Rejected indexing

One or more nodes are rejecting indexing requests. Clients might lose data if they do not retry successfully.

Note

For a complete list of insights, refer to AutoOps insights.

Field Value
Component Elasticsearch
Severity High
Scope Node
Domains performance, indexing, stability

You can customize these settings to adjust when AutoOps detects this event and presents the insight. Refer to AutoOps event settings for details.

The default customization settings are:

Setting Type Default
Rejected indexing count threshold Integer 1
Consecutive samples above threshold Integer 1
Tip

Raising these thresholds reduces noise but delays detection. Lowering them triggers the insight sooner but can increase alerts during minor blips.

The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.

Indexing requests are being rejected on es-data-01 and es-data-02.

  • Indices with high indexing activity: logs-prod-000045
Note

AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.

When Elasticsearch rejects indexing requests, writes fail at the client. Without successful retries, data can lag or be lost.

Rejections often follow sustained ingest pressure: a full or backed-up write thread pool, documents that do not match the index mapping, indices put into read-only mode at the flood-stage disk watermark, or circuit breakers that trip while processing bulks.

If rejections continue, ingest stays unreliable until pressure drops, mappings and disk pressure are fixed, or capacity increases.