Loading

Increase in shards count

The number of shards on a node jumped sharply compared with the prior observation window, faster than normal growth for that cluster. Frequent index creation, high primary counts per index, daily rollovers, extra replicas, splits, or ingest spikes are common drivers.

Note

For a complete list of insights, refer to AutoOps insights.

Field Value
Component Elasticsearch
Severity Medium
Scope Index
Domains index-management, shard-allocation

You can customize these settings to adjust when AutoOps detects this event and presents the insight. Refer to AutoOps event settings for details.

The default customization settings are:

Setting Type Default
Minimum shards count threshold Integer 500
Minimum shards increase percentage Percentage 50
Shard increase check period in hours Integer 12
Minimum shards count increase Integer 50

The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.

An unusual increase in the number of shards was identified on node es-data-01 and es-data-02. Over the past 48 hours, the number of shards has increased by 12%. However, in the previous period of 48 hours, the number of shards had increased only by 12%.

Note

AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.

The sharp increase of shards can occur due to frequent index creation, high shard settings per index, daily time-based indices, rollover actions, excessive use of replicas, index splitting, increased data intake, or a lack of shard optimization or merging. A rapid, unsupervised rise in the number of shards can negatively impact performance.

Size your shards