OpenSearch (formerly named ElastiSearch) can encrypt data at rest using customer managed keys stored in AWS KMS. Encrypting data at rest is considered best practice and can help protect sensitive data. For more information, see the AWS documentation.
References:
https://docs.aws.amazon.com/opensearch-service/latest/developerguide/encryption-at-rest.html
In AWS Console -
In Terraform -
References:
https://docs.aws.amazon.com/opensearch-service/latest/developerguide/encryption-at-rest.html
https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/elasticsearch_domain#encrypt_at_rest