Node observability APIs

Node observability APIs #

The /_node/_local/* surface exposes this node’s runtime state — recovery progress, build backlog, shard inventory, storage layout, slowlogs, logs and the trash. All of it is read-only except where noted, and every endpoint can be reached on a remote node through the unified forward: replace _local with the node id (/_node/<node_id>/...) — the console’s node pages are built on this.

Runtime knobs live on the sibling Node Settings page.

Node level #

EndpointWhat it reports
GET /_nodesThe cluster’s node inventory.
GET /_node/_localThis node’s identity, roles and reported addresses.
GET /_node/_local/stats (aliases /_nodes/stats, /_nodes/_local/stats)Node-level counters.
GET /_node/_local/recoveryShard recovery progress — restart WAL replay and peer pulls, including the queue behind node.recovery_concurrency. The cluster health timeout response points here.
GET /_node/_local/readyReadiness probe — answers once startup gates have passed.
GET /_node/_local/tasksThe unified task view — the single task surface: every maintenance lane (flush, epoch build, recovery, compaction), the batch job registries (flush_jobs[], compaction_jobs[]), the per-shard maintenance tables (build_tasks[], compaction_tasks[]) and engine task-loop health. POST /_node/_local/tasks/flush/<job_id>/cancel cancels a flush job, POST /_node/_local/tasks/compact/<job_id>/cancel a compaction job.
GET /_node/_local/memoryMemory usage summary.
GET /_node/_local/memory/profileA detailed memory profile breakdown.
GET /_node/_local/logsRecent node logs — the console’s log viewer.

Shards #

EndpointWhat it reports
GET /_node/_local/shardsEvery shard copy this node holds, with state, role, and per-shard counters — including reshard_purged (documents purged as superseded by a committed reshard).
GET /_node/_local/shards/metricsPer-shard serving metrics (search lanes, queueing).
GET /_node/_local/shards/<shard_id>/<allocation_id>/filesThe shard’s on-disk files.
GET /_node/_local/shards/<shard_id>/<allocation_id>/storageThe shard’s FIRE storage layout — segments with per-file and per-field costs; feeds the console’s storage explorer.
GET /_node/_local/shards/<shard_id>/<allocation_id>/epochsThe shard’s epoch ledger (frozen, building, built).
GET /_node/_local/shards/<shard_id>/<allocation_id>/wal/<epoch_id>[/<seq>]WAL inspection: an epoch’s entries, or a single entry by sequence number — the crash-forensics view.
GET /_node/_local/storageNode-wide storage usage summary.

Shard maintenance actions #

EndpointEffect
POST /_node/_local/shards/<shard_id>/<allocation_id>/compactRun one synchronous compaction pass on this shard copy — the single-shard form; returns when the pass lands.
POST /_node/_local/shards/<shard_id>/<allocation_id>/compact/cancelCancel that copy’s manual compaction: parked passes are drained, a running merge unwinds cooperatively.
POST /_node/_local/shards/compact_all[?collection=]Batch form over every local started primary — queues a cancellable job (see /tasks); the node-local form behind the collection-wide _compact.
POST /_node/_local/shards/<shard_id>/<allocation_id>/epoch/rollFreeze the shard’s active epoch now (starts a segment build).
POST /_node/_local/shards/<shard_id>/<allocation_id>/epoch/flushRoll the active epoch and build every frozen epoch, then purge the covered WAL.
POST /_node/_local/shards/flush_allBatch form of epoch flush across all local shards — runs as a cancellable task (see /tasks).
POST /_node/_local/shards/<shard_id>/<allocation_id>/doc/<doc_id>/_fieldsApply an inplace fast-lane field update directly on this shard (internal fast-lane form).

Search observability #

EndpointWhat it reports
GET /_node/_local/search_slowlogSearches slower than node.search.slow_threshold_ms, captured with their full DSL.
GET /_node/_local/search_auditThe search audit trail (failed/slow/bad requests); DELETE on the same path clears it.

Trash #

Deleted namespaces and collections (and replaced shards) are moved into <data>/trash/ and purged after trash.retention_secs (default 1 day) — see Backup and restore. These node-local APIs manage that window for THIS node; the cluster-wide, namespace-centric view lives under the Trash APIs (GET /_cluster/trash aggregates every node server-side):

EndpointEffect
GET /_node/_local/trashList trashed items with age, size and snapshot summary (kind/namespace/restorable).
GET /_node/_local/trash/<item>/verifyRead-only shard-completeness check of this node’s copy (?deep=true also parses every segment file’s footer).
POST /_node/_local/trash/<item>/restoreRestore a trashed collection — or a whole deleted namespace — cluster-coordinated, gated by the verification above.
POST /_node/_local/trash/<item>/prepareStage a trashed item for inspection.
GET /_node/_local/trash/<item>/snapshotSnapshot view of a trashed item’s metadata.
DELETE /_node/_local/trash/<item>Physically delete one trashed item now.
POST /_node/_local/trash/<item>/delete_everywhereDelete one item on every node’s trash.
POST /_node/_local/trash/empty_everywhereEmpty the trash on every node.
Calendar September 29, 2026
Edit Edit this page