# Is there a slow log (or something similar) for shard refresh durations?

**URL:** <https://discuss.elastic.co/t/is-there-a-slow-log-or-something-similar-for-shard-refresh-durations/324188>\
**Category:** Elasticsearch\
**Created:** [January 30, 2023, 12:02am UTC](https://discuss.elastic.co/t/is-there-a-slow-log-or-something-similar-for-shard-refresh-durations/324188 "2023-01-30T00:02:07Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [January 30, 2023, 12:02am UTC](https://discuss.elastic.co/t/is-there-a-slow-log-or-something-similar-for-shard-refresh-durations/324188/1 "2023-01-30T00:02:07Z")

</div>

Hi All,

I'm attempting to debug a somewhat strange issue. Where I have a query which runs every 60 seconds to check a set of logs and if there are no logs for 90 seconds then trigger an alert (this is done via a Kibana rule).

These logs get generated (and in theory indexed) on a regular interval, every ~20 seconds, so the only time this alert should fire is when logs are not getting generated for some reason. However, I have had on a number of occasions now, false positive alerts where the rule thinks there are no logs, but if I check the logs they exist for the alerting window (I am looking at both the `@timestamp` and `event.ingested` times.

I have a hypothesis that these false positives happen because the Elasticsearch node which holds the index becomes overload (CPU maxed out) for a period of time and thus causes a shard refresh to take longer than expected, thus causing the query to not see the logs even though they technically exists. What I haven't found is a way to prove/disprove this hypothesis, as by the time I actually get to look at the logs in question they exist. Does anyone know if there is a way to have Elasticsearch log when a shard refresh takes longer than a specific duration? (Or have another idea for trying to debug this issue?)

For reference I'm using an Elastic Stack on 8.5.3

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2023, 12:02am UTC](https://discuss.elastic.co/t/is-there-a-slow-log-or-something-similar-for-shard-refresh-durations/324188/2 "2023-02-27T00:02:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
