# Search knowledge in Elasticsearch with vector, keyword and hybrid search

> Agno now supports Elasticsearch as a vector database. One index serves vector, keyword and hybrid search, with filters, per-user isolation and sync and async clients.

- Published: 2026-09-16
- Author: Sannya Singal
- Categories: Changelog
- Canonical: https://www.agno.com/articles/search-knowledge-in-elasticsearch-with-vector-keyword-and-hybrid-search
- Markdown: https://www.agno.com/articles/search-knowledge-in-elasticsearch-with-vector-keyword-and-hybrid-search.md

Agno's new `Elasticsearch` vector database, from `agno.vectordb.elasticsearch`, stores the chunks of an Agno `Knowledge` in an Elasticsearch index. Teams that already run Elasticsearch for search and logs can keep agent knowledge there too.

<Video
  src="/videos/changelog-elasticsearch-terminal.mp4"
  controls
  preload="metadata"
  aria-label="A terminal recording of the same Elasticsearch index searched with vector, keyword and hybrid search for an error code and for a question in plain words"
/>

```python
from agno.knowledge.knowledge import Knowledge
from agno.vectordb.elasticsearch import Elasticsearch
from agno.vectordb.search import SearchType

knowledge = Knowledge(
    vector_db=Elasticsearch(
        index_name="recipes",
        url="http://localhost:9200",
        search_type=SearchType.hybrid,
    ),
)
```

![Three ways to search one Elasticsearch index. SearchType.vector, the default, runs kNN over a dense_vector field with filters applied before the search. SearchType.keyword runs multi_match over each chunk's content and name. SearchType.hybrid with HybridStrategy.boost adds 0.7 of the vector score to 0.3 of the keyword score and works on every license. SearchType.hybrid with HybridStrategy.rrf uses reciprocal rank fusion, needs a Platinum, Enterprise or trial license, and falls back to boost with a warning.](https://www.agno.com/images/v3-0-10-elasticsearch-search-types.png)

Vector search is the default. It runs kNN over a `dense_vector` field and applies your filters before the search. Keyword search runs `multi_match` over each chunk's content and name. Hybrid search combines the two, and `hybrid_strategy` picks how:

- `HybridStrategy.boost`, the default, adds 0.7 of the vector score to 0.3 of the keyword score. It works on every Elasticsearch license.
- `HybridStrategy.rrf` uses reciprocal rank fusion. It needs a Platinum, Enterprise or trial license. On a cluster without one, Agno logs a warning and falls back to boost.

The `Elasticsearch` vector database connects with a URL, a list of node URLs, or an Elastic Cloud ID, and authenticates with an API key or basic auth. It verifies TLS certificates by default. It also supports metadata filters, rerankers, bulk inserts and upserts, and per-user isolation through a `user_id` field. Every read and write has an async version on the native async client.

Pin the `elasticsearch` client to your cluster's major version. An 8.x cluster rejects a 9.x client.

See the [cookbook](https://github.com/agno-agi/agno/blob/main/cookbook/07_knowledge/09_archive/vector_dbs/elasticsearch_db.py), and learn more about the [Elasticsearch vector database](https://docs.agno.com/knowledge/vector-stores/elasticsearch/overview) and [per-user isolation](https://docs.agno.com/examples/knowledge/advanced/per-user-isolation/elasticsearch-db) in the documentation.
