350,527 Elasticsearch Matches and 161,615 Kibana Matches: Where Logging Data Actually Lives
On 20 August 2026, CISA released guidance on logging, visibility, and operational standards for federal agencies. The guidance is about collecting and retaining the data needed to detect and investigate incidents. A related question is where that data sits, and how much of it is externally reachable.
Two ZoomEye queries measured the most common open source logging stack. The Elasticsearch fingerprint returned 350,527 matches. The Kibana fingerprint returned 161,615.
What the queries measured
Query 1: app="Elasticsearch"
Result: 350,527 matches
Search link: https://www.zoomeye.ai/searchResult?q=YXBwPSJFbGFzdGljc2VhcmNoIg%3D%3D
Query 2: app="Kibana"
Result: 161,615 matches
Search link: https://www.zoomeye.ai/searchResult?q=YXBwPSJLaWJhbmEi
Collection time: 23 September 2026, 02:34 UTC
Scope: all asset types, global
Why the ratio matters
Elasticsearch stores and indexes data. Kibana provides the interface for querying it. The counts show roughly twice as many Elasticsearch instances as Kibana instances, which is consistent with deployments where Elasticsearch is used programmatically or by other tools without a Kibana front end.
For a logging program, both components are sensitive. Elasticsearch holds the log data itself, which may include authentication records, request contents, and internal hostnames. Kibana provides a query interface that, if unauthenticated, exposes that data directly.
The logging paradox
The CISA guidance asks organizations to collect more data and retain it longer. That improves detection and investigation. It also creates a larger store of sensitive information that has to be protected. A logging platform that is reachable from the internet converts a defensive control into an exposure.
This is not a hypothetical concern. Log stores commonly contain the kind of information an attacker wants: service account names, internal network topology, and the contents of authentication events. An unauthenticated search interface over that data is a reconnaissance tool.
What to check
- Confirm that neither Elasticsearch nor Kibana is reachable from outside the network. Both are designed for internal deployment and neither enables authentication by default in older versions.
- Verify that authentication and authorization are enabled, and that the anonymous access role is disabled.
- Check what the log store contains. If it holds credentials or session material, that changes the priority of protecting it.
- Apply retention limits that match the guidance without keeping data longer than necessary.
- Monitor for unusual query patterns, which may indicate someone using the platform for discovery.
What the measurement does not show
The counts do not show authentication state, version, or data content. A matched instance may be a properly secured internal deployment that happens to be visible, or an open store. The external view cannot distinguish them. What the numbers establish is the scale of the technology in the internet-facing dataset, which is the starting point for checking your own deployments.
References
- CISA, "CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards," 20 August 2026. https://www.cisa.gov/news-events/news/cisa-releases-foundational-flexible-guidance-help-federal-agencies-implement-effective-logging
- ZoomEye searches,
app="Elasticsearch"(350,527 matches) andapp="Kibana"(161,615 matches), collected 23 September 2026.
Top comments (0)