> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vortexiq.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Elasticsearch on Vortex IQ

> Monitor Elasticsearch health, cost and reliability signals, and catch incidents and runaway spend early.

Monitor Elasticsearch health, cost and reliability signals, and catch incidents and runaway spend early.

No changes are made without the configured approval policy. Read-only operations do not modify the connected system; schedules, access scopes, API usage and data handling remain governed by Vortex IQ controls.

[Connect or manage this source](https://app.vortexiq.ai/workbench/settings/sources) · [How connecting works](/integrations/connector-catalogue)

| **34**              | **8**            | **Build your own** | **Ready to build yours** | **8**          |
| ------------------- | ---------------- | ------------------ | ------------------------ | -------------- |
| performance signals | automated checks | automated fixes    | workflows                | API operations |

## Monitor performance

34 performance signals. Signals with an alert band can raise Nerve Centre alerts; every signal supports a merchant-configured watcher.

| Signal                                                 | Outcome         | Alert behaviour      | What it tracks                                                                                                                                  |
| ------------------------------------------------------ | --------------- | -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
| **Bulk Rejections (24h)**                              | Protect revenue | Merchant rule        | thread\_pool.write.rejected. Indexing backpressure = client retry / data loss risk.                                                             |
| **Cluster Not Green (yellow or red)**                  | Grow revenue    | Merchant rule        | Elasticsearch-distinctive ,  RED = data unavailable on affected indexes. Page on-call.                                                          |
| **Cluster Status (green / yellow / red)**              | Grow revenue    | Merchant rule        | From /\_cluster/health.status. Elasticsearch-defining: YELLOW = replicas missing, RED = primary unallocated.                                    |
| **ES Product Index Doc Count vs Ecom Catalog**         | Protect revenue | Merchant rule        | Elasticsearch-distinctive XC ,  drift = product-sync to search broken; merchants miss SKUs in search results.                                   |
| **ES Search Pool Saturation vs Ecom Burst**            | Protect revenue | Alert band 70 / 90   | ES Search Pool Saturation vs Ecom Burst, broken down by row.                                                                                    |
| **Indexing Rate (docs/sec)**                           | Grow revenue    | Watch only           | From indices.indexing.index\_total delta. Elasticsearch-distinctive ,  drives sync-lag investigations.                                          |
| **JVM Heap >85% Sustained or Circuit Breaker Tripped** | Run operations  | Merchant rule        | Alerts for JVM Heap >85% Sustained or Circuit Breaker Tripped.                                                                                  |
| **JVM Heap Used %**                                    | Grow revenue    | Merchant rule        | Elasticsearch-distinctive ,  JVM heap >75% triggers GC pressure + circuit breakers; >90% = node may OOM.                                        |
| **Last Snapshot Age (hours)**                          | Run operations  | Alert band 24 / 72   | Last successful \_snapshot run from registered repository.                                                                                      |
| **Query Cache Hit Rate %**                             | Run operations  | Alert band 95 / 80   | Sum of indices.query\_cache.hit\_count / (hit\_count + miss\_count) across all nodes from /\_nodes/stats/indices - cumulative since node start. |
| **Search Error Rate Spike (>1% in 5m)**                | Grow revenue    | Alert band 0.1 / 1   | Alerts for Search Error Rate Spike (>1% in 5m).                                                                                                 |
| **Search Latency p95 (ms)**                            | Grow revenue    | Alert band 50 / 200  | From indices.search.query\_time\_in\_millis / query\_total delta. Storefront-facing ,  directly user-impacting.                                 |
| **Shard Size Skew %**                                  | Grow revenue    | Merchant rule        | (max shard size - min shard size) / avg. >25% = hot shard. Elasticsearch-distinctive.                                                           |
| **Slow Searches During Checkout Window (5m)**          | Protect revenue | Merchant rule        | Slow Searches During Checkout Window (5m), broken down by row.                                                                                  |
| **Slow-Query Rate %**                                  | Grow revenue    | Alert band 1 / 5     | Searches exceeding slowlog threshold (default 1s) as % of total.                                                                                |
| **Storage Usage %**                                    | Run operations  | Alert band 70 / 90   | Disk usage relative to flood-stage watermark (default 95%). Hitting marks indexes read-only.                                                    |
| **Unassigned Shards**                                  | Protect revenue | Merchant rule        | From /\_cluster/health.unassigned\_shards. Any unassigned = data loss risk for that shard's replicas.                                           |
| **Active Node Count**                                  | Run operations  | Merchant rule        | Description pending editorial review; the signal is live.                                                                                       |
| **Elasticsearch Health Score**                         | Grow revenue    | Merchant rule        | Description pending editorial review; the signal is live.                                                                                       |
| **HTTP Connection Saturation %**                       | Run operations  | Alert band 70 / 90   | Description pending editorial review; the signal is live.                                                                                       |
| **Replica Sync Lag**                                   | Run operations  | Alert band 1 / 10    | Description pending editorial review; the signal is live.                                                                                       |
| **Search Error Rate %**                                | Grow revenue    | Alert band 0.1 / 1   | Description pending editorial review; the signal is live.                                                                                       |
| **Search Latency p99 (ms)**                            | Grow revenue    | Alert band 100 / 500 | Description pending editorial review; the signal is live.                                                                                       |
| **Search QPS Spike vs Ecom Traffic**                   | Protect revenue | Merchant rule        | Description pending editorial review; the signal is live.                                                                                       |
| **Search Queries per Second (live)**                   | Grow revenue    | Watch only           | Description pending editorial review; the signal is live.                                                                                       |
| **Avg Index Refresh Time (ms)**                        | Run operations  | Merchant rule        | indices.refresh.total\_time\_in\_millis / refresh.total. Climbing = segments stacking up.                                                       |
| **Circuit Breaker Trips (24h)**                        | Run operations  | Merchant rule        | From breakers tripped count. Requests rejected to prevent OOM.                                                                                  |
| **GC Pause Time (5m total ms)**                        | Grow revenue    | Merchant rule        | From jvm.gc.collectors. Long pauses = node temporarily unavailable for search/indexing.                                                         |
| **Pending Cluster Tasks**                              | Run operations  | Merchant rule        | From /\_cluster/pending\_tasks. High = master node overloaded with cluster-state updates.                                                       |
| **Top 10 Slow Searches**                               | Grow revenue    | Watch only           | Top 10 Slow Searches, broken down by row.                                                                                                       |
| **HTTP Connections In Use**                            | Run operations  | Watch only           | Description pending editorial review; the signal is live.                                                                                       |
| **Initializing / Relocating Shards**                   | Run operations  | Merchant rule        | Description pending editorial review; the signal is live.                                                                                       |
| **Search Latency p50 (ms)**                            | Grow revenue    | Watch only           | Description pending editorial review; the signal is live.                                                                                       |
| **Total Shards (primary + replica)**                   | Run operations  | Watch only           | Description pending editorial review; the signal is live.                                                                                       |

## Audit risks and opportunities

A fix status appears only where the action, inputs, approval, verification and recovery controls are mapped. Candidate remediations are never executable.

| Check                                           | Severity | Outcome             | Why it matters                                                                                                                                                                                 | Fix status  |
| ----------------------------------------------- | -------- | ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------- |
| **Connection pool saturation above 90%**        | critical | Customer experience | At 90% of the connection pool in use, the database is close to refusing new connections outright. Once it does, every part of the application that needs a fresh database connection, includin | Report only |
| **Disk usage above 90%**                        | critical | Run operations      | A database that runs out of disk stops accepting writes entirely, which for most stores means orders, inventory updates and customer records stop being saved, not just that the database gets | Report only |
| **Query error rate above 1% in last 5 minutes** | critical | Run operations      | More than 1 in 100 queries is failing right now. Depending on what those queries do, this can mean orders not saving, pages failing to load product or customer data, or background jobs silen | Report only |
| **Last successful backup older than 72 hours**  | high     | Run operations      | If something goes wrong with this database right now, the most recent point it can be restored to is over 3 days old. Every order, customer record and inventory change since that backup woul | Report only |
| **Replication lag above 10 seconds**            | high     | Run operations      | Anything reading from the replica, reports, dashboards, or read traffic split off the primary for capacity, is now up to 10+ seconds stale. If the primary fails while lag is this high, the r | Report only |
| **Slow-query rate above 5% of total**           | high     | Customer experience | More than 1 in 20 queries is landing in the slow bucket. That is frequent enough to be a pattern, not noise, and it means a meaningful share of every page load or job that touches this datab | Report only |
| **p95 query latency above 200ms sustained 15m** | high     | Customer experience | One in twenty queries against this database is taking over 200ms, sustained for at least 15 minutes, not a brief spike. Any storefront page, checkout step or order sync that depends on this  | Report only |
| **Buffer / cache hit rate below 80%**           | medium   | Run operations      | More than 1 in 5 reads is missing the cache and going to disk instead, which is markedly slower. This shows up as everything the database does feeling incrementally heavier, rather than as o | Report only |

### Build your own automated fixes

8 checks report findings on Elasticsearch today. Turn any finding into an automated fix with a Vortex IQ workflow: **13,885 read and write operations across 229 connectors** are available as building blocks, with approval, verification and rollback on every change.

## Automate approved work

Vortex IQ is integrated with **8 read** and **0 write** operations across catindices, catshards, clusterhealths, clusterpendingtasks, clusterstats, nodestats on Elasticsearch. Combine them with anything from the **13,885 operations across 229 connectors** to automate the work in your own words.

Changes follow the merchant's configured approval policy: the target, proposed change, affected records, risk, reversibility and verification plan are shown before execution. Read-only operations do not modify the connected system.

[Create a workflow](https://app.vortexiq.ai/workbench/flows/create?connector=elasticsearch)

<Accordion title="Browse the operations you can build with">
  | Resource            | Read operations | Write operations |
  | ------------------- | --------------- | ---------------- |
  | catindices          | 1               | 0                |
  | catshards           | 1               | 0                |
  | clusterhealths      | 1               | 0                |
  | clusterpendingtasks | 1               | 0                |
  | clusterstats        | 1               | 0                |
  | nodestats           | 1               | 0                |
  | nodestathttps       | 1               | 0                |
  | snapshotstatus      | 1               | 0                |

  Signed-in users see the full catalogue in the workflow builder, filtered to the sources they have connected.
</Accordion>

### Ready to build your first Elasticsearch workflow

Pick a trigger, add the operations above as steps, and every step that changes data pauses for your approval. Monitoring and audits are live now and can start any workflow you build.

***

*Generated from the connector capability graph. Counts reflect the servable registry after alias normalisation and de-duplication, and refresh automatically when the registry changes.*
