Dear All,
We are using AutoOps for our on-prem cluster for about 5 months now (we connect AutoOps as soon as we heard of it at the end of october).
After the first few hickups trying to install it, the installation was smooth and we already had a few situations that AutoOps saved us. For that alone, a big thank you from us! ![]()
That being said, I think there is plenty of improvement (or maybe I am just not using AutoOps correctly) so here is my personal wishlist for the future.
Attention: This list is long - you have been warned...
Recommendations
While I know that the recommendations cannot fit all situations, I think that some recommendations shouldn't be made:
- Events recommend that we should optimize system templates, e.g.
Template .siem-signals-default can be optimized Many shards in the cluster are emptyrecommends to delete indexes - even if they are the active write index for an aliasSome data nodes do not contain any shardsrecommends to enable shard allocation - even if the affected node is a frozen node
Handling multiple Clusters
Either the documentation for on-prem clusters could use some improvement or the UI:
We connected 2 clusters (our current production and our future production system) to AutoOps and now see both under "Connected Clusters":
But in the AutoOps UI, we only see a single cluster and we always need to change the page to switch between clusters:
Is it expected that I only see a single cluster here? Should I have onboarded the clusters differently?
Template Optimizer Overview
- troublesome template selection
It is fine if I use an Alert-Link to switch to the Template Optimizer, but when going directly to the UI the template selection is difficult:
- I cannot just select the template name, I need to expand it and select one of the dates below. Improvement: allow selecting just the template name and just use the latest date in this case
- it is unclear what the date means: last seen? created? last changed?
- when a template is selected, the template selection field doesn't show the name - it shows the date

- It's hard to get a list of templates to optimize
- The Cluster->Open Events only shows 5 templates at a time and i have to load the next 5 templates X times
- The Template Optimizer shows all templates, but I don't see which can be optimized and which are already in a good state
Shard Overview
- In the Shards Overview, the low values while the high values are dark. This causes a readability problem because the contrast is not that good:

- It would be a great addition to also show the phase for each index shown (or even allow filtering?). This could be used for questions like:
- if the index is still in warm phase but has a low search rate - maybe we could move it to frozen earlier?
- if the index is in frozen but has a high search rate - maybe we should keep it in warm for longer?
- Allow to search a timespan instead of a single second
Right now, the shards seem to show a snapshot of a single second? This doesn't make sense to me, as this could wildly change every second.
Instead, I would like to be able to select a timeframe and then get the average values for it.
Nodes Overview
- The UI doesn't really make it clear that I can click the titles to expand them. I thought at first that they are empty:
Instead, you could use the same logic as for the events to show that the user can expand/collapse an entry:
Best regards
Wolfram





