Data node disconnected
A data node is no longer connected to the cluster. Remaining nodes must handle its indexing, search, and shard work, which can slow operations and reduce availability.
For a complete list of insights, refer to AutoOps insights.
| Field | Value |
|---|---|
| Component | Elasticsearch |
| Severity | High |
| Scope | Cluster |
| Domains | node-lifecycle, stability |
You can customize these settings to adjust when AutoOps detects this event and presents the insight. Refer to AutoOps event settings for details.
The default customization settings are:
| Setting | Type | Default |
|---|---|---|
| Node disconnect timeout in seconds | Integer | 300 |
The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.
Disconnected node: es-data-01 and es-data-02
Before the node disconnected, related conditions were observed:
-
AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.
Investigate disconnected node activity
Condition: Always shown for this insight.
Review tasks, slow search logs, and indexing logs from before the disconnect to find costly requests or errors that might have caused the node to drop.
Data nodes hold primary and replica shards. When a data node disconnects unexpectedly, shards on that node become unavailable until replicas are promoted or reassigned. Remaining data nodes take on indexing and search work from the lost shards, which can slow operations and reduce availability.
The cluster also spends resources recovering and relocating shards. Unplanned disconnects often point to host failure, disk or memory pressure, or network problems. If multiple nodes fail in succession, cluster health can degrade quickly.