Skip to content

Troubleshooting overview

Start with the symptom. Change one layer at a time and record the result.

Choose a guide

Safe first response

  1. Record the deployment resource ID, time in UTC, user-visible symptom, and last known successful action.
  2. Check whether the issue affects one user, one client network, or all users.
  3. Check the Azure managed application state.
  4. Check DNS, TCP connectivity, TLS, and authentication in that order.
  5. Check Elasticsearch health only after connectivity works.
  6. Stop before a destructive change, broad permission grant, watermark override, certificate replacement, or managed-resource modification.

Protect diagnostic information

Elastic diagnostics and logs can contain settings or data. Remove tokens, passwords, cookies, authorization headers, private keys, personal information, internal addresses not required for the case, and customer data before sharing. Never upload diagnostics to a public issue or forum.