Skip to main content
idle · aws

OpenSearch Service domains with no searches, no indexing and under 5% CPU for 30 days

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Amazon OpenSearch Service domain when `SearchRate` and `IndexingRate` both stay under 0.10 per minute and `CPUUtilization` stays under 5%, on average and at peak, across 30 days of data. Instance hours and EBS storage bill regardless of use, so the saving is the domain's full monthly cost.

Signal and threshold

How ZopNight evaluates OpenSearch Service domains with no searches, no indexing and under 5% CPU for 30 days.
Field Value
Rule IDsRC-104
Categoryidle
Severitymedium
MetricSearchRate, IndexingRate, CPUUtilization
Thresholdunder 0.10 per minute and under 5% CPU
Evaluation window30d
SourceZopNight
Permissions usedes:ListDomainNames · es:DescribeDomain · cloudwatch:GetMetricStatistics

A domain costs the same whether or not anyone queries it

A provisioned OpenSearch Service domain is a cluster of instances, each with its own EBS storage. OpenSearch Service pricing lists on-demand and reserved instance pricing for these clusters, and the instances and volumes bill for as long as the domain exists. Dedicated master nodes and UltraWarm nodes add to the same total.

Domains are often created per project or per environment and outlive both. They look healthy in the console, which is why they are rarely deleted.

Reading the three activity metrics

The OpenSearch CloudWatch metrics page defines SearchRate as search requests per minute across all shards on a data node and IndexingRate as indexing operations per minute. Both are per-minute figures, which matters when you set a floor:

Terminal window
aws opensearch list-domain-names --engine-type OpenSearch
aws cloudwatch get-metric-statistics \
--namespace AWS/ES --metric-name SearchRate \
--dimensions Name=DomainName,Value=my-domain Name=ClientId,Value=111122223333 \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Maximum

Repeat for IndexingRate and CPUUtilization.

Search, indexing and CPU all have to agree

Each of the three series must be present and cover at least 30 days. SearchRate and IndexingRate must both read under 0.10 per minute on average and at peak, a bound tight enough to mean fewer than six requests an hour. CPUUtilization must stay under 5% on average and at peak, which rules out domains doing background work such as merges or scheduled jobs. The domain also needs a priced monthly cost.

Evidence gaps mean no finding

A domain missing any one of the three series, or with less than 30 days of any of them, is not flagged. A reading above any floor ends it. A domain with no price is skipped rather than shown with a $0 saving. OpenSearch Serverless collections are a different resource and are not covered here.

What deleting the domain saves

Terminal window
saving = instance hours x node count + EBS storage, per month
cost after fix = 0

Snapshot, then delete or shrink

  1. Confirm with the owning team that no application, dashboard or ingestion pipeline uses the domain endpoint.
  2. Take a manual snapshot to an S3 repository; the snapshot guide notes that manual snapshots are the ones meant for moving data between clusters.
  3. Delete with aws opensearch delete-domain --domain-name my-domain, or reduce the instance type and count if some use remains.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·