All skills
aws avatar

/amazon-opensearch-service

@04f39cf

Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration (Solr/ES/self-managed into AOS/AOSS, schema/query translation, sizing, cutover); provisioning (domain + AOSS lifecycle, upgrades, FGAC, monitoring); search (vector / semantic / hybrid / RAG with Bedrock); log-analytics (PPL, OSI, anomaly detection, Dashboards); trace-analytics (OTel spans, service maps, Data Prepper); ai-assistant (natural language data exploration, incident investigation, root cause analysis). Triggers on OpenSearch, AOS, AOSS, Elasticsearch, Solr, vector/k-NN/semantic/hybrid search, RAG, log analytics, PPL, trace analytics, ISM, FAISS, HNSW, Migration Assistant, UltraWarm, OR1, query my data, analyze logs, investigate errors, root cause analysis.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/amazon-opensearch-service

This session only. Nothing lands on disk.

referenceslog-analytics-troubleshooting.md

≈404 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Troubleshooting AOS Log Analytics

Common Issues

Error Cause Fix
403 Forbidden on PPL query Missing data access policy or FGAC role Add IAM principal to data access policy; for AOS, map IAM role in Dashboards
index_not_found_exception Wrong index pattern or no data ingested List indices with GET /_cat/indices; verify OSI pipeline is running
PPL syntax error Unquoted dotted field name Backtick-quote: `log.level` not log.level
OSI pipeline STOPPED Role permission issue or sink unreachable Check pipeline logs in CloudWatch; verify role trust policy
SearchPhaseExecutionException Query too broad, OOM Add head 1000 to limit results; narrow time range with where
Subscription filter not delivering Wrong destination ARN or permission Verify pipeline ARN format and logs:PutSubscriptionFilter permission

Debugging OSI Pipelines

  1. Check pipeline status: aws osis get-pipeline --pipeline-name <name>
  2. Check CloudWatch Logs for pipeline errors: /aws/vendedlogs/OpenSearchIngestion/<pipeline-name>/
  3. Verify source role can read CloudWatch: aws iam simulate-principal-policy --action-names logs:GetLogEvents
  4. Verify sink role can write to AOS: test with curl -XPOST using SigV4

Debugging PPL Queries

  1. Start simple: source = <index> | head 5 — verify access
  2. Check field names: GET /<index>/_mapping — confirm exact field paths
  3. Narrow time range first, then add filters
  4. If patterns returns nothing: ensure there are enough documents (needs ≥10 for pattern detection)

Source: SKILL.md on GitHub

No alerts28d3 checks · Risk SAFE
  • Gen Agent Trust Hub28d

    This skill is a highly structured and security-conscious guide for managing Amazon OpenSearch Service and Serverless. It provides comprehensive instructions for migrations, provisioning, and analytics while strictly adhering to AWS security best practices, such as using SigV4 signing, IAM least-privilege, and AWS Secrets Manager for credential handling.

  • Socket28d

    No alerts

  • Snyk28d

    Risk: LOW · No issues

Signed by skilld at 04f39cf. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "version": "2"
}

README badge

README badge for aws/agent-toolkit-for-aws/amazon-opensearch-service