Faster Elasticsearch issue triage with redesigned AutoOps

AutoOps introduces clearer severity, updated page layouts, and simpler issue triage for Elastic Cloud Hosted deployments and Cloud Connect clusters.

Simplify your Elasticsearch operations with real-time issue detection and actionable recommendations to optimize performance and reduce costs. AutoOps is available for cloud and self-managed deployments. Learn more about AutoOps.

AutoOps has a redesigned experience for Elastic Cloud Hosted deployments and Cloud Connect clusters. The update adds a new Critical severity level and refreshes every page, including Template Optimizer, Nodes, Shards and Overview. Updated layouts and navigation make Elasticsearch issues easier to scan and triage. This post covers the redesigned UI and where AutoOps is headed next, including a headless, agentic experience.

Why AutoOps for Elasticsearch needs clearer prioritization

Running Elasticsearch at scale requires administrators to monitor cluster health, performance, capacity, and configuration at the same time. AutoOps now provides a clearer way to distinguish conditions that threaten cluster functionality from significant but less urgent degradation. The redesigned interface also follows familiar Elastic Cloud Console patterns, making active issues easier to find and investigate.

What changed in AutoOps: severity, navigation, configuration, and page design

The monitoring engine remains the same. The redesigned layout, navigation, and workflows now follow familiar Elastic patterns.

A clearer severity model

We added Critical as a new severity level for conditions that pose an immediate threat to cluster functionality and require urgent intervention. Several events previously classified as High are now Critical. Others are now Medium because they represent potential risk rather than active, significant degradation. The reclassified events are:

  • Promoted from High to Critical: Disk Watermark Flood Stage, Master Not Discovered, and Status Red.
  • Demoted from High to Medium: Disk Watermark Low Threshold, Disk Watermark Low, and Disk Watermark Configuration Incorrect.
SeverityWhat it means
CriticalImmediate threat to cluster functionality. Urgent intervention required.
HighSignificant degradation to usability, performance, or stability.
MediumPotential risk that can escalate if left unaddressed.
LowMinor anomalies with minimal operational impact.
InfoRoutine operational updates and configuration changes. No action required. (Coming in a near-future update).

Every severity level ships with an updated icon set and color palette. Levels are fixed so teams can build consistent runbooks and notification filters: route Critical and High events to PagerDuty or Slack, keep Medium and Low in the console for periodic review, and when Info arrives, use it for awareness without alert fatigue.

Deployment view: open events and history, side by side

The redesigned deployment view presents the existing Open events and Event history tabs in a clearer layout.

Event flyout: a clearer view of what matters

The event detail flyout is redesigned around action. High-severity events include a notification callout and an interactive badge that shows whether alerts are configured and links directly to setup. Recommendations collapse by default so the core event stays in focus. Settings live in the flyout menu; share is a separate icon in the header. The Dismiss action appears only when your role has the required admin permissions and the event is dismissible.

AutoOps overview: triage active events across your Elasticsearch fleet

The Overview page is reorganized around how operators scan an estate. Elasticsearch context sits directly under the page header, and active events appear as event ribbons below the deployments table. Each ribbon shows the latest active event in your selected time range; if the same event type is open on other deployments, a new badge lets you expand the view without opening each resource individually. Event search moved to the left for quicker filtering.

The “Events over time” chart moved off Overview to keep this page focused on fleet-level triage; open a single deployment when you need that timeline.

Nodes, Shards, and Indices are designed with easier navigation and information hierarchy

Nodes view now uses updated chart components and the Elastic UI color scheme, with clear expansion indicators on accordion sections. Event and instance lists that duplicated deployment-level views were removed to reduce noise.

Shards view improves node selection and groups view controls in the upper-right corner. A horizontal scrollbar supports wider layouts, and the time slider now uses native Elastic UI components. Node selection in Shards view now works across larger clusters and presents up to 100 nodes at a time.

Index view keeps the Indices table experience you already use, including sorting, time-range brushing, and chart zoom behavior tuned for meaningful ranges.

Template Optimizer

The Template Optimizer now provides a searchable list of templates ordered by the most recently identified recommendations. You can open each recommendation directly or expand the JSON panel to inspect the complete template.

Configure notifications and event settings

Notification settings now include connector search, clearer filters, and a simpler connector editing flow. Event settings moved from a popup to a flyout, matching the pattern used across AutoOps. Notification reports retain the same 10-day history window with minor layout updates, and dismiss events use updated confirmation components aligned with Elastic UI.

The deployment picker now shows deployment ID and real-time cluster status, with copy actions for deployment name and ID in the dropdown sub-menu. Node selection supports select-all, select-by-tier grouping, and clear master node indication. The date picker follows the same relative-range and custom-range model used in Kibana and other Cloud Console monitoring views.

AutoOps roadmap: API, MCP, CLI, and agentic experience

Looking ahead, we are building toward a headless, agentic AutoOps experience. A forthcoming public AutoOps API will make insights and raw metrics available outside the AutoOps interface. Administrators and agents will be able to query the API directly or store its data in Elasticsearch. The API will also provide the foundation for integrations with MCP, Elastic Agent Builder, the Elastic CLI, Kibana, and native AutoOps chat.

  • Hosted MCP server: Make AutoOps insights available to MCP clients such as Claude and Cursor.
  • Native Elastic Agent Builder tool: Use AutoOps insights in Elastic Agent Builder.
  • Elastic CLI support: Access the AutoOps API through the Elastic CLI.
  • AutoOps in Kibana: Surface relevant insights and metrics within Kibana.
  • Native AutoOps chat: Investigate cluster issues through an agentic chat experience within AutoOps UI in Elastic Cloud Console.

The application redesign is the foundation; these surfaces will meet operators where automation and AI already live. Read more about what is coming on the Elastic public roadmap.

How to start using the redesigned AutoOps in Elastic Cloud Console

Sign in to Elastic Cloud Console, open a deployment, project, or connected cluster, and select AutoOps from the navigation. Learn more in the AutoOps documentation.

The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all.

How helpful was this content?

Not helpful

Somewhat helpful

Very helpful

Related Content

Ready to build state of the art search experiences?

Sufficiently advanced search isn’t achieved with the efforts of one. Elasticsearch is powered by data scientists, ML ops, engineers, and many more who are just as passionate about search as you are. Let’s connect and work together to build the magical search experience that will get you the results you want.

Try it yourself