> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vortexiq.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Elasticsearch on Vortex IQ

> Monitor Elasticsearch health, cost and reliability signals, and catch incidents and runaway spend early.

Monitor Elasticsearch health, cost and reliability signals, and catch incidents and runaway spend early.

[Connect or manage this source](https://app.vortexiq.ai/workbench/settings/sources) · [How connecting works](/integrations/connector-catalogue) · [Create a workflow](https://app.vortexiq.ai/workbench/flows/create?connector=elasticsearch)

<CardGroup cols={5}>
  <Card title="34">
    performance signals
  </Card>

  <Card title="8">
    automated checks
  </Card>

  <Card title="0">
    prepared fixes
  </Card>

  <Card title="0">
    proven workflows
  </Card>

  <Card title="8">
    API operations
  </Card>
</CardGroup>

<Tabs>
  <Tab title="Overview">
    ### What you can achieve

    Capabilities are grouped around merchant outcomes, not API terminology.

    <CardGroup cols={2}>
      <Card title="Protect revenue">
        Find failures, leaks and risks before they cost sales.
      </Card>

      <Card title="Grow revenue">
        Improve discovery, conversion, campaigns and repeat purchase.
      </Card>

      <Card title="Run operations">
        Monitor orders, fulfilment, delivery and settlement.
      </Card>

      <Card title="Customer experience">
        Find storefront, speed, accessibility and journey problems.
      </Card>
    </CardGroup>

    ### From connection to verified outcome

    The controlled sequence every capability follows. Nothing changes a connected system without the approval step.

    <Steps>
      <Step title="Connect">
        Authorise the source. Scopes are shown before access is granted.
      </Step>

      <Step title="Monitor">
        Watch the signals against your own baselines, not universal defaults.
      </Step>

      <Step title="Detect">
        Run checks and gather evidence specific to your store.
      </Step>

      <Step title="Recommend">
        Explain what happened, why it matters and the proposed action.
      </Step>

      <Step title="Approve">
        You review scope, risk and reversibility before anything changes.
      </Step>

      <Step title="Execute">
        Apply through governed connector operations.
      </Step>

      <Step title="Verify">
        Confirm the intended result and keep the receipt.
      </Step>
    </Steps>

    No changes are made without the configured approval policy. Read-only operations do not modify the connected system; schedules, access scopes, API usage and data handling remain governed by Vortex IQ controls.
  </Tab>

  <Tab title="Monitor (34)">
    ### Monitor performance

    34 performance signals. Open an outcome to see its signals and how each one alerts. Read-only operations do not modify the connected system.

    <AccordionGroup>
      <Accordion title="Grow revenue (15 signals)">
        | Signal                                    | Alert behaviour      | What it tracks                                                                                                 |
        | ----------------------------------------- | -------------------- | -------------------------------------------------------------------------------------------------------------- |
        | **Cluster Not Green (yellow or red)**     | Merchant rule        | Elasticsearch-distinctive , RED = data unavailable on affected indexes. Page on-call.                          |
        | **Cluster Status (green / yellow / red)** | Merchant rule        | From /\_cluster/health.status. Elasticsearch-defining: YELLOW = replicas missing, RED = primary unallocated.   |
        | **Elasticsearch Health Score**            | Merchant rule        | Description pending editorial review; the signal is live.                                                      |
        | **GC Pause Time (5m total ms)**           | Merchant rule        | From jvm.gc.collectors. Long pauses = node temporarily unavailable for search/indexing.                        |
        | **Indexing Rate (docs/sec)**              | Watch only           | From indices.indexing.index\_total delta. Elasticsearch-distinctive , drives sync-lag investigations.          |
        | **JVM Heap Used %**                       | Merchant rule        | Elasticsearch-distinctive , JVM heap >75% triggers GC pressure + circuit breakers; >90% = node may OOM.        |
        | **Search Error Rate %**                   | Alert band 0.1 / 1   | Description pending editorial review; the signal is live.                                                      |
        | **Search Error Rate Spike (>1% in 5m)**   | Alert band 0.1 / 1   | Alerts for Search Error Rate Spike (>1% in 5m).                                                                |
        | **Search Latency p50 (ms)**               | Watch only           | Description pending editorial review; the signal is live.                                                      |
        | **Search Latency p95 (ms)**               | Alert band 50 / 200  | From indices.search.query\_time\_in\_millis / query\_total delta. Storefront-facing , directly user-impacting. |
        | **Search Latency p99 (ms)**               | Alert band 100 / 500 | Description pending editorial review; the signal is live.                                                      |
        | **Search Queries per Second (live)**      | Watch only           | Description pending editorial review; the signal is live.                                                      |
        | **Shard Size Skew %**                     | Merchant rule        | (max shard size - min shard size) / avg. >25% = hot shard. Elasticsearch-distinctive.                          |
        | **Slow-Query Rate %**                     | Alert band 1 / 5     | Searches exceeding slowlog threshold (default 1s) as % of total.                                               |
        | **Top 10 Slow Searches**                  | Watch only           | Top 10 Slow Searches, broken down by row.                                                                      |
      </Accordion>

      <Accordion title="Run operations (13 signals)">
        | Signal                                                 | Alert behaviour    | What it tracks                                                                                                                                  |
        | ------------------------------------------------------ | ------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------- |
        | **Active Node Count**                                  | Merchant rule      | Description pending editorial review; the signal is live.                                                                                       |
        | **Avg Index Refresh Time (ms)**                        | Merchant rule      | indices.refresh.total\_time\_in\_millis / refresh.total. Climbing = segments stacking up.                                                       |
        | **Circuit Breaker Trips (24h)**                        | Merchant rule      | From breakers tripped count. Requests rejected to prevent OOM.                                                                                  |
        | **HTTP Connection Saturation %**                       | Alert band 70 / 90 | Description pending editorial review; the signal is live.                                                                                       |
        | **HTTP Connections In Use**                            | Watch only         | Description pending editorial review; the signal is live.                                                                                       |
        | **Initializing / Relocating Shards**                   | Merchant rule      | Description pending editorial review; the signal is live.                                                                                       |
        | **JVM Heap >85% Sustained or Circuit Breaker Tripped** | Merchant rule      | Alerts for JVM Heap >85% Sustained or Circuit Breaker Tripped.                                                                                  |
        | **Last Snapshot Age (hours)**                          | Alert band 24 / 72 | Last successful \_snapshot run from registered repository.                                                                                      |
        | **Pending Cluster Tasks**                              | Merchant rule      | From /\_cluster/pending\_tasks. High = master node overloaded with cluster-state updates.                                                       |
        | **Query Cache Hit Rate %**                             | Alert band 95 / 80 | Sum of indices.query\_cache.hit\_count / (hit\_count + miss\_count) across all nodes from /\_nodes/stats/indices - cumulative since node start. |
        | **Replica Sync Lag**                                   | Alert band 1 / 10  | Description pending editorial review; the signal is live.                                                                                       |
        | **Storage Usage %**                                    | Alert band 70 / 90 | Disk usage relative to flood-stage watermark (default 95%). Hitting marks indexes read-only.                                                    |
        | **Total Shards (primary + replica)**                   | Watch only         | Description pending editorial review; the signal is live.                                                                                       |
      </Accordion>

      <Accordion title="Protect revenue (6 signals)">
        | Signal                                         | Alert behaviour    | What it tracks                                                                                               |
        | ---------------------------------------------- | ------------------ | ------------------------------------------------------------------------------------------------------------ |
        | **Bulk Rejections (24h)**                      | Merchant rule      | thread\_pool.write.rejected. Indexing backpressure = client retry / data loss risk.                          |
        | **ES Product Index Doc Count vs Ecom Catalog** | Merchant rule      | Elasticsearch-distinctive XC , drift = product-sync to search broken; merchants miss SKUs in search results. |
        | **ES Search Pool Saturation vs Ecom Burst**    | Alert band 70 / 90 | ES Search Pool Saturation vs Ecom Burst, broken down by row.                                                 |
        | **Search QPS Spike vs Ecom Traffic**           | Merchant rule      | Description pending editorial review; the signal is live.                                                    |
        | **Slow Searches During Checkout Window (5m)**  | Merchant rule      | Slow Searches During Checkout Window (5m), broken down by row.                                               |
        | **Unassigned Shards**                          | Merchant rule      | From /\_cluster/health.unassigned\_shards. Any unassigned = data loss risk for that shard's replicas.        |
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="Audit (8)">
    ### Audit risks and opportunities

    A fix status appears only where the action, inputs, approval, verification and recovery controls are mapped. Candidate remediations are never executable. Open a check for the detail.

    <AccordionGroup>
      <Accordion title="Connection pool saturation above 90%">
        **Severity** critical · **Outcome** Customer experience · **Fix status** Report only

        At 90% of the connection pool in use, the database is close to refusing new connections outright. Once it does, every part of the application that needs a fresh database connection, including new customer sessions and checkout, starts failing, not just slowing down.

        Vortex IQ detects and explains this; resolution is manual, with evidence and recommended steps.

        Reference: `DB-CAP-001`
      </Accordion>

      <Accordion title="Disk usage above 90%">
        **Severity** critical · **Outcome** Run operations · **Fix status** Report only

        A database that runs out of disk stops accepting writes entirely, which for most stores means orders, inventory updates and customer records stop being saved, not just that the database gets slower. There is very little runway left at 90%.

        Vortex IQ detects and explains this; resolution is manual, with evidence and recommended steps.

        Reference: `DB-CAP-002`
      </Accordion>

      <Accordion title="Query error rate above 1% in last 5 minutes">
        **Severity** critical · **Outcome** Run operations · **Fix status** Report only

        More than 1 in 100 queries is failing right now. Depending on what those queries do, this can mean orders not saving, pages failing to load product or customer data, or background jobs silently dropping work, and a rate this high in a 5-minute window is an active incident, not background noise.

        Vortex IQ detects and explains this; resolution is manual, with evidence and recommended steps.

        Reference: `DB-ERR-001`
      </Accordion>

      <Accordion title="Last successful backup older than 72 hours">
        **Severity** high · **Outcome** Run operations · **Fix status** Report only

        If something goes wrong with this database right now, the most recent point it can be restored to is over 3 days old. Every order, customer record and inventory change since that backup would be unrecoverable in a real incident, not just delayed.

        Vortex IQ detects and explains this; resolution is manual, with evidence and recommended steps.

        Reference: `DB-BAK-001`
      </Accordion>

      <Accordion title="Replication lag above 10 seconds">
        **Severity** high · **Outcome** Run operations · **Fix status** Report only

        Anything reading from the replica, reports, dashboards, or read traffic split off the primary for capacity, is now up to 10+ seconds stale. If the primary fails while lag is this high, the replica is also that far behind on failover, which is a bigger problem than the staleness alone.

        Vortex IQ detects and explains this; resolution is manual, with evidence and recommended steps.

        Reference: `DB-REP-001`
      </Accordion>

      <Accordion title="Slow-query rate above 5% of total">
        **Severity** high · **Outcome** Customer experience · **Fix status** Report only

        More than 1 in 20 queries is landing in the slow bucket. That is frequent enough to be a pattern, not noise, and it means a meaningful share of every page load or job that touches this database is paying the slow-query cost, not just an unlucky occasional request.

        Vortex IQ detects and explains this; resolution is manual, with evidence and recommended steps.

        Reference: `DB-PERF-002`
      </Accordion>

      <Accordion title="p95 query latency above 200ms sustained 15m">
        **Severity** high · **Outcome** Customer experience · **Fix status** Report only

        One in twenty queries against this database is taking over 200ms, sustained for at least 15 minutes, not a brief spike. Any storefront page, checkout step or order sync that depends on this database inherits that slowness directly, and a sustained p95 this high is usually already visible to customer

        Vortex IQ detects and explains this; resolution is manual, with evidence and recommended steps.

        Reference: `DB-PERF-001`
      </Accordion>

      <Accordion title="Buffer / cache hit rate below 80%">
        **Severity** medium · **Outcome** Run operations · **Fix status** Report only

        More than 1 in 5 reads is missing the cache and going to disk instead, which is markedly slower. This shows up as everything the database does feeling incrementally heavier, rather than as one obvious failure.

        Vortex IQ detects and explains this; resolution is manual, with evidence and recommended steps.

        Reference: `DB-CACHE-001`
      </Accordion>
    </AccordionGroup>

    #### Build your own automated fixes

    Turn any finding into an automated fix with a Vortex IQ workflow: **over 13,000 read and write operations across more than 200 connectors** are available as building blocks, with approval, verification and rollback on every change.
  </Tab>

  <Tab title="Automate">
    ### Automate approved work

    Vortex IQ is integrated with **8 read** and **0 write** operations across catindices, catshards, clusterhealths, clusterpendingtasks, clusterstats, nodestats on Elasticsearch. Combine them with anything from the **over 13,000 operations across more than 200 connectors** to automate the work in your own words.

    Changes follow your configured approval policy: the target, proposed change, affected records, risk, reversibility and verification plan are shown before execution.

    [Create a workflow](https://app.vortexiq.ai/workbench/flows/create?connector=elasticsearch)

    #### Ready to build your first Elasticsearch workflow

    Pick a trigger, add the operations above as steps, and every step that changes data pauses for your approval. Monitoring and audits are live now and can start any workflow you build.

    <Accordion title="Browse the operations you can build with">
      | Resource            | Read operations | Write operations |
      | ------------------- | --------------- | ---------------- |
      | catindices          | 1               | 0                |
      | catshards           | 1               | 0                |
      | clusterhealths      | 1               | 0                |
      | clusterpendingtasks | 1               | 0                |
      | clusterstats        | 1               | 0                |
      | nodestats           | 1               | 0                |
      | nodestathttps       | 1               | 0                |
      | snapshotstatus      | 1               | 0                |

      Signed-in users see the full catalogue in the workflow builder, filtered to the sources they have connected.
    </Accordion>
  </Tab>
</Tabs>
