Long running delete by query task

A delete-by-query task has exceeded your configured runtime threshold. Delete by query scrolls matching documents and removes them in batches, keeping search contexts open for extended periods.

Note

For a complete list of insights, refer to AutoOps insights.

Field Value
Component Elasticsearch
Severity Medium
Scope Node
Domains performance, indexing, stability, tasks

You can customize these settings to adjust when AutoOps detects this event and presents the insight. Refer to AutoOps event settings for details.

The default customization settings are:

Setting Type Default
Long running delete by query task threshold in minutes Integer 60

The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.

There are 3 tasks that ran more than the 12 minutes threshold.

The longest task running start time was 2026-03-15T14:22:00 UTC time.

The longest task running time is 48 minutes.

Note

AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.

Delete by query removes documents that match a query by scrolling the index and deleting matched documents in batches. The scroll context stays in memory until the task completes, and each batch refreshes the keep-alive timeout, so deletes on large indices can run for a long time.

Broad queries that match many documents, tombstone accumulation during concurrent indexing, and several delete-by-query tasks running together increase heap pressure and I/O on data nodes. Extended deletes during heavy ingest or search traffic can slow cluster operations on affected nodes.