Andrew Mercer
on this page

Upstream reference: https://www.elastic.co/docs/deploy-manage/deploy/self-managed/install-elasticsearch-with-rpm

Add the repository

sudo rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch
# /etc/yum.repos.d/elasticsearch.repo
[elasticsearch]
name=Elasticsearch repository for 9.x packages
baseurl=https://artifacts.elastic.co/packages/9.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=0
type=rpm-md

The repo is enabled=0 on purpose, so a routine dnf upgrade can't move you to a new Elasticsearch version. You enable it only when you mean to upgrade.

Install

sudo dnf install --enablerepo=elasticsearch elasticsearch

On first install, security is configured automatically: TLS certificates are generated under /etc/elasticsearch/certs/ and the elastic superuser password is printed once in the install output. Save it in your password manager now.

Start and enable

sudo systemctl daemon-reload
sudo systemctl enable --now elasticsearch.service

Verify

sudo curl --cacert /etc/elasticsearch/certs/http_ca.crt -u elastic https://localhost:9200

Useful follow-ups

# Lost the elastic password
sudo /usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic

# Enrollment token for connecting Kibana
sudo /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana
Path Contents
/etc/elasticsearch/elasticsearch.yml Main config
/etc/elasticsearch/jvm.options.d/ Heap overrides (-Xms/-Xmx)
/var/lib/elasticsearch Data
/var/log/elasticsearch Logs