Description
Slow logs help identify search or indexing requests that take too long. Without the logs needed for operations, diagnosing performance problems can become harder. INDEX_SLOW_LOGS publishes indexing slow logs, while SEARCH_SLOW_LOGS publishes search slow logs.
CloudWatch publishing alone does not generate shard slow logs. Per-index thresholds must also be configured; the default value of -1 disables the corresponding logging.
Potential impact
- Diagnosing slow searches or indexing operations can become harder.
- Responding to performance problems can take longer.
- Operational bottlenecks can remain unnoticed for longer.
Remediation
- Enable the required slow-log types in
log_publishing_options, and configure the CloudWatch log group and the service's write permissions. - Set per-index thresholds appropriate for the workload and verify actual log collection. Retain any application logs that are still required.
- Restrict access and retention according to the sensitive content of logs, and review collection volume and cost.
Examples
These excerpts compare log types. Required domain settings, the log group resource policy and per-index thresholds are omitted. Configure all publishing blocks that the environment needs.
Before
hcl
resource "aws_elasticsearch_domain" "example" {
log_publishing_options {
cloudwatch_log_group_arn = aws_cloudwatch_log_group.example.arn
log_type = "ES_APPLICATION_LOGS"
enabled = true
}
}
After
hcl
resource "aws_elasticsearch_domain" "example" {
log_publishing_options {
cloudwatch_log_group_arn = aws_cloudwatch_log_group.example.arn
log_type = "INDEX_SLOW_LOGS"
enabled = true
}
}
Explanation:
- Before: This publishes
ES_APPLICATION_LOGS, rather than configuring search or indexing slow logs. - After: This enables indexing slow-log publishing. Configure search slow logs and the thresholds needed to generate logs separately.