ElasticSearch itself should be safe, because of the Java Security Manager settings. We're not using logging anyway, so even if those settings are disturbed, we might not be sending anything to the logger.
But Amazon has still issued a log4j patch for our instance -- after several days now. The patch (R20211203-P2) could just be upgrading to log4j2.15. Or maybe there's some other logger in the control plane we can't see that it is securing?
We have tried requests containing common exploit strings and we do not see any requests coming to our target.
Were we safe before patch R20211203-P2 arrived? Does anyone know what R20211203-P2 actually does? There are no release notes.