốc độ cao, hỗ trợ:
-
Indexing & querying JSON documents
-
Text search (relevance, ranking)
-
Aggregations (analytics)
-
Distributed scalability (shards & replicas)
Các node trong cluster phối hợp xử lý indexing & search
Core Concepts
Documents
-
JSON objects chứa dữ liệu tìm kiếm.
-
Cũng như “rows” trong RDBMS nhưng linh hoạt hơn, mỗi document có thể có schema khác nhau.
-
Một tập hợp documents.
-
Tương đương “table” trong DBMS.
-
Có thể cấu hình số primary shards & replicas.
-
Index chia thành nhiều shards để scale ngang.
-
Replicas tăng khả năng chịu lỗi & read throughput.
-
Mappings định nghĩa “schema” cho index: field type, search analyzers…
-
Field type ảnh hưởng đến cách dữ liệu được tokenized và indexed.
Distributed Search & Analytics
Distributed Search
-
Query được gửi đến cluster
-
Each shard trả kết quả cục bộ
-
Coordinator merge & sort trước khi trả về cho client
-
Tính toán metrics, group-by, histograms trên dữ liệu lớn rất nhanh
-
Elastic sử dụng data structures tối ưu cho aggregations
Use Cases
-
Full-text search (search bar, fuzzy match)
-
Logging & observability (ELK stack: Elasticsearch + Logstash + Kibana)
-
Analytics & BI (dashboard, events)
-
RAG (retrieval-augmented generation) cho LLMs
Features & Ecosystem
OpenSearch
-
Tích hợp sẵn security, multi-tenant, alerting, anomaly detection.
-
Plugin ecosystem linh hoạt, cộng đồng mở rộng.
-
Enterprise features mạnh (Machine Learning, searchable snapshots, adaptive routing).
-
Elastic Stack (Observability, Security, APM) đồng bộ và tích hợp sâu hơn.
Performance & Optimization
Benchmark khác nhau giữa hai dự án:
-
Elasticsearch benchmark internal cho thấy thường nhanh & hiệu quả tài nguyên hơn trong nhiều tác vụ.
-
Independent tests (2025) có kết quả khác nhau tùy workload — OpenSearch có ưu điểm latency thấp hơn trong workload cụ thể.
-
Elasticsearch mạnh về enterprise search stack & automation
-
OpenSearch mạnh về OSS ecosystem & flexibility
When to Use Which?
Use OpenSearch
-
Bạn cần open source hoàn chỉnh (Apache 2.0)
-
Tránh vendor lock-in & license cost
-
Want customizable plugin & observability features built-in
-
Enterprise search + SIEM + observability stack
-
Licensing acceptable and enterprise features matter
-
Managed Elastic Cloud + advanced automations
Internal Architecture / How It Works
Indexing
-
Document inserted → tokenization → inverted index build
-
Stored in segments
-
Merges & refresh cycles orchestrate real-time indexing
-
Each shard có replicas → tăng fault tolerance & read throughput
-
Receive query
-
Fan-out to shards
-
Each shard local search
-
Merge & sort results
-
Return final ranked results