Expensive queries disabled
search.allow_expensive_queries is false, so expensive query types cannot run. That can protect CPU and heap, and it can break Kibana and Fleet features that need those queries.
For a complete list of insights, refer to AutoOps insights.
| Field | Value |
|---|---|
| Component | Elasticsearch |
| Severity | Medium |
| Scope | Cluster |
| Domains | performance, search, configuration |
The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.
search.allow_expensive_queries is false. Expensive query types cannot run (for example fuzzy, regexp, prefix, wildcard, script, and percolate).
AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.
Re-enable expensive queries
Condition: Always shown for this insight.
Set search.allow_expensive_queries to true unless this cluster does not use Kibana or Fleet and you are blocking expensive query types on purpose. False can break alerting, dashboards, saved-object search, and Fleet setup. Use the action below.
PUT _cluster/settings
{
"persistent": {
"search.allow_expensive_queries": "true"
}
}
Requires the manage cluster privilege. Requires Elasticsearch 8.0.0 or later. This action changes cluster or index configuration.
Elasticsearch treats some Query DSL features as expensive because they can use large amounts of CPU and memory and slow other search and indexing on the same nodes.
The default is true so those query types can run. Kibana (alerting, dashboards, saved objects) and Fleet can fail when the setting is false.
If you turned it off to lock down a cluster that does not use Kibana or Fleet, the restriction might be intentional. On a typical Stack deployment, false is usually an unsafe override of the default.