Empty indices

Many shards or indices in the cluster contain no documents. Shard balancing counts shards per node, not how much data each shard holds, so empty shards spread like busy ones.

Note

For a complete list of insights, refer to AutoOps insights.

Field Value
Component Elasticsearch
Severity Medium
Scope Index
Domains performance, index-management, shard-allocation

You can customize these settings to adjust when AutoOps detects this event and presents the insight. Refer to AutoOps event settings for details.

The default customization settings are:

Setting Type Default
Exclude indices based on this pattern List of strings
Total empty indices threshold Integer 50

The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.

Empty indices: 12

Empty shards: 12

Sample empty indices: logs-prod-000045, logs-prod-000046

Note

AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.

The cluster shard balancer tries to give each data node the same number of shards. It does not weigh how much data each shard holds. Some nodes can end up with many active shards while others hold mostly empty ones. That uneven distribution can create hot spots where search and indexing concentrate on a subset of nodes.

Size your shards