Indexing throttle time

One or more nodes are throttling indexing because they cannot keep up with the current ingest rate. Throttling slows writes on purpose to protect the node.

Note

For a complete list of insights, refer to AutoOps insights.

Field Value
Component Elasticsearch
Severity High
Scope Node
Domains performance, indexing

The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.

Indexing throttle time is elevated on es-data-01.

Index with high indexing activity: logs-prod-000045

Note

AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.

Indexing throttle means the data node is limiting the rate of write work because it cannot keep up with demand. That protects the node, but it also delays how quickly new documents become searchable.

If throttling continues, indexing requests might start getting rejected. Upstream producers that retry aggressively can add more load. In the worst case, data lags or is lost when clients do not retry failed writes.