Elasticsearch 8 end of maintenance lands 15 January 2027: the dated hook for estates still on 8.x and planning Elasticsearch upgrade services. This guide covers Elasticsearch end of life timelines, the Elasticsearch to OpenSearch migration decision, and OpenSearch migration services scope for Australian workloads that must stay in ap-southeast-2 or ap-southeast-4.
The dates that matter
Elastic separates maintenance (bug fixes, performance, security patches) from support (vendor assistance under support terms). Cite elastic.co/support/eol before locking a production date.
| Release | End of maintenance | End of support |
|---|---|---|
| Elasticsearch < 7.17 | Passed | Passed |
| Elasticsearch 7.17.x | 15 Apr 2025 | 15 Jan 2026 (unsupported) |
| Elasticsearch 8.x | 15 Jan 2027 | 15 Jul 2027 |
| Elastic Enterprise Search 8.x | 15 Jan 2027 | 15 Jul 2027 (no 9.x) |
| Elasticsearch 9.x | 15 Oct 2027 baseline | +6 months |
15 July 2027 is a support tail, not six extra months of normal 8.x maintenance. If you are still on 7.17.x, stabilise and plan a supported target immediately.
Classify your estate in 60 seconds
| Current state | What it means | Next step |
|---|---|---|
| 7.17.x or older | Outside Elastic support | Emergency stabilisation + target selection |
| 8.0–8.17 | Not a sensible 9.x staging point | Plan path to 8.19.x |
| 8.19.x | Current staging family for 9.x | Upgrade Assistant + restore rehearsal |
| Enterprise Search / App Search | No 9.x continuation | App Search migration |
A useful audit returns version bucket, blockers, target options, rollback mechanism and cutover sequence, not a generic “upgrade before EOL” slide. Run the 60-second estate classifier on the EOL hub.
Elastic 9 or OpenSearch?
Use the EOM pressure to decide deliberately, this is the core opensearch vs elasticsearch migration question:
Elastic 9 fits when you depend on Elastic security, observability, ML, Kibana features or Elastic Cloud operations.
OpenSearch fits when the workload is indexing, search and log analytics with portable APIs, especially when Apache 2.0 licensing, AWS integration or cost redesign matters.
To migrate Elasticsearch to OpenSearch, export what you actually use: templates, ingest pipelines, ILM, security realms, alerting, dashboards, transforms, ML jobs, plugins and client APIs, then score both targets against that inventory. Our OpenSearch vs Elastic cutover checklist and ELK on-call cutover guide cover mechanics; this article adds 8.x dated deadlines and Australian constraints.
Elasticsearch does not support in-place downgrade. Rollback is restore, rebuild or traffic reversal. Rehearse before production.
When EOL work becomes a SIEM cost decision
Log and security estates often hit the EOM date at the same time as a licensing review. If Elasticsearch carries your SIEM tier, treat SIEM migration services and platform EOL as one programme: trimming ingest before you move means you migrate less data, licence less volume and cut cutover risk.
The same applies to Splunk cost reduction, QRadar migration services or any effort to reduce SIEM ingest cost: filter and route noise first, then size the target cluster. Our noise-first SIEM migration cut ingest 58% before migration and halved SIEM spend with zero detection coverage lost.
Australian residency during migration
“Hosted in Sydney” is not enough for Elasticsearch support Australia residency reviews:
- Source and target clusters in
ap-southeast-2orap-southeast-4 - Snapshot buckets and replication in approved Regions
- Dual-write / replay queues and workers in-region
- No raw payloads to overseas observability SaaS
- Support bundles and CI fixtures with production data controlled
See Keeping Security and Search Logs in Australia and the Australia delivery hub.
Readiness checklist
- Confirm exact Elastic Stack version, plugins, templates, ILM and client libraries
- Decide Elastic 9.x vs OpenSearch from the feature inventory
- Run Upgrade Assistant on supported 8.19.x
- Test snapshot restore and record elapsed time
- Replay representative queries; document count ≠ relevance
- Define rollback metrics and owner before 15 January 2027
Our tier-1 bank ELK migration preserved detection coverage through dual-write. For SIEM cost pressure, see Splunk noise-first migration.
Limitations
Engineering guidance only. Not legal or licensing advice. Re-check Elastic's EOL page before production approval. Australian residency depends on architecture end to end, not Region selection alone.
Sources: Elastic EOL, Upgrade guidance, verified 8 August 2026.
Next step: Book a version audit · Elasticsearch EOL hub · Australia delivery