OpenSearch Service domains with no searches, no indexing and under 5% CPU for 30 days
What does ZopNight detect here?
ZopNight flags an Amazon OpenSearch Service domain when `SearchRate` and `IndexingRate` both stay under 0.10 per minute and `CPUUtilization` stays under 5%, on average and at peak, across 30 days of data. Instance hours and EBS storage bill regardless of use, so the saving is the domain's full monthly cost.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-104 |
| Category | idle |
| Severity | medium |
| Metric | SearchRate, IndexingRate, CPUUtilization |
| Threshold | under 0.10 per minute and under 5% CPU |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | es:ListDomainNames · es:DescribeDomain · cloudwatch:GetMetricStatistics |
Where it applies
A domain costs the same whether or not anyone queries it
A provisioned OpenSearch Service domain is a cluster of instances, each with its own EBS storage. OpenSearch Service pricing lists on-demand and reserved instance pricing for these clusters, and the instances and volumes bill for as long as the domain exists. Dedicated master nodes and UltraWarm nodes add to the same total.
Domains are often created per project or per environment and outlive both. They look healthy in the console, which is why they are rarely deleted.
Reading the three activity metrics
The OpenSearch CloudWatch metrics page
defines SearchRate as search requests per minute across all shards on a data node and
IndexingRate as indexing operations per minute. Both are per-minute figures, which matters when
you set a floor:
aws opensearch list-domain-names --engine-type OpenSearch
aws cloudwatch get-metric-statistics \ --namespace AWS/ES --metric-name SearchRate \ --dimensions Name=DomainName,Value=my-domain Name=ClientId,Value=111122223333 \ --start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics MaximumRepeat for IndexingRate and CPUUtilization.
Search, indexing and CPU all have to agree
Each of the three series must be present and cover at least 30 days. SearchRate and
IndexingRate must both read under 0.10 per minute on average and at peak, a bound tight enough to
mean fewer than six requests an hour. CPUUtilization must stay under 5% on average and at peak,
which rules out domains doing background work such as merges or scheduled jobs. The domain also
needs a priced monthly cost.
Evidence gaps mean no finding
A domain missing any one of the three series, or with less than 30 days of any of them, is not flagged. A reading above any floor ends it. A domain with no price is skipped rather than shown with a $0 saving. OpenSearch Serverless collections are a different resource and are not covered here.
What deleting the domain saves
saving = instance hours x node count + EBS storage, per monthcost after fix = 0Snapshot, then delete or shrink
- Confirm with the owning team that no application, dashboard or ingestion pipeline uses the domain endpoint.
- Take a manual snapshot to an S3 repository; the snapshot guide notes that manual snapshots are the ones meant for moving data between clusters.
- Delete with
aws opensearch delete-domain --domain-name my-domain, or reduce the instance type and count if some use remains.