Elasticsearch issues
Use this guide when network, DNS, TLS, and authentication are working but Elasticsearch, Kibana, indexing, or search behavior is not.
Start with Troubleshooting overview.
Check Elasticsearch health
Users with appropriate permissions can review high-level cluster health.
curl --fail-with-body --user "<user>" \
"https://<elasticsearch-hostname>/_cluster/health?pretty"
Review the cluster status:
| Status | Meaning |
|---|---|
| Green | Primary and replica shards are available |
| Yellow | Primary shards are available, but one or more replicas are unavailable |
| Red | One or more primary shards are unavailable |
Persistent yellow or any red condition should be investigated.
Do not modify shard allocation, disk watermarks, Kubernetes resources, or Elasticsearch infrastructure directly.
Indexing fails
If an application cannot index documents, record the HTTP status code and redacted error message.
Common areas to check include:
- target index or data-stream name;
- mapping conflicts;
- document format;
- API-key or user permissions;
- rejected requests;
- available capacity.
Typical HTTP responses include:
| Status | Typical cause |
|---|---|
400 |
Invalid document, mapping, or request |
401 |
Authentication |
403 |
Insufficient privileges |
404 |
Incorrect target or endpoint |
409 |
Document or version conflict |
429 |
Elasticsearch is temporarily unable to accept more work |
5xx |
Service or platform condition |
Do not grant administrator privileges to an application just to bypass an indexing error.
Observability data is missing
For logs, metrics, or traces, first determine whether the problem is before or after Elasticsearch.
Check:
- Fleet → Agents and confirm the Elastic Agent is Healthy.
- Confirm the correct Fleet policy is assigned.
- Confirm the expected OpenTelemetry or Elastic integration is enabled.
- Verify the source is actually producing telemetry.
- Confirm the expected OTel-native dataset or data stream exists.
- Check the Kibana time range and filters.
For OpenTelemetry workloads, also verify important resource attributes such as:
service.name;- environment;
- host;
- cloud;
- Kubernetes metadata.
If the Elastic Agent is unhealthy, troubleshoot Fleet or connectivity first.
Search returns no results
If a query returns no data:
- Confirm the expected index or data stream exists.
- Confirm it contains documents.
- Confirm the user has read access.
- Check the Kibana data view.
- Check the selected time range.
- Confirm the query uses the expected fields.
- Verify that data was not written to a different index, data stream, or dataset.
For application search, also review mappings and analyzers when the document exists but expected text does not match.
Search results are incorrect
If documents are returned but relevance or filtering is incorrect, review:
- field mappings;
- text versus keyword fields;
- analyzers;
- query structure;
- filters;
- document values;
- vector or semantic-search configuration when used.
This is usually an application/search-design issue rather than a managed-platform health problem.
Kibana does not load correctly
If Kibana cannot be reached at all, use Connectivity issues.
If Kibana loads but behaves incorrectly, check:
- authentication;
- user roles;
- Kibana space access;
- Elasticsearch health;
- expected indices and data streams;
- browser session state.
For SSO issues, verify Microsoft Entra authentication and Elastic role mappings.
Writes are blocked or requests return 429
Sustained capacity pressure can affect indexing.
Do not change Elasticsearch disk watermarks or managed infrastructure directly.
Check:
- whether ingestion recently increased;
- whether retention increased;
- whether stored data is growing rapidly;
- whether query or indexing demand changed.
If the condition persists, request a capacity review through iVedha.
See Monitor health and capacity.
Collect evidence
Before escalating, collect:
- deployment reference;
- affected index or data stream;
- approximate start time;
- HTTP status;
- redacted Elasticsearch error;
- whether all workloads or only one workload is affected;
- Elastic Agent status when relevant;
- affected OpenTelemetry signal: logs, metrics, or traces.
Do not include passwords, API keys, enrollment tokens, private keys, or sensitive production documents.
Get help
For managed-platform investigation:
- AI chat:
https://copilot.opsflw.io - Support portal:
https://support.ivedha.com/
For detailed Elasticsearch product behavior, use Elastic’s official troubleshooting documentation.