Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / OpenSearch on Ubuntu 24.04 LTS

OpenSearch on Ubuntu 24.04 LTS — Support & Quick Start

OpenSearch 3.0 with Dashboards on Ubuntu 24.04 LTS — search and log analytics with a unique per-VM admin password.

Fixed on image version 2026.916.1427 (published 2026-09-16)

opensearch.service is given 10 minutes to start instead of 75 seconds, the generated admin password is hashed with the bundled JDK and written into /etc/opensearch/opensearch-security/internal_users.yml (the step that used to die silently when `java` was not on PATH), and first boot verifies the password against the running node.

If you deployed this VM before 2026-09-16, it came from the older image and is not changed by the new publication — redeploy from the current Marketplace version, or apply the one-time repair below:

  1. On a VM from an earlier image the node may never have finished starting within the first-boot window. Watch `sudo journalctl -u opensearch -f`; once the node is up, the password in /var/lib/opensearch/admin-password applies. If `admin` is still refused, the hash step never ran on that image — email support or redeploy from the current Marketplace version.

Image change: see the pull request.

Source: the Marketplace live version set for this offer, read from Partner Center on 2026-09-16. New deployments take the newest version by default.

At a glance

Application ports5601 (Dashboards, HTTP), 9200 (REST API, HTTPS with the bundled self-signed demo certificates)
Open in browserhttp://<VM-IP>:5601/
Admin credential filesudo cat /var/lib/opensearch/admin-password
Sign in asadmin
Service(s)opensearch, opensearch-dashboards
Configuration/etc/opensearch/opensearch.yml; /etc/opensearch/opensearch-security/internal_users.yml; /etc/opensearch-dashboards/opensearch_dashboards.yml
Logs/var/log/opensearch/; journalctl -u opensearch-dashboards -f
VersionOpenSearch 3.0.0 + OpenSearch Dashboards (3.x apt repository)
PlatformUbuntu 24.04 LTS

Quick start

  1. Deploy from the Azure Marketplace (Get It Now → Create), choosing your SSH key at the Administration step.
  2. Allow inbound SSH (22) for yourself plus the application port(s): 5601 (Dashboards) and, for API clients, 9200 — restrict to your own IP where possible. The in-image firewall already allows them; only the Network Security Group (NSG) keeps them closed.
  3. Open http://<VM-IP>:5601/ and sign in as admin (see First login below).
  4. Create an index pattern and start ingesting via the REST API on https://<VM-IP>:9200 (Beats/Logstash/Data Prepper compatible).

First login / credentials

This image generates its admin credential on the VM at first boot — nothing is pre-set. SSH into the VM with the username + key you chose at deploy, then print the generated credential:

ssh <your-username>@<VM-IP>
sudo cat /var/lib/opensearch/admin-password

Sign in as admin.

  1. Print the generated admin password (OPENSEARCH_ADMIN_PASSWORD) from the file — first boot rotates the build-time password.
  2. Open http://<VM-IP>:5601/ and sign in as admin; the REST API is https://<VM-IP>:9200/ (curl -ku admin:<password>).
  3. Change the password (Security → Internal users) and replace the demo TLS certificates before production.

Sign in as admin. The REST API on 9200 is HTTPS with self-signed demo certificates (use -k / your CA); replace them and rotate the password before exposing the node.

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or send a message via the contact form. Include the offer name, VM size, region, and any log output — sudo journalctl -u <service> -n 100 usually tells the story.