src/health/guides/elasticsearch/elasticsearch_cluster_health_status_red.md
This alert is triggered when the Elasticsearch cluster health status turns RED. If you receive this alert, it means that there is a problem that needs immediate attention, such as data loss or one or more primary and replica shards are not allocated to the cluster.
Elasticsearch cluster health status provides an indication of the cluster's overall health, based on the state of its shards. The status can be green, yellow, or red:
Green: All primary and replica shards are allocated.Yellow: All primary shards are allocated, but some replica shards are not.Red: One or more primary shards are not allocated, leading to data loss._cat API:curl -XGET 'http://localhost:9200/_cat/health?v'
Examine the output to understand the current health status, the number of nodes and shards, and any unassigned shards.
_cat/shards API:curl -XGET 'http://localhost:9200/_cat/shards?v'
Look for shards with the status UNASSIGNED.
Identify the root cause of the issue, such as:
Take appropriate action based on the root cause:
Monitor the health status as the cluster recovers:
curl -XGET 'http://localhost:9200/_cat/health?v'
If the health status turns YELLOW or GREEN, the cluster is no longer in the RED state.