Rejected search
One or more nodes are rejecting search requests. Clients see errors, timeouts, or partial results instead of completed searches.
For a complete list of insights, refer to AutoOps insights.
| Field | Value |
|---|---|
| Component | Elasticsearch |
| Severity | High |
| Scope | Node |
| Domains | performance, search, stability |
You can customize these settings to adjust when AutoOps detects this event and presents the insight. Refer to AutoOps event settings for details.
The default customization settings are:
| Setting | Type | Default |
|---|---|---|
| Rejected search count threshold | Integer | 1 |
| Consecutive samples above threshold | Integer | 1 |
Raising these thresholds reduces noise but delays detection. Lowering them triggers the insight sooner but can increase alerts during minor blips.
The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.
Search requests are being rejected on es-data-01 and es-data-02.
- Indices with high search activity:
logs-prod-000045
AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.
Increase replica count
Condition: Shown when high-searching activity is detected and if index has no replica.
Set number_of_replicas to 1 on logs-prod-000045 (currently 2) using the action below.
PUT logs-prod-000045/_settings
{
"index": {
"number_of_replicas": 1
}
}
Requires the manage index privilege. Requires Elasticsearch 8.0.0 or later. This action changes cluster or index configuration.
Enable and review search slow logs
Condition: Shown when search rejections occur on the node.
Enable search slow logs with the action below, then review the slow log to find expensive queries. See Slow logs for configuration details.
PUT logs-prod-000045/_settings
{
"index.search.slowlog.threshold.query.warn": "10s",
"index.search.slowlog.threshold.query.info": "5s",
"index.search.slowlog.threshold.query.debug": "2s",
"index.search.slowlog.threshold.query.trace": "500ms",
"index.search.slowlog.threshold.fetch.warn": "1s",
"index.search.slowlog.threshold.fetch.info": "800ms",
"index.search.slowlog.threshold.fetch.debug": "500ms",
"index.search.slowlog.threshold.fetch.trace": "200ms"
}
Requires the manage index privilege. Requires Elasticsearch 8.0.0 or later. This action changes cluster or index configuration.
Add data node
Condition: Shown when high-searching activity is detected and if index has more than twice as many pri/rep shards as available data nodes.
Add a data node to increase capacity and reduce pressure on the existing nodes.
Review high search queue load
Condition: Always shown for this insight.
Investigate what is filling the search thread pool queue on es-data-01: expensive queries, under-sized search capacity, or hotspot nodes. Enable and review search slow logs to identify costly queries, then tune queries or add search capacity as needed.
When Elasticsearch rejects search requests, callers receive errors instead of results. That breaks dashboards and applications that depend on those queries.
Rejections often follow sustained search pressure: a full or backed-up search thread pool, queries that are too expensive for available memory or CPU, or circuit breakers that trip while building responses. After an upgrade, incompatible query DSL can also cause rejections.
If rejections continue, search availability stays degraded until load drops, queries are fixed, or capacity increases.