Slow indexing

Indexing latency on one or more nodes stayed above your configured threshold for enough consecutive samples. Slow writes can fill the write queue and eventually cause indexing rejections.

Note

For a complete list of insights, refer to AutoOps insights.

Field Value
Component Elasticsearch
Severity High
Scope Node
Domains performance, indexing

You can customize these settings to adjust when AutoOps detects this event and presents the insight. Refer to AutoOps event settings for details.

The default customization settings are:

Setting Type Default
Indexing latency threshold (ms) Integer 80
Consecutive samples above threshold Integer 1
Tip

Raising these thresholds reduces noise but delays detection. Lowering them triggers the insight sooner but can increase alerts during minor blips.

The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.

Indexing latency on es-data-01 and es-data-02 stayed above your configured threshold for enough consecutive samples. Peak latency over the evaluated window was 420 ms.

  • Indices with high indexing activity: logs-prod-000045
Note

AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.

When each index operation takes too long, the write queue fills and indexing requests can be rejected. Common causes include large or complex documents, costly mappings or analyzers, a high ingest rate, disk I/O pressure, and competing background work on the same node.

If latency stays high, ingest falls behind and client retries can add more load.