Architecture and migration
Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.

WZ-IT plans, installs and operates OpenSearch as managed hosting, in your cloud or on premises. Depending on the target design, we also provide migration, secure network and identity integration, monitoring, backups, updates, integrations and further development.
The following are trademarks of their respective owners: OpenSearch (The OpenSearch Software Foundation). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.

OpenSearch is an open-source search and analytics engine under the Apache 2.0 licence. It supports full-text, log and vector search as well as dashboards; security, scaling and operational capabilities are verified for the selected version.
We support the installation, configuration and optimisation of OpenSearch clusters for log analytics, full-text search, observability and semantic AI search. Architecture, performance and cost are aligned with the actual data and query profile.
We install, host, and operate OpenSearch for your company - either on our secure, privacy-focused infrastructure in Germany or other locations, as well as on-premise in your own environment.
We provide 24/7 monitoring, backups and maintenance for your OpenSearch instance. Human response times and support coverage follow the selected service level.
Powerful lexical full-text search with BM25 algorithm combined with semantic k-NN search for precise search results in large datasets.
State-of-the-art AI vector search with Facebook FAISS integration, SIMD hardware acceleration, and quantization for high-performance semantic search and RAG applications.
Comprehensive security features with RBAC, TLS encryption, audit logging, fine-grained access management, and support for LDAP, SAML, OpenID Connect - completely free.
Trace Analytics, Event Analytics, Operational Panels, and Metrics Analytics with OTLP support for comprehensive monitoring of logs, traces, and metrics.
Powerful visualization dashboards as Kibana alternative with Event Analytics, Notebooks, Piped Processing Language, and flexible visualization options.
Remote-backed storage and cluster sharding can support large data volumes. Sizing and sustainable scale are tested against data volume, query patterns and recovery targets.
Advanced log analysis, trace analytics, and correlation across logs, traces, and metrics for deep insights into your systems.
Query and ingestion performance is tested against data volume, shard strategy, replication and real search profiles, then optimised for the workload.
Extensive RESTful API, plugin ecosystem, integration with AI services, and compatibility with Elasticsearch clients for seamless migration and flexible extensions.
Professional installation on your infrastructure - on-premise, cloud or hybrid
In your data center
AWS, Azure, Hetzner & more
Advanced architecture after technical and licence assessment
Secure access and access control for your installation
WireGuard, NetBird or Tailscale
Directly or through an upstream identity layer
Depends on application, edition and identity provider
Fail2Ban, Rate Limiting, IP Whitelisting
We set up secure VPN access to your installation - ideal for remote work and external employees.
Full-service installation with no hidden costs
Search is more than `SELECT *`. We optimize OpenSearch for relevance, performance, and AI-powered vector search.
Manipulation of queries before execution. We develop request processors that enrich synonyms, correct typos, or analyze user intent.
ETL directly in the cluster. We write ingest processors that enrich documents upon indexing (GeoIP, NLP sentiment, PII masking).
Implementation of semantic search via k-NN plugin. We connect OpenSearch with embedding models for RAG applications.
How we implement OpenSearch development in practice.
LLMs hallucinate without context. Vector databases are complex to manage.
OpenSearch as hybrid search store (keyword + vector). Optimized retrieval queries for precise LLM answers.
Customers don't find products when they misspell technical terms or part numbers.
Custom N-Gram tokenizers and phonetic analysis that finds 'screwdriver' even with dialect/typos.
We do more than provide an application. WZ-IT designs the technical architecture, integrates network and identity, operates the agreed scope and develops integrations when the standard product is not enough.
Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.
SSO, secure access, internal systems and existing security components are integrated appropriately.
Updates, backups, technical monitoring and response paths follow a transparent operational scope.
APIs, automation and custom extensions can be delivered beyond basic deployment.
The exact scope depends on the application, edition, infrastructure and criticality. Vendor licences and non-standard components are quoted separately.
Data platforms are designed around access patterns, consistency, growth, recovery and the applications that depend on them.
Defined clients, services and ingestion processes connect through private or secured interfaces.
TLS, firewall rules, reverse proxies or private network paths are designed around the platform's exposure.
Local accounts, SSO, directories, service accounts and emergency access are connected through clear roles.
Queries, indexes, roles, resource limits and maintenance processes are configured for the workload.
Storage class, capacity, latency and growth aligned with the data profile.
Optional cluster, replica or failover design according to the required protection objective.
Consistent backups, retention and scheduled restore checks.
The diagram is a resilient target model. Its implementation depends on edition, data flows, load, availability objectives and existing infrastructure.
A clearly defined operating scope instead of an opaque hosting flat fee.
We set up a test instance for you, usually on the next business day. No payment details required. After seven days it is deleted unless you continue.
Compute, applications, storage and response are shown separately. You can see what ongoing operations include and which requirements need a technical assessment.
We also design custom OpenSearch architectures, integrations and migrations. Contact us for a technical assessment.
One managed standard OpenSearch application is included in the Starter workload. Every service level also includes flexible expert time for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€79.90 per started TB and month, including daily encrypted offsite backup with 7-day retention.
Briefly describe the current state and objective for OpenSearch. We assess infrastructure, integration, and ongoing operations.
Whether you run OpenSearch in-house or need to host confidentiality-professional data §203-ready - we build, operate and maintain OpenSearch on an encrypted on-site server. Data never leaves the building in cleartext.
See OpenSearch on-premise
These solutions are often used together with OpenSearch
These solutions offer similar functionalities and can be evaluated together
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.
Timo Wevelsiep & Robin Zins
Managing Directors of WZ-IT
