Expensive queries disabled

search.allow_expensive_queries is false, so expensive query types cannot run. That can protect CPU and heap, and it can break Kibana and Fleet features that need those queries.

Note

For a complete list of insights, refer to AutoOps insights.

Field Value
Component Elasticsearch
Severity Medium
Scope Cluster
Domains performance, search, configuration

The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.

search.allow_expensive_queries is false. Expensive query types cannot run (for example fuzzy, regexp, prefix, wildcard, script, and percolate).

Note

AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.

Elasticsearch treats some Query DSL features as expensive because they can use large amounts of CPU and memory and slow other search and indexing on the same nodes.

The default is true so those query types can run. Kibana (alerting, dashboards, saved objects) and Fleet can fail when the setting is false.

If you turned it off to lock down a cluster that does not use Kibana or Fleet, the restriction might be intentional. On a typical Stack deployment, false is usually an unsafe override of the default.

Elastic Support Hub