I have Elasticsearch running on two nodes with kibana on one of them. I have port 9200 closed on the firewall and can't access it from outside the network. When I list the indices, it shows several that I did not create. It looks like .kibana is legitimate, but I am worried about the other ones. Are these indices supposed to be there, or is this a sign that the servers have been compromised?
root@web-server-03:/var/log/elasticsearch# curl 'localhost:9200/_cat/indices?v'
health status index pri rep docs.count docs.deleted store.size pri.store.size
green open mambo 5 1 0 0 1.3kb 720b
green open newsletter 5 1 0 0 1.3kb 720b
green open modules 5 1 0 0 1.3kb 720b
green open robohelp 5 1 0 0 1.3kb 720b
green open create_account_process.php 5 1 0 0 1.2kb 720b
green open action.php 5 1 0 0 1.2kb 720b
green open index.htm 5 1 0 0 1.3kb 720b
green open cgi-bin 5 1 0 0 1.2kb 720b
green open login.jsp 5 1 0 0 1.3kb 720b
green open reports 5 1 0 0 1.3kb 720b
green open admin 5 1 0 0 1.3kb 720b
green open modules.php 5 1 0 0 1.3kb 720b
green open xmlrpc.php 5 1 0 0 1.3kb 720b
green open payonline.asp 5 1 0 0 1.3kb 720b
green open forum 5 1 0 0 1.3kb 720b
green open nquser.php 5 1 0 0 1.2kb 720b
green open flatnuke 5 1 0 0 1.3kb 720b
green open server.php 5 1 0 0 1.3kb 720b
green open netquery 5 1 0 0 1.2kb 720b
green open e107 5 1 0 0 1.3kb 720b
green open auth.php 5 1 0 0 1.3kb 720b
green open weblibs.pl 5 1 0 0 1.2kb 720b
green open jhot.php 5 1 0 0 1.3kb 720b
green open tiki 5 1 0 0 1.3kb 720b
green open tikiwiki 5 1 0 0 1.3kb 720b
green open goform 5 1 0 0 1.3kb 720b
green open login.php 5 1 0 0 1.3kb 720b
green open check 5 1 0 0 1.3kb 720b
green open index.php 5 1 0 0 1.3kb 720b
green open users 5 1 0 0 1.3kb 720b
green open shopproductselect.asp 5 1 0 0 1.3kb 720b
green open data 5 1 0 0 1.3kb 720b
green open .kibana 1 1 14 1 52.3kb 26.1kb
green open search.php 5 1 0 0 1.2kb 720b
green open shopping 5 1 0 0 1.2kb 720b
green open blog 5 1 0 0 1.3kb 720b