All skills
aws avatar

/amazon-opensearch-service

@04f39cf

Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration (Solr/ES/self-managed into AOS/AOSS, schema/query translation, sizing, cutover); provisioning (domain + AOSS lifecycle, upgrades, FGAC, monitoring); search (vector / semantic / hybrid / RAG with Bedrock); log-analytics (PPL, OSI, anomaly detection, Dashboards); trace-analytics (OTel spans, service maps, Data Prepper); ai-assistant (natural language data exploration, incident investigation, root cause analysis). Triggers on OpenSearch, AOS, AOSS, Elasticsearch, Solr, vector/k-NN/semantic/hybrid search, RAG, log analytics, PPL, trace analytics, ISM, FAISS, HNSW, Migration Assistant, UltraWarm, OR1, query my data, analyze logs, investigate errors, root cause analysis.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/amazon-opensearch-service

This session only. Nothing lands on disk.

referencestrace-analytics-troubleshooting.md

≈412 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Troubleshooting AOS Trace Analytics

Common Issues

Error Cause Fix
No trace data in otel-v1-apm-span-* Pipeline not running or misconfigured aws osis get-pipeline; check CloudWatch logs
traceId not found Trace hasn't been indexed yet or retention expired Verify time range; check ISM policy retention
PPL returns empty for OTel fields Field not indexed or wrong name Sample a doc first; OTel attributes are nested under attributes.*
Service map empty Service map processor not configured Verify OSI pipeline has index_type: trace-analytics-service-map sink
High latency on trace queries Large index, no time filter Always add time range: where startTime > DATE_SUB(NOW(), INTERVAL 1 HOUR)

Debugging Steps

No Traces Appearing

  1. Check OSI pipeline status: aws osis get-pipeline --pipeline-name <name>
  2. Check pipeline CloudWatch logs: /aws/vendedlogs/OpenSearchIngestion/<pipeline-name>/
  3. Verify ADOT collector is sending to correct endpoint
  4. Verify trace index exists: GET /_cat/indices/otel-v1-apm-span-*
  5. Check AOSS data access policy includes pipeline role

Incomplete Trace Trees

  1. Some spans may arrive late — add 1-2 minute buffer before querying
  2. If cross-service: verify all services export to the same pipeline
  3. Check parentSpanId field is populated in child spans

Application Signals Not Routing to AOS

  1. Verify X-Ray is receiving traces in the AWS console
  2. Confirm OSI pipeline source is configured for X-Ray format
  3. Check IAM role has xray:GetTraceSummaries and xray:BatchGetTraces permissions

Source: SKILL.md on GitHub

No alerts28d3 checks · Risk SAFE
  • Gen Agent Trust Hub28d

    This skill is a highly structured and security-conscious guide for managing Amazon OpenSearch Service and Serverless. It provides comprehensive instructions for migrations, provisioning, and analytics while strictly adhering to AWS security best practices, such as using SigV4 signing, IAM least-privilege, and AWS Secrets Manager for credential handling.

  • Socket28d

    No alerts

  • Snyk28d

    Risk: LOW · No issues

Signed by skilld at 04f39cf. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "version": "2"
}

README badge

README badge for aws/agent-toolkit-for-aws/amazon-opensearch-service