All skills
aws avatar

/amazon-opensearch-service

@04f39cf

Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration (Solr/ES/self-managed into AOS/AOSS, schema/query translation, sizing, cutover); provisioning (domain + AOSS lifecycle, upgrades, FGAC, monitoring); search (vector / semantic / hybrid / RAG with Bedrock); log-analytics (PPL, OSI, anomaly detection, Dashboards); trace-analytics (OTel spans, service maps, Data Prepper); ai-assistant (natural language data exploration, incident investigation, root cause analysis). Triggers on OpenSearch, AOS, AOSS, Elasticsearch, Solr, vector/k-NN/semantic/hybrid search, RAG, log analytics, PPL, trace analytics, ISM, FAISS, HNSW, Migration Assistant, UltraWarm, OR1, query my data, analyze logs, investigate errors, root cause analysis.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/amazon-opensearch-service

This session only. Nothing lands on disk.

referencessearch-troubleshooting.md

≈496 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Troubleshooting AOS Search

Common Issues

Error Cause Fix
AccessDeniedException on connector creation Missing IAM permissions Verify role has es:ESHttpPost and data access policy grants ML actions
Model deployment stuck in DEPLOYING Resource limits Check GET /_plugins/_ml/models/<id> status; may need to undeploy unused models
ConnectorAccessControlDisabledException ML access control not enabled Enable via PUT /_cluster/settings {"persistent": {"plugins.ml_commons.connector_access_control_enabled": true}}
k-NN search returns 0 results Index not refreshed or wrong dimension Verify embedding dimension matches index mapping; force refresh with POST /index/_refresh
403 on AOSS collection Data access policy missing Create/update data access policy to include the IAM principal
Bedrock throttling (429) Rate limit exceeded Implement exponential backoff; request quota increase via Service Quotas

Debugging Steps

Connector Not Returning Embeddings

  1. Verify Bedrock model access: aws bedrock list-foundation-models --region <region>
  2. Test connector: POST /_plugins/_ml/models/<model_id>/_predict {"parameters": {"inputText": "test"}}
  3. Check connector role can invoke Bedrock: aws iam simulate-principal-policy --policy-source-arn <role-arn> --action-names bedrock:InvokeModel

AOSS Authentication Failures

  1. Verify SigV4 credentials: aws sts get-caller-identity
  2. Check data access policy includes your IAM principal for the collection
  3. Verify network policy allows access from your IP/VPC
  4. Ensure collection type matches workload (VECTORSEARCH for k-NN)

Ingest Pipeline Failures

  1. Check pipeline exists: GET /_ingest/pipeline/my-pipeline
  2. Simulate: POST /_ingest/pipeline/my-pipeline/_simulate {"docs": [{"_source": {"text": "test"}}]}
  3. If model timeout: check model is deployed and healthy via GET /_plugins/_ml/models/<id>

Source: SKILL.md on GitHub

No alerts28d3 checks · Risk SAFE
  • Gen Agent Trust Hub28d

    This skill is a highly structured and security-conscious guide for managing Amazon OpenSearch Service and Serverless. It provides comprehensive instructions for migrations, provisioning, and analytics while strictly adhering to AWS security best practices, such as using SigV4 signing, IAM least-privilege, and AWS Secrets Manager for credential handling.

  • Socket28d

    No alerts

  • Snyk28d

    Risk: LOW · No issues

Signed by skilld at 04f39cf. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "version": "2"
}

README badge

README badge for aws/agent-toolkit-for-aws/amazon-opensearch-service