Monitor workflow execution
After you run a workflow, you can track its progress in real time, review past executions, and diagnose any failures. This page explains how to use the execution panel and logs on the Executions tab to understand what happened during a workflow run.
To use workflows, you must turn on the feature and ensure your role has the appropriate privileges. Refer to Set up Workflows for more information.
You must also have the appropriate subscription. Refer to the subscription page for Elastic Cloud and Elastic Stack/self-managed for the breakdown of available features and their associated subscription tiers.
On Elastic Cloud Hosted, workflows is billed based on workflow executions. Each workflow run counts as one execution, including runs that fail, are canceled, or time out. Runs skipped by concurrency controls are not metered.
The first 10,000 workflow executions across the Elastic Cloud Hosted deployments in an Elastic Cloud organization each month are included. Additional executions are billed according to the published amounts.
When a workflow invokes an agent, the Elastic Agent Builder execution is metered separately. Refer to the Hosted add-ons pricing table for current billing amounts.
This billing model doesn't apply to Elastic Cloud Hosted FedRAMP authorized Cloud offerings, which remain under promotional pricing.
When a workflow runs, the execution panel displays:
- Real-time logs: Each step appears as it executes.
- Status indicators: Green indicates success and red represents failure.
- Timestamps: The duration of each step.
- Expandable details: Click any step to examine details such as input parameters, output data, and execution timelines.
Every execution begins with a trigger entry that shows how the run started, such as a manual run, a schedule, an alert, or an event. Expand this entry to see the input the workflow received, including the full event payload for event-driven runs. This lets you trace an execution back to the event or action that started it, which is especially useful when workflows react to one another through event-driven triggers.
To review past runs, select the Executions tab, then select each run to see detailed logs. Workflow runs can have the following statuses:
- Pending: The run hasn't started yet.
- Queued: The run is in the concurrency backlog waiting for a slot. For more information, refer to Concurrency control.
- Running: The run is executing at least one step.
- Waiting: The run paused on a
waitstep, awaitForInputorwaitForApprovalstep, or while waiting for a child workflow to finish. - Success: The run finished successfully.
- Error: The run stopped because a step failed and the workflow didn't recover.
- Canceled: The run was stopped before it finished.
- Timed out: The run exceeded its workflow timeout.
- Skipped: The run was discarded because another execution was already in flight.
To start a new test run with data from a past execution, open the workflow in the editor and follow Reuse data from a previous run. After a run from the editor finishes, you can also click the Run again icon in the execution panel to open the Test workflow dialog with that run already selected.
When a workflow fails, open the failed execution from the Executions tab, then find the step with the error indicator. Expand the step to view the error message and to learn more about the root cause, such the input that caused the failure. After fixing an error, save the workflow before running it again.
Common issues that can cause failures:
| Issue | Cause | Solution |
|---|---|---|
| Syntax error | Invalid YAML | Check indentation and formatting. |
| Step failed | Action error | Review step configuration and inputs. |
| Missing variable | Undefined reference | Verify variable names and data flow. |