Indexing Throttle Time
One or more nodes are throttling indexing because they cannot satisfy the current ingest rate. Throttling deliberately slows writes to protect the node from overload.
For a complete list of insights, refer to AutoOps insights.
| Field | Value |
|---|---|
| Component | Elasticsearch |
| Severity | High |
| Scope | Node |
| Domains | performance, indexing |
The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.
No description available.
AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.
Rollover indices
Condition: Shown when high-indexing activity is detected and if index has less primary shards than available data nodes.
If logs-prod-000045 are time-based, roll them over and set 2 primary shards on the new write index so you can avoid a heavy segment merge on the current indices.
Rollover indices by shard size
Condition: Shown when high-indexing activity is detected and if primary shard size > 30GB.
If logs-prod-000045 are time-based, roll them over when average shard size reaches your target.
Review index templates and mappings
Condition: Shown when high-indexing activity is detected and for indexes with highest indexing latency.
Review templates and mappings for logs-prod-000045; they strongly affect indexing performance. Fix oversized mappings, unnecessary fields, and inefficient index settings.
Review indexing slow logs
Condition: Always shown for this insight.
Enable indexing slow logs with the action below on logs-prod-000045, then review the logs to find slow index operations. On Elasticsearch 8.14+, set index.indexing.slowlog.include.user to true to record which user triggered a slow operation.
PUT logs-prod-000045/_settings
{
"index.indexing.slowlog.threshold.index.warn": "10s",
"index.indexing.slowlog.threshold.index.info": "5s",
"index.indexing.slowlog.threshold.index.debug": "2s",
"index.indexing.slowlog.threshold.index.trace": "500ms",
"index.indexing.slowlog.source": "1000"
}
Requires the manage index privilege. Requires Elasticsearch 8.0.0 or later. This action changes cluster or index configuration.
Add data node
Condition: Shown when high-indexing activity is detected and if index has more primary shards as available data nodes.
Add a data node to increase capacity and reduce pressure on the existing nodes.
Impact: Throttling means that the data node is limiting the rate of certain operations (usually indexing operations) because the node cannot keep up with the current rate of demand. If this situation persists, then indexing requests might be rejected. In the best case scenario, data will not be completely up to date, and in the worst case scenario data might be lost if the application fails to retry the throttled write requests. Retrying throttled requests can also put an extra burden on processors upstream since they have to hold data in a queue (if possible) and use resources retrying requests.