Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
••••••••
Sichere ProgrammierungI built a tool that makes images bigger, not smaller – here's why(25.09.2026 um 05:56 Uhr)
••••••••••
Sichere ProgrammierungI built a tool that makes images bigger, not smaller – here's why(25.09.2026 um 05:56 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

We Chose Meilisearch Over 10+ Other Search Engines Despite a Major Drawback

Is it worth investing resources in a third-party search engine? Here are our reasons. We are continuously working on improving our product Feedback by Hexmos day by day for the upcoming release. New features and pages are coming up, the…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




Is it worth investing resources in a third-party search engine? Here are our reasons.



We are continuously working on improving our product Feedback by Hexmos day by day for the upcoming release.



New features and pages are coming up, the UI is changing, bugs are being noticed and fixed, and many changes are happening in the product. As the product grows, we realize we need to improve the navigation across the product.



We already have a sidebar and a client-side search package cmdk to navigate to different screens, but difficulties arise when we want to search for different user profiles, teams, team performance, etc., which forces us to integrate a better third party search engine for Feedback.



Another reason for a dedicated search engine is that we have other products in the chain such as FeedZap, which requires a complex text search operations in future.



Considering this, we are planning to put effort into implementing a dedicated, powerful search engine that adapts to our use cases and resource availability.






How to Choose the Right Search Engine that fit your Needs



There are a lot of search engines available, including open-source search engines, serverless, server-based, etc.

Before diving in to figure out the right one, it's always better to do an analysis of your requirements and infrastructure, including present and future needs.



For some products, searchable data are minimal but require a decent search feature with minimal operation, yet can't afford a dedicated server.

For other products, the dataset is larger, requires additional complex search operations and have enough resources to load a dedicated search engine.



Based on this, I reviewed a few popular search engines.






Need Decent Performance, Dataset Is Small, and Can't Afford a Server





If you are using PostgreSQL and don't want to maintain any other index-based database, then PostgreSQL Full-Text Search (PSFTS) is a good option. However, it is not recommended for large use cases where you deal with millions of transactions and extensive data management.






Bleve



Bleve is another option to consider if your project is within the Go ecosystem. It is recommended if you can't rely on powerful server-based search engine services. Here is the benchmark report on Bleve.






Tantivy



Tantivy is written in Rust and is particularly useful for Rust-based projects. It has received numerous positive feedbacks and is a good option to consider.

searchbenchmark






Need Powerful Performance, Large Dataset, and Can Afford a Server






Need Powerful Performance, Large Dataset, and Can Afford a Server



If you own a server or cloud instance and require a powerful, scalable search engine with full control, then a server-based option is the way to go.



Our considerations and requirements led us to choose a server-based search engine. We have enough resources to host it, and it is better than serverless options for




  • Long-term use

  • Scalability

  • Additional support for complex search operations such as:



    • Facet search: it means when shopping online, you might search for "laptops" and then use facet search to narrow down results by selecting filters like "price under $1000," "brand: Apple," and "RAM: 16GB."


    • Multisearch: Consider travel website which might let users search for flights, hotels, and car rentals all at once and display back the integrated results.


    • Search-as-you-type: It provides real-time search results based on each key stroke.






  • Common search system for mulitiple products.




After extensive filtering, we narrowed it down to four options in this category such as:




  1. Meilisearch

  2. Typesense

  3. PISA Search

  4. Manticore



Here is a comparison between them:

























































Criteria meiliSearch Typesense Pisa Search Manticore
Search-as-you-type yes yes No No
facet search yes yes No No
multiple schema/product support yes yes - yes
RAM usage
for 224 MB disk:~305 MB RAM prmary index location is disk
primary index location is RAM, for 100MB disk requires 300MB RAM - -
CPU Usage
for 12 core machine it uses maximum 6 core github issues related to high cpu usage
for 4vCPU handle 104 concurrent search/seconds - -
typo, synonyms handling yes yes - -


We filtered out PISA Search and Manticore because neither of them offers search-as-you-type and facet search features, which are required for our application.



Continue reading the full article here: https://journal.hexmos.com/we-chose-meilisearch-over-10-other-search-engines-despite-a-major-drawback/

1. Sofort-Triage & Abwehrmaßnahmen

SOC Incident Playbook: Remote Code Execution (RCE) Defense
Syntax validiert (0 Fehler)
title: Detect Exploitation - We Chose Meilisearch Over 10+ Other Search Engines Despite a Major Drawback
id: 268c145f-ed74-4e43-89dc-0787c1013fbd
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-25
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-25"
        description = "YARA Signature for "
    strings:
        $str = "We Chose Meilisearch Over 10+ " ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("We Chose Meilisearch Over 10 Other Searc")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*We Chose Meilisearch Over 10 Other Searc*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "We Chose Meilisearch Over 10 Other Searc"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph3 Knoten / 2 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich We Chose Meilisearch Over 10+ Other Sear.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten We Chose Meilisearch Over 10+ Other Search Engines Despite a Major Drawback

Thematisch verwandte Begriffe: Chose, Meilisearch, Over, Other · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-87722 | Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search q…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag