Description
Search and indexing slow logs in Amazon OpenSearch Service help investigate operations exceeding configured thresholds. Both log publishing and domain thresholds are required; these logs do not replace audit logs.
Potential impact
Without slow logs, identifying the cause of slow searches or indexing operations can be harder.
Remediation
Enable the required SEARCH_SLOW_LOGS and INDEX_SLOW_LOGS in LogPublishingOptions, and configure CloudWatch Logs groups and write permissions. Set suitable slow-log thresholds on the domain as well.
Examples
The examples enable log publishing on an existing AWS::Elasticsearch::Domain resource. The same settings apply to AWS::OpenSearchService::Domain. Log-group policies and thresholds are omitted.
Before
AWSTemplateFormatVersion: "2010-09-09"
Description: Slow-log publishing example
Resources:
ElasticsearchDomain:
Type: "AWS::Elasticsearch::Domain"
Properties:
DomainName:
Ref: DomainName
LogPublishingOptions:
SEARCH_SLOW_LOGS:
CloudWatchLogsLogGroupArn: >-
arn:aws:logs:us-east-1:123456789012:log-group:/aws/aes/domains/es-slow-logs
Enabled: "false"
INDEX_SLOW_LOGS:
CloudWatchLogsLogGroupArn: >-
arn:aws:logs:us-east-1:123456789012:log-group:/aws/aes/domains/es-index-slow-logs
Enabled: "false"
After
AWSTemplateFormatVersion: "2010-09-09"
Description: Slow-log publishing example
Resources:
ElasticsearchDomain:
Type: "AWS::Elasticsearch::Domain"
Properties:
DomainName:
Ref: DomainName
LogPublishingOptions:
SEARCH_SLOW_LOGS:
CloudWatchLogsLogGroupArn: >-
arn:aws:logs:us-east-1:123456789012:log-group:/aws/aes/domains/es-slow-logs
Enabled: "true"
INDEX_SLOW_LOGS:
CloudWatchLogsLogGroupArn: >-
arn:aws:logs:us-east-1:123456789012:log-group:/aws/aes/domains/es-index-slow-logs
Enabled: "true"