SkillVaultskills Browse all 1,000+ skills

Debugging · Version 1.1.0 · Reviewed 2026-08-02

Elasticsearch Production Debug Specialist

Diagnose elasticsearch production incident triage and elasticsearch root-cause isolation with evidence, explicit trade-offs, and a verification plan.

4 method steps 4 documented failure modes 4 diagnostic checks 7 quality gates

Diagnoses production failures from runtime evidence instead of symptom matching in Elasticsearch using mappings, analyzers, query DSL, shard layout, and lifecycle policy and query profiles, segment counts, heap pressure, and shard allocation, with explicit attention to mapping explosion or oversharding exhausting heap and coordination capacity.

₹199 one-time

Get this skill archive

Install in your AI coding tool

SkillVault packages this skill in the open Agent Skills format for five leading coding tools.

What this skill helps you do

  • Elasticsearch production incident triage
  • Elasticsearch root-cause isolation
  • Elasticsearch fix verification

How Elasticsearch Production Debug Specialist works

You provide

Symptoms, timestamps, recent changes, and logs

It inspects

Correlated subset and first failing component for elasticsearch production incident triage

It decides

A ranked cause for elasticsearch root-cause isolation that explains recovery too

You verify

The cheapest discriminating test, run before the fix

What it checks first

Elasticsearch Production Debug Specialist diagnoses production failures from runtime evidence instead of symptom matching in Elasticsearch using mappings, analyzers, query DSL, shard layout, and lifecycle policy and query profiles, segment counts, heap pressure, and shard allocation, with explicit attention to mapping explosion or oversharding exhausting heap and coordination capacity. Use it when the work involves Elasticsearch production incident triage, Elasticsearch root-cause isolation, Elasticsearch fix verification.

  1. The precise first failure time and whether it is a step change or gradual degradation.
  2. What changed within the preceding window: deploy, config, flag, traffic shape, or data.
  3. Whether the failure is universal or correlated with a subset (region, tenant, version, device).
  4. Whether the error is deterministic on retry, which separates a logic defect from a timing or capacity defect.

Failure modes it recognizes

  • A symptom appearing in a component that merely shares a resource with the failing one.
  • An error message describing the last effect rather than the original cause.
  • A latent bug activated by a data value that first appeared in production traffic.
  • A retry layer masking an underlying failure until it saturates and fails loudly.

Answers it will reject

  • Accepting the first plausible hypothesis without testing an alternative that would falsify it.
  • Changing several variables at once, making the recovery unattributable.
  • Trusting a log timestamp without confirming clock alignment across hosts.

Decision rules it applies

  • A valid explanation must account for onset, all symptoms, the affected subset, and the recovery.
  • Choose the test that eliminates the most hypotheses per unit of effort.
  • If nothing in the system changed, examine the inputs.

Evidence it asks for

  • Reconstruct a timestamped timeline from artifacts, not memory.
  • Break metrics down by dimension to isolate the correlated subset.
  • Reproduce in a controlled environment before attempting a fix.

The method inside

  1. Reconstruct the symptom timeline and define what healthy behavior would look like for elasticsearch production incident triage.
  2. Rank hypotheses for elasticsearch root-cause isolation by evidence, blast radius, and ability to explain every observed symptom.
  3. Run the cheapest discriminating check for elasticsearch fix verification; update confidence only when evidence changes.
  4. Separate immediate stabilization, confirmed cause, contributing conditions, and prevention; finish with a reproducible verification.

Deliverables

  • Elasticsearch production incident triage assessment
  • Elasticsearch root-cause isolation decision and action plan
  • Elasticsearch fix verification verification checklist

Evidence requirements

  • Exact symptoms and timestamps
  • Reproduction conditions and recent changes
  • Logs, traces, metrics, code, or configuration

Quality gates

  • Every material claim traces to supplied evidence or is labeled as a hypothesis.
  • The response follows the declared deliverable contract.
  • No execution, access, measurement, or verification is invented.
  • Secrets and personal data are redacted rather than repeated.
  • The user receives a concrete independent verification step.
  • The relevant failure modes in this domain were considered rather than only the reported symptom.
  • No listed anti-pattern was recommended as a solution.

Example task

Input

Apply the production debug specialist to our Elasticsearch system before the next production change. We can provide mappings, analyzers, query DSL, shard layout, and lifecycle policy; the main concern is mapping explosion or oversharding exhausting heap and coordination capacity.

Expected output

Start with query profiles, segment counts, heap pressure, and shard allocation and split the affected population before changing configuration. The leading hypothesis is mapping explosion or oversharding exhausting heap and coordination capacity. Run the smallest test that distinguishes that mechanism from dependency failure, preserve the evidence, and verify recovery against the original symptom.

Boundaries and compatibility

Ideal for

  • Elasticsearch production incident triage: produce a decision or artifact grounded in supplied evidence.
  • Elasticsearch root-cause isolation: produce a decision or artifact grounded in supplied evidence.
  • Elasticsearch fix verification: produce a decision or artifact grounded in supplied evidence.

Out of scope

  • Guessing a root cause from a symptom alone
  • Claiming a fix worked without test evidence

Agent compatibility

  • GitHub Copilot Agent Skills
  • Cursor Agent Skills
  • Claude Code Skills
  • OpenAI Codex Skills
  • JetBrains Junie Skills

Tool policy: Advisory by default. No tools are assumed. If the host provides tools, use read-only evidence gathering unless the user explicitly approves a scoped write or execution action.