Skip to content

Elasticsearch issues

Use this guide when network, DNS, TLS, and authentication are working but Elasticsearch, Kibana, indexing, or search behavior is not.

Start with Troubleshooting overview.

Check Elasticsearch health

Users with appropriate permissions can review high-level cluster health.

curl --fail-with-body --user "<user>" \
  "https://<elasticsearch-hostname>/_cluster/health?pretty"

Review the cluster status:

Status Meaning
Green Primary and replica shards are available
Yellow Primary shards are available, but one or more replicas are unavailable
Red One or more primary shards are unavailable

Persistent yellow or any red condition should be investigated.

Do not modify shard allocation, disk watermarks, Kubernetes resources, or Elasticsearch infrastructure directly.

Indexing fails

If an application cannot index documents, record the HTTP status code and redacted error message.

Common areas to check include:

  • target index or data-stream name;
  • mapping conflicts;
  • document format;
  • API-key or user permissions;
  • rejected requests;
  • available capacity.

Typical HTTP responses include:

Status Typical cause
400 Invalid document, mapping, or request
401 Authentication
403 Insufficient privileges
404 Incorrect target or endpoint
409 Document or version conflict
429 Elasticsearch is temporarily unable to accept more work
5xx Service or platform condition

Do not grant administrator privileges to an application just to bypass an indexing error.

Observability data is missing

For logs, metrics, or traces, first determine whether the problem is before or after Elasticsearch.

Check:

  1. Fleet → Agents and confirm the Elastic Agent is Healthy.
  2. Confirm the correct Fleet policy is assigned.
  3. Confirm the expected OpenTelemetry or Elastic integration is enabled.
  4. Verify the source is actually producing telemetry.
  5. Confirm the expected OTel-native dataset or data stream exists.
  6. Check the Kibana time range and filters.

For OpenTelemetry workloads, also verify important resource attributes such as:

  • service.name;
  • environment;
  • host;
  • cloud;
  • Kubernetes metadata.

If the Elastic Agent is unhealthy, troubleshoot Fleet or connectivity first.

Search returns no results

If a query returns no data:

  1. Confirm the expected index or data stream exists.
  2. Confirm it contains documents.
  3. Confirm the user has read access.
  4. Check the Kibana data view.
  5. Check the selected time range.
  6. Confirm the query uses the expected fields.
  7. Verify that data was not written to a different index, data stream, or dataset.

For application search, also review mappings and analyzers when the document exists but expected text does not match.

Search results are incorrect

If documents are returned but relevance or filtering is incorrect, review:

  • field mappings;
  • text versus keyword fields;
  • analyzers;
  • query structure;
  • filters;
  • document values;
  • vector or semantic-search configuration when used.

This is usually an application/search-design issue rather than a managed-platform health problem.

Kibana does not load correctly

If Kibana cannot be reached at all, use Connectivity issues.

If Kibana loads but behaves incorrectly, check:

  • authentication;
  • user roles;
  • Kibana space access;
  • Elasticsearch health;
  • expected indices and data streams;
  • browser session state.

For SSO issues, verify Microsoft Entra authentication and Elastic role mappings.

Writes are blocked or requests return 429

Sustained capacity pressure can affect indexing.

Do not change Elasticsearch disk watermarks or managed infrastructure directly.

Check:

  • whether ingestion recently increased;
  • whether retention increased;
  • whether stored data is growing rapidly;
  • whether query or indexing demand changed.

If the condition persists, request a capacity review through iVedha.

See Monitor health and capacity.

Collect evidence

Before escalating, collect:

  • deployment reference;
  • affected index or data stream;
  • approximate start time;
  • HTTP status;
  • redacted Elasticsearch error;
  • whether all workloads or only one workload is affected;
  • Elastic Agent status when relevant;
  • affected OpenTelemetry signal: logs, metrics, or traces.

Do not include passwords, API keys, enrollment tokens, private keys, or sensitive production documents.

Get help

For managed-platform investigation:

  • AI chat: https://copilot.opsflw.io
  • Support portal: https://support.ivedha.com/

For detailed Elasticsearch product behavior, use Elastic’s official troubleshooting documentation.