Port 9200: Elasticsearch
Port 9200 is the HTTP API port for Elasticsearch and OpenSearch.
What runs on port 9200
Elasticsearch and its fork OpenSearch are search and log databases. They serve their REST API on TCP 9200 and talk between cluster nodes on 9300. Older versions shipped with no authentication at all; since version 8, Elasticsearch enables security by default.
On a home network
Home labs running log stacks (ELK), some self-hosted apps and NAS Docker setups may run Elasticsearch. Consumer devices do not.
If port 9200 is reachable from the internet
Unprotected Elasticsearch servers are behind many of the largest data leaks of the past decade, exposing billions of records because anyone could query them over 9200. Ransom campaigns have also wiped open clusters. It should never be reachable from the internet without authentication, and ideally not at all.
How to check whether it is open on your network
Query the server's address on 9200 from another machine; if it answers without asking for a password, security is off. RECON's Exposure Check shows whether it answers on your public address.
To find out whether port 9200 is open on something in your home, and whether the internet can reach it, the app scans your Wi-Fi from your phone and checks your public address from the outside. It says what it checked and what it could not. Get RECON for iPhone — one-time purchase, no account, nothing leaves the device.