﻿---
title: Slow search on content tier nodes
description: Describes what AutoOps detects and surfaces with the Slow search on content tier nodes insight: Search on content-tier nodes exceeded the content-tier latency threshold for consecutive samples.
url: https://docs-v3-preview.elastic.dev/elastic/autoops-insights/tree/main/elasticsearch/slow_search_on_content_tier_nodes
products:
  - Elastic Cloud Enterprise
  - Elastic Cloud Hosted
  - Elastic Cloud on Kubernetes
  - Elasticsearch
applies_to:
  - Elastic Cloud Hosted: Generally available
  - Elastic Cloud on Kubernetes: Generally available
  - Elastic Cloud Enterprise: Generally available
  - Self-managed Elastic deployments: Generally available
---

# Slow search on content tier nodes
Search on content-tier nodes exceeded the content-tier latency threshold for consecutive samples. Content indices often hold large, mixed workloads, so slow queries here can affect many applications at once.
<note>
  For a complete list of insights, refer to [AutoOps insights](https://docs-v3-preview.elastic.dev/elastic/autoops-insights/tree/main/elasticsearch).
</note>


## Insight details


| Field     | Value               |
|-----------|---------------------|
| Component | Elasticsearch       |
| Severity  | High                |
| Scope     | Node                |
| Domains   | performance, search |


## Customization settings

You can customize these settings to adjust when AutoOps detects this event and presents the insight. Refer to [AutoOps event settings](https://docs-v3-preview.elastic.dev/elastic/docs-content/tree/main/deploy-manage/monitor/autoops/ec-autoops-event-settings) for details.
The default customization settings are:

| Setting                             | Type    | Default |
|-------------------------------------|---------|---------|
| Search latency threshold (ms)       | Integer | 250     |
| Consecutive samples above threshold | Integer | 5       |

<tip>
  Raising these thresholds reduces noise but delays detection. Lowering them triggers the insight sooner but can increase alerts during minor blips.
</tip>


## Example: What you might see in AutoOps

The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.

### Slow search detected on `es-data-01`


#### What was detected

Search latency on `es-data-01` and `es-data-02` on content-tier nodes stayed above your configured threshold for enough consecutive samples. Peak latency in the latest sample was 420 ms. Indices with high search activity: `logs-prod-000045` Indices with high indexing activity on the same node: `logs-prod-000045` Review query logs or search slow logs on the affected node, tune expensive queries, and check CPU, heap, and indexing load on the same node if latency stays high.

#### Recommendations

<note>
  AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.
</note>

<dropdown title="Increase replica count">
  **Condition**: Shown when index has no replica.Set `number_of_replicas` to 2 on logs-prod-000045 (currently 1) using the action below.
  ```json

  {
    "index": {
      "number_of_replicas": 2
    }
  }
  ```

  <note>
    Requires the `manage` index privilege. Requires Elasticsearch 8.0.0 or later. This action changes cluster or index configuration.
  </note>
</dropdown>

<dropdown title="Review query logs">
  **Condition**: Shown when cluster version is 9.4 or above.Review query logs on `es-data-01` to find expensive searches that fill the queue. Query logs (Elasticsearch 9.4+) give structured per-query timing with less overhead than search slow logs. See [Query logs](https://docs-v3-preview.elastic.dev/elastic/docs-content/tree/main/deploy-manage/monitor/logging-configuration/query-logs).
</dropdown>

<dropdown title="Enable and review search slow logs">
  **Condition**: Shown when cluster version is below 9.4.Enable search slow logs with the action below, then review the slow log to find expensive queries. See [Slow logs](https://docs-v3-preview.elastic.dev/elastic/docs-content/tree/main/deploy-manage/monitor/logging-configuration/slow-logs) for configuration details.
  ```json

  {
    "index.search.slowlog.threshold.query.warn": "10s",
    "index.search.slowlog.threshold.query.info": "5s",
    "index.search.slowlog.threshold.query.debug": "2s",
    "index.search.slowlog.threshold.query.trace": "500ms",
    "index.search.slowlog.threshold.fetch.warn": "1s",
    "index.search.slowlog.threshold.fetch.info": "800ms",
    "index.search.slowlog.threshold.fetch.debug": "500ms",
    "index.search.slowlog.threshold.fetch.trace": "200ms"
  }
  ```

  <note>
    Requires the `manage` index privilege. Requires Elasticsearch 8.0.0 or later. This action changes cluster or index configuration.
  </note>
</dropdown>

<dropdown title="Add data node">
  **Condition**: Shown when index has more than twice as many pri/rep shards as available data nodes.Add a data node to increase capacity and reduce pressure on the existing nodes.
</dropdown>


#### Background and impact

When search stays slow on a data node, dashboards and applications feel sluggish even before requests fail. Common causes include expensive or repeated queries, CPU or heap pressure, heavy indexing on the same node, and background work such as segment merges or snapshots. If latency remains high, focus on the indices in the preceding section. Add replicas or data capacity where shard layout limits parallelism. Your log threshold settings control which queries are recorded — tune them to capture the queries most likely driving the latency.