Troubleshooting shards capacity health issues

Elasticsearch limits the maximum number of shards to be held per node using the cluster.max_shards_per_node and cluster.max_shards_per_node.frozen settings. The current shards capacity of the cluster is available in the health API shards capacity section.

Cluster is close to reaching the configured maximum number of shards for data nodes. ¶

The cluster.max_shards_per_node cluster setting limits the maximum number of open shards for a cluster, only counting data nodes that do not belong to the frozen tier.

This symptom indicates that action should be taken, otherwise, either the creation of new indices or upgrading the cluster could be blocked.

If you’re confident your changes won’t destabilize the cluster, you can temporarily increase the limit using the cluster update settings API:

Use Kibana

  1. Log in to the Elastic Cloud console.
  2. On the Elasticsearch Service panel, click the name of your deployment.

Note

If the name of your deployment is disabled your Kibana instances might be unhealthy, in which case please contact Elastic Support. If your deployment doesn’t include Kibana, all you need to do is enable it first.
::::

  1. Open your deployment’s side navigation menu (placed under the Elastic logo in the upper left corner) and go to Dev Tools > Console.
{{kib}} Console
  1. Check the current status of the cluster according the shards capacity indicator:
    			    GET _health_report/shards_capacity
    			
    		
    The response will look like this:
    			{
      "cluster_name": "...",
      "indicators": {
        "shards_capacity": {
          "status": "yellow",
          "symptom": "Cluster is close to reaching the configured maximum number of shards for data nodes.",
          "details": {
            "data": {
              "max_shards_in_cluster": 1000, 1
              "current_used_shards": 988 2
            },
            "frozen": {
              "max_shards_in_cluster": 3000,
              "current_used_shards": 0
            }
          },
          "impacts": [
            ...
          ],
          "diagnosis": [
            ...
        }
      }
    }
    
    		
    1. Current value of the setting cluster.max_shards_per_node
    2. Current number of open shards across the cluster
  2. Update the cluster.max_shards_per_node setting with a proper value:
    			    PUT _cluster/settings
    			{
      "persistent" : {
        "cluster.max_shards_per_node": 1200
      }
    }
    
    		
    This increase should only be temporary. As a long-term solution, we recommend you add nodes to the oversharded data tier or reduce your cluster’s shard count on nodes that do not belong to the frozen tier.
  3. To verify that the change has fixed the issue, you can get the current status of the shards_capacity indicator by checking the data section of the health API:
    			    GET _health_report/shards_capacity
    			
    		
    The response will look like this:
    			{
      "cluster_name": "...",
      "indicators": {
        "shards_capacity": {
          "status": "green",
          "symptom": "The cluster has enough room to add new shards.",
          "details": {
            "data": {
              "max_shards_in_cluster": 1000
            },
            "frozen": {
              "max_shards_in_cluster": 3000
            }
          }
        }
      }
    }
    
    		
  4. When a long-term solution is in place, we recommend you reset the cluster.max_shards_per_node limit.
    			    PUT _cluster/settings
    			{
      "persistent" : {
        "cluster.max_shards_per_node": null
      }
    }
    
    		

Check the current status of the cluster according the shards capacity indicator:

			GET _health_report/shards_capacity
			
		

The response will look like this:

			{
  "cluster_name": "...",
  "indicators": {
    "shards_capacity": {
      "status": "yellow",
      "symptom": "Cluster is close to reaching the configured maximum number of shards for data nodes.",
      "details": {
        "data": {
          "max_shards_in_cluster": 1000, 1
          "current_used_shards": 988 2
        },
        "frozen": {
          "max_shards_in_cluster": 3000
        }
      },
      "impacts": [
        ...
      ],
      "diagnosis": [
        ...
    }
  }
}

		
  1. Current value of the setting cluster.max_shards_per_node
  2. Current number of open shards across the cluster

Using the cluster settings API, update the cluster.max_shards_per_node setting:

			PUT _cluster/settings
			{
  "persistent" : {
    "cluster.max_shards_per_node": 1200
  }
}

		

This increase should only be temporary. As a long-term solution, we recommend you add nodes to the oversharded data tier or reduce your cluster’s shard count on nodes that do not belong to the frozen tier. To verify that the change has fixed the issue, you can get the current status of the shards_capacity indicator by checking the data section of the health API:

			GET _health_report/shards_capacity
			
		

The response will look like this:

			{
  "cluster_name": "...",
  "indicators": {
    "shards_capacity": {
      "status": "green",
      "symptom": "The cluster has enough room to add new shards.",
      "details": {
        "data": {
          "max_shards_in_cluster": 1200
        },
        "frozen": {
          "max_shards_in_cluster": 3000
        }
      }
    }
  }
}

		

When a long-term solution is in place, we recommend you reset the cluster.max_shards_per_node limit.

			PUT _cluster/settings
			{
  "persistent" : {
    "cluster.max_shards_per_node": null
  }
}

		

Cluster is close to reaching the configured maximum number of shards for frozen nodes. ¶

The cluster.max_shards_per_node.frozen cluster setting limits the maximum number of open shards for a cluster, only counting data nodes that belong to the frozen tier.

This symptom indicates that action should be taken, otherwise, either the creation of new indices or upgrading the cluster could be blocked.

If you’re confident your changes won’t destabilize the cluster, you can temporarily increase the limit using the cluster update settings API:

Use Kibana

  1. Log in to the Elastic Cloud console.
  2. On the Elasticsearch Service panel, click the name of your deployment.

Note

If the name of your deployment is disabled your Kibana instances might be unhealthy, in which case please contact Elastic Support. If your deployment doesn’t include Kibana, all you need to do is enable it first.
::::

  1. Open your deployment’s side navigation menu (placed under the Elastic logo in the upper left corner) and go to Dev Tools > Console.
{{kib}} Console
  1. Check the current status of the cluster according the shards capacity indicator:
    			    GET _health_report/shards_capacity
    			
    		
    The response will look like this:
    			{
      "cluster_name": "...",
      "indicators": {
        "shards_capacity": {
          "status": "yellow",
          "symptom": "Cluster is close to reaching the configured maximum number of shards for frozen nodes.",
          "details": {
            "data": {
              "max_shards_in_cluster": 1000
            },
            "frozen": {
              "max_shards_in_cluster": 3000, 1
              "current_used_shards": 2998 2
            }
          },
          "impacts": [
            ...
          ],
          "diagnosis": [
            ...
        }
      }
    }
    
    		
    1. Current value of the setting cluster.max_shards_per_node.frozen
    2. Current number of open shards used by frozen nodes across the cluster
  2. Update the cluster.max_shards_per_node.frozen setting:
    			    PUT _cluster/settings
    			{
      "persistent" : {
        "cluster.max_shards_per_node.frozen": 3200
      }
    }
    
    		
    This increase should only be temporary. As a long-term solution, we recommend you add nodes to the oversharded data tier or reduce your cluster’s shard count on nodes that belong to the frozen tier.
  3. To verify that the change has fixed the issue, you can get the current status of the shards_capacity indicator by checking the data section of the health API:
    			    GET _health_report/shards_capacity
    			
    		
    The response will look like this:
    			{
      "cluster_name": "...",
      "indicators": {
        "shards_capacity": {
          "status": "green",
          "symptom": "The cluster has enough room to add new shards.",
          "details": {
            "data": {
              "max_shards_in_cluster": 1000
            },
            "frozen": {
              "max_shards_in_cluster": 3200
            }
          }
        }
      }
    }
    
    		
  4. When a long-term solution is in place, we recommend you reset the cluster.max_shards_per_node.frozen limit.
    			    PUT _cluster/settings
    			{
      "persistent" : {
        "cluster.max_shards_per_node.frozen": null
      }
    }
    
    		

Check the current status of the cluster according the shards capacity indicator:

			GET _health_report/shards_capacity
			
		
			{
  "cluster_name": "...",
  "indicators": {
    "shards_capacity": {
      "status": "yellow",
      "symptom": "Cluster is close to reaching the configured maximum number of shards for frozen nodes.",
      "details": {
        "data": {
          "max_shards_in_cluster": 1000
        },
        "frozen": {
          "max_shards_in_cluster": 3000, 1
          "current_used_shards": 2998 2
        }
      },
      "impacts": [
        ...
      ],
      "diagnosis": [
        ...
    }
  }
}

		
  1. Current value of the setting cluster.max_shards_per_node.frozen.
  2. Current number of open shards used by frozen nodes across the cluster.

Using the cluster settings API, update the cluster.max_shards_per_node.frozen setting:

			PUT _cluster/settings
			{
  "persistent" : {
    "cluster.max_shards_per_node.frozen": 3200
  }
}

		

This increase should only be temporary. As a long-term solution, we recommend you add nodes to the oversharded data tier or reduce your cluster’s shard count on nodes that belong to the frozen tier. To verify that the change has fixed the issue, you can get the current status of the shards_capacity indicator by checking the data section of the health API:

			GET _health_report/shards_capacity
			
		

The response will look like this:

			{
  "cluster_name": "...",
  "indicators": {
    "shards_capacity": {
      "status": "green",
      "symptom": "The cluster has enough room to add new shards.",
      "details": {
        "data": {
          "max_shards_in_cluster": 1000
        },
        "frozen": {
          "max_shards_in_cluster": 3200
        }
      }
    }
  }
}

		

When a long-term solution is in place, we recommend you reset the cluster.max_shards_per_node.frozen limit.

			PUT _cluster/settings
			{
  "persistent" : {
    "cluster.max_shards_per_node.frozen": null
  }
}

		

Admonition

If you’re using Elastic Cloud Hosted, then you can use AutoOps to monitor your cluster. AutoOps significantly simplifies cluster management with performance recommendations, resource utilization visibility, real-time issue detection and resolution paths. For more information, refer to Monitor with AutoOps.