Amazon Opensearch Service
aws/agent-toolkit-for-aws
Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…
Amazon OpenSearch Service domain health assessment. An agent skill from aws/tools-for-devops-agent.
$ npx skills add aws/tools-for-devops-agent --skill analytics-opensearch-expertise -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/tools-for-devops-agent analytics-opensearch-expertise --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analytics-opensearch-expertise .claude/skills/analytics-opensearch-expertise && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "analytics-opensearch-expertise" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/analytics-opensearch-expertise into .claude/skills/analytics-opensearch-expertise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analytics-opensearch-expertise", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/tools-for-devops-agent/tree/main/skills/analytics-opensearch-expertiseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/tools-for-devops-agent --skill analytics-opensearch-expertise -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/tools-for-devops-agent analytics-opensearch-expertise --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/analytics-opensearch-expertise .agents/skills/analytics-opensearch-expertise && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "analytics-opensearch-expertise" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/analytics-opensearch-expertise into .agents/skills/analytics-opensearch-expertise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analytics-opensearch-expertise", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill analytics-opensearch-expertise -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/tools-for-devops-agent analytics-opensearch-expertise --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/analytics-opensearch-expertise .cursor/skills/analytics-opensearch-expertise && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "analytics-opensearch-expertise" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/analytics-opensearch-expertise into .cursor/skills/analytics-opensearch-expertise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analytics-opensearch-expertise", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/tools-for-devops-agent.git --path skills/analytics-opensearch-expertise--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/tools-for-devops-agent --skill analytics-opensearch-expertise -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/tools-for-devops-agent analytics-opensearch-expertise --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/analytics-opensearch-expertise .gemini/skills/analytics-opensearch-expertise && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "analytics-opensearch-expertise" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/analytics-opensearch-expertise into .gemini/skills/analytics-opensearch-expertise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analytics-opensearch-expertise", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/tools-for-devops-agent analytics-opensearch-expertiseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/tools-for-devops-agent --skill analytics-opensearch-expertise -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/analytics-opensearch-expertise .github/skills/analytics-opensearch-expertise && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "analytics-opensearch-expertise" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/analytics-opensearch-expertise into .github/skills/analytics-opensearch-expertise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analytics-opensearch-expertise", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill analytics-opensearch-expertise -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/tools-for-devops-agent analytics-opensearch-expertise --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/analytics-opensearch-expertise .opencode/skills/analytics-opensearch-expertise && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "analytics-opensearch-expertise" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/analytics-opensearch-expertise into .opencode/skills/analytics-opensearch-expertise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analytics-opensearch-expertise", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
analytics-opensearch-expertiseAmazon OpenSearch Service domain health assessment. An agent skill from aws/tools-for-devops-agent.
Analytics Opensearch Expertise is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Amazon OpenSearch Service domain health assessment. Performs read-only, API-driven checks against a customer's OpenSearch domain(s) covering cluster health, node/shard configuration, performance metrics, security posture, and cost optimization signals. Activate this skill for requests about OpenSearch or Elasticsearch domain health, cluster review, domain assessment, performance, security posture, or cost optimization. Given a domain ARN (or name + region), it produces a structured findings report with…
Its SKILL.md is about 6.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including reference files (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).
It sits in DevOps & Cloud, covering Search implementation and OKRs and executive reporting. It works with OpenSearch, Amazon Web Services and Elasticsearch. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.aws.amazon.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Analytics Opensearch Expertise loads about 6.9k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 186 tokens; SKILL.md has 3,091 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 3,091 words, ~6,931 tokens.
.claude/skills/analytics-opensearch-expertise/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.This skill performs a comprehensive, read-only health assessment of Amazon OpenSearch Service domains using AWS APIs available through the customer's local AWS profile. It produces a structured report with findings and actionable recommendations.
Scope: CLI-agent compatible. No external packages, no IDE workspace, no human review gates.
opensearch, opensearch health, domain health, cluster review, opensearch review, opensearch assessment, opensearch check, open search, opensearch performance, opensearch security, opensearch cost
es:DescribeDomaines:DescribeDomainHealthes:GetCompatibleVersionses:DescribeReservedInstanceses:ListDomainNamescloudwatch:GetMetricDataRequired: Domain ARN (e.g., arn:aws:es:us-west-2:123456789012:domain/my-domain)
Parse the ARN to extract:
us-west-2)123456789012)domain/ in field 6Fallback / Target Resolution (apply these rules exactly — never silently substitute a target):
DescribeDomain → proceed with the assessment.ListDomainNames in the user's likely region(s) (cross-region scan if needed) and present the discovered domains as options for the user to choose. Do not pick one yourself unless exactly one domain exists in the entire account — state that you did so.ListDomainNames in the ARN's region, then other regions). Then STOP and confirm — do NOT assess:prod-es-content / prod-es-users), a silently substituted target produces a confident report about the wrong domain, which is worse than an error.1. Parse domain ARN → region, account, domain name
2. Resolve the target (Target Resolution rules above) — confirm with the user if not an exact match
3. Describe domain configuration (DescribeDomain)
4. Describe domain health (DescribeDomainHealth)
5. Pull CloudWatch metrics (last 24h)
6. Check upgrade eligibility (GetCompatibleVersions; ListVersions fallback)
7. Check reserved instance coverage (DescribeReservedInstances)
8. Analyze findings against thresholds
9. Load the Remediation Reference — read_skill_resource(skill_id='analytics-opensearch-expertise',
path='references/remediation-reference.md') — MANDATORY before writing recommendations
10. Generate report with recommendationsThe DevOps Agent AWS tool exposes the LEGACY Elasticsearch-compatible client. Call legacy operation names FIRST; fall back to the modern names only if the legacy call fails:
| Purpose | Try first (legacy) | Modern equivalent |
|---|---|---|
| Domain config | describe_elasticsearch_domain | describe_domain |
| Version catalog | list_elasticsearch_versions | list_versions |
| Upgrade targets | get_compatible_elasticsearch_versions | get_compatible_versions |
| Reserved instances | describe_reserved_elasticsearch_instances | describe_reserved_instances |
es:Describe* and es:List* —
Describe/List operations succeed under either naming; Get* actions (BOTH GetCompatible
variants) are typically denied. This is exactly why the 1.4 ListVersions fallback exists.DescribeDomainHealth has NO legacy equivalent. If it fails, do NOT skip checks 2.2/2.3 —
use CloudWatch instead: Shards.active (Maximum) = active shards, Shards.unassigned
(Maximum) = unassigned, TotalShards ≈ active + unassigned; ClusterStatus.green/yellow/red
for 1.1/3.7. Never report the checks as SKIPPED when this fallback is available.AWS/ES, dimensions DomainName and
ClientId (the account ID).DescribeDomainHealthClusterHealth (green | yellow | red)DescribeDomain → ClusterConfigInstanceCount, ZoneAwarenessEnabled, AvailabilityZoneCountZoneAwarenessEnabled == true:InstanceCount % AvailabilityZoneCount != 0 → ⚠️ "Data node count ({count}) is not a multiple of AZ count ({az_count}). This causes uneven shard distribution across AZs, reducing fault tolerance."ZoneAwarenessEnabled == false and InstanceCount > 1:DescribeDomain → ClusterConfigDedicatedMasterEnabled, DedicatedMasterType, DedicatedMasterCountDedicatedMasterEnabled == false AND InstanceCount >= 3 → ⚠️ "No dedicated master nodes. Clusters with 3+ data nodes should use dedicated masters for stability."DedicatedMasterCount == 2 → ⚠️ "Even number of master nodes ({count}) risks split-brain. Use 3 dedicated master nodes."DedicatedMasterCount < 3 → ⚠️ "Fewer than 3 master nodes reduces fault tolerance."GetCompatibleVersions with DomainNameGetCompatibleVersions returns AccessDeniedException — do NOT skip):
call ListVersions and derive upgrade candidates using these two rules:ListVersions with the SAME major version as the
domain and a LATER minor version (e.g., a 2.11 domain → every later 2.x in the region).ListVersions; never hard-code a specific version number).
Label fallback results as "derived upgrade candidates (ListVersions + documented upgrade-path
rules)" and cite https://docs.aws.amazon.com/opensearch-service/latest/developerguide/version-migration.html
for the reader. Only mark 1.4 SKIPPED if BOTH APIs are denied.
Note placement: the fallback provenance note belongs INSIDE the 1.4 finding ONLY — do NOT
surface it in the Executive Summary or any report-level note box, and do NOT name API errors
(e.g., AccessDeniedException) anywhere in the report. Phrase it customer-friendly: "Upgrade
candidates were derived from the available version listings and are not API-confirmed — verify
eligible target versions in the console before planning an upgrade."
Render candidates as a SET of direct single-hop targets (comma-separated) — NEVER as an arrow chain (NOT "2.13 → 2.15 → 2.19"): every listed same-major version is directly reachable in ONE hop. Any upgrade recommendation MUST propose a single hop to the latest same-major version (plus one more hop for a major jump). Do NOT invent sequential multi-hop plans or per-hop time estimates.ListVersions/GetCompatibleVersions (e.g., 2.11 with {2.13, 2.15, 2.17, 2.19} available = 4 releases behind) — NEVER the numeric delta between version numbers (2.19 − 2.11 is NOT "8 versions behind").DescribeDomain → EBSOptionsVolumeType, VolumeSize, Iops, ThroughputVolumeType == "gp2" → ⚠️ "Using gp2 volumes. gp3 offers better price/performance with configurable IOPS and throughput."VolumeSize × InstanceCountIopsThrottle, ThroughputThrottle, ReadIOPSMicroBursting, WriteIOPSMicroBursting, ReadThroughputMicroBursting, WriteThroughputMicroBursting (Maximum statistic, last 7 days)IopsThrottle Max > 0 OR ThroughputThrottle Max > 0 in the window → ⚠️ "EBS IOPS/throughput throttling detected. Increase provisioned Iops/Throughput on gp3 via UpdateDomainConfig."Iops/Throughput."DescribeDomainHealthTotalShards, ActiveShardsshards_per_node = TotalShards / InstanceCountDescribeDomain → EngineVersion):heap_GiB ≈ min(32, instance_RAM_GiB / 2) (e.g., t3.medium.search 4 GiB RAM → ~2 GiB heap; r6g.xlarge.search 32 GiB RAM → ~16 GiB heap).
Instance RAM reference (GiB): t3.small=2 · t3.medium=4 · c6g.large=4 · m6g.large=8 ·
c6g.xlarge=8 · r6g.large=16 · m6g.xlarge=16 · c6g.2xlarge=16 · r6g.xlarge=32 ·
m6g.2xlarge=32 · r6g.2xlarge=64 (heap caps at 32 GiB). For unlisted types use the EC2
equivalent's memory — never guess silently; name the assumed RAM in the report.bp_limit = 25 × heap_GiB shards/node.shards_per_node > hard_limit → 🔴 "Exceeds hard shard limit for engine version {version}."shards_per_node > 4 × bp_limit → 🔴 "Shard density ({shards_per_node}/node) is more than 4× the best-practice limit ({bp_limit}/node for ~{heap_GiB} GiB heap). Severe heap/GC and recovery risk." (This tier is 🔴, not ⚠️ — do not downgrade.)shards_per_node > bp_limit → ⚠️ "Shard density ({shards_per_node}/node) exceeds best-practice threshold of 25 shards/GiB heap ({bp_limit}/node for ~{heap_GiB} GiB heap)."shards_per_node > 0.5 × bp_limit → ℹ️ "Moderate shard density. Monitor JVM heap pressure."shards_per_node <= 0.5 × bp_limit → ✅ PASS. (Verbatim: at or below half the best-practice limit the verdict is PASS, never ℹ️ — low density is not a finding.)DescribeDomainHealthActiveShards, TotalShardsActiveShards == TotalShards (all shards placed and serving)ActiveShards < TotalShards:TotalShards - ActiveShards_cluster/allocation/explain for unassigned shard root cause."FreeStorageSpace (Minimum statistic, last 24h)free_pct = FreeStorageSpace_min_MB / (VolumeSize_GiB × 1024) × 100
(Dividing the per-node Minimum by VolumeSize × InstanceCount understates free space by a
factor of InstanceCount — this is wrong. Cross-check: the Sum statistic ÷ (VolumeSize ×
InstanceCount × 1024) should give approximately the same percentage.)free_pct < 10% → 🔴 "Free storage below 10%. High watermark may trigger read-only mode."free_pct < 20% → ⚠️ "Free storage below 20%. Approaching low watermark. Plan capacity increase."free_pct < 30% → ℹ️ "Storage utilization above 70%. Monitor trend."free_pct >= 30% → ✅ PASS.Note on percentiles: CloudWatch metrics for OpenSearch (
SearchLatency,IndexingLatency) report aggregate values, not per-request percentiles. We use the Maximum statistic over 1-minute periods as a "worst-case" proxy. True p50/p99 latency requires OpenSearch slow-log analysis or UltraWarm query insights, which is outside the scope of API-only checks.
Time range: Last 24 hours, 1-minute period granularity.
JVMMemoryPressure, Statistic: Maximum — the verdict MUST be computed from the
Maximum statistic. Never substitute Average (an idle cluster commonly shows Avg ~43% while Max
sustains ~74% — these produce different verdicts). Report Average only as context.CPUUtilization, Statistic: Average (sustained) and Maximum (spikes)SearchLatency, Statistic: Maximum (worst-case proxy)IndexingLatency, Statistic: Maximum (worst-case proxy)SearchRate (Sum), IndexingRate (Sum)4xx (Sum), 5xx (Sum)5xx > 0 → ⚠️ "{count} server errors (5xx) in last 24h. Indicates cluster-side failures (overload, circuit breaker, shard failures)."5xx == 0 AND 4xx > 0 → ℹ️ "{count} client errors (4xx). May indicate malformed queries, auth issues, or unauthenticated probes against a public endpoint." (Verbatim: with zero 5xx this is ℹ️ regardless of 4xx volume — never ⚠️. Note spikes/patterns as context only.)5xx == 0 AND 4xx == 0 → ✅ PASS.ClusterStatus.red (Maximum), ClusterStatus.yellow (Maximum)red == 1 datapoints → 🔴 "Cluster entered RED status {count} times in last 24h."yellow == 1 datapoints (and currently not yellow) → ℹ️ "Cluster experienced YELLOW status {count} times in last 24h (now recovered)."SEVERITY OVERRIDE PROHIBITION (apply exactly): The verdict tier for every check in this document comes ONLY from the Logic line that matches the observed values — NEVER from general security judgment. Several security checks below are deliberately rated ⚠️ (not 🔴) by owner decision: a single disabled control in isolation is a Warning; only the fully-compounded 4.4 case is Critical. Rendering 4.1, 4.2, 4.3, 4.5, or 4.6 as 🔴/CRITICAL is a SPEC VIOLATION even if it feels more correct — if your judgment disagrees with a Logic line, the Logic line wins. You may add ONE sentence of context inside the finding; you may never change the verdict tier, the emoji, or the severity word. This applies to the matrix, the executive summary, section headings, and prose equally.
DescribeDomain → EncryptionAtRestOptions.Enabledfalse → ⚠️ "Encryption at rest is disabled. Data on disk is unencrypted — non-compliant with most regulatory frameworks." (⚠️ by owner decision — do NOT escalate to 🔴.)DescribeDomain → NodeToNodeEncryptionOptions.Enabledfalse → ⚠️ "Node-to-node encryption disabled. Inter-node traffic is unencrypted." (⚠️ by owner decision — do NOT escalate to 🔴.)DescribeDomain → DomainEndpointOptions.EnforceHTTPSfalse → ⚠️ "HTTPS not enforced. Clients can connect over HTTP (plaintext)."TLSSecurityPolicy — if not Policy-Min-TLS-1-2-2019-07 or newer → ℹ️ "TLS policy allows older protocol versions."DescribeDomain → VPCOptionsVPCOptions is empty/null AND EnforceHTTPS == false AND AdvancedSecurityOptions.Enabled == false → 🔴 "Domain uses a public endpoint with BOTH transport and access controls disabled — fully compounded exposure. Migrate to VPC or close both gaps." (This is an AND — BOTH controls must be disabled. A single weak control does NOT escalate 4.4; it is already flagged ⚠️ by its own check: HTTPS by 4.3, FGAC by 4.6. The fully-compounded case is the ONLY security condition rated 🔴.)VPCOptions is empty/null (any other combination) → ⚠️ "Domain uses a public endpoint{; weak control: {name the single false one, if any}}. Consider VPC deployment for network isolation."DescribeDomain → AccessPolicies (JSON string)"*" with no IP condition → ⚠️ "Access policy allows unauthenticated access from any IP.""*" with IP condition → ℹ️ "Access restricted by IP/CIDR but no IAM authentication."DescribeDomain → AdvancedSecurityOptionsEnabled, InternalUserDatabaseEnabledEnabled == false → ⚠️ "Fine-grained access control disabled. No index-level or document-level permissions." (⚠️ by owner decision — do NOT escalate to 🔴.)InternalUserDatabaseEnabled == true → ℹ️ "Internal user database enabled. Consider SAML or IAM-based auth for production."DescribeDomain → ClusterConfig.WarmEnabled, ColdStorageOptions.EnabledWarmEnabled == false → ℹ️ "UltraWarm not enabled. If you have infrequently accessed indices (e.g., >30 days old), UltraWarm can reduce cost by ~80% for those indices."ColdStorageEnabled == false AND WarmEnabled == true → ℹ️ "Cold storage not enabled. For rarely accessed data, cold storage offers lowest-cost option."DescribeReservedInstancesFor EVERY finding rated 🔴, ⚠️, or ℹ️, the Prioritized Recommendations section MUST include that check's entry from references/remediation-reference.md (loaded in Execution Flow step 9 via read_skill_resource): copy the "Why it matters" line and "Resolve" steps verbatim (you may instantiate observed values, e.g. the actual master count), and include the "Dive deeper" link(s) EXACTLY as written. NEVER emit a documentation link that is not present in the Remediation Reference — do not construct, recall, or infer URLs from any other source. PASS/✅ checks get no remediation entry.
MANDATORY COVERAGE RULE: The report MUST evaluate and account for EVERY check in this document (1.1–1.4, 2.1–2.4, 3.1–3.7, 4.1–4.6, 5.1–5.3 — 24 checks total). No check may be silently omitted. ID FIDELITY: matrix rows MUST use these exact IDs with these exact meanings — never renumber, split, merge, or invent checks: 1.1 Cluster Status · 1.2 Node Count & AZ Balance · 1.3 Dedicated Masters · 1.4 Engine Version · 2.1 EBS Configuration · 2.2 Shard Count & Density · 2.3 Active vs Total Shards · 2.4 Free Storage · 3.1 JVM Memory Pressure · 3.2 CPU Utilization · 3.3 Search Latency · 3.4 Indexing Latency · 3.5 Search & Indexing Rate · 3.6 HTTP Errors · 3.7 Cluster Status History · 4.1 Encryption at Rest · 4.2 Node-to-Node Encryption · 4.3 HTTPS Enforcement · 4.4 Network Exposure · 4.5 Access Policy · 4.6 FGAC · 5.1 Instance Right-Sizing · 5.2 Storage Tiering · 5.3 Reserved Instances. (Splitting 1.1 into red/yellow/green rows, or using "1.4" for service-software patches, are documented failure modes — do not reproduce them.) CATEGORY ROLL-UP: each category's executive-summary status = the WORST finding in it: any 🔴 → Critical; else any ⚠️ → Warning; else all ✅/ℹ️ → Healthy. Never judgment-based. Apply the exact thresholds written in each check's Logic section verbatim — do not substitute your own thresholds or severity levels, and do not round a verdict up or down a tier based on judgment: the tier is determined solely by which Logic line matches. If a check cannot be evaluated (API error, no data), it MUST appear in the Check Coverage Matrix as SKIPPED with the reason. For every CloudWatch-based check (2.1 throttle sub-check, 2.4, 3.1–3.7, 5.1), the matrix's Observed Value column MUST name the statistic used (e.g., "Max=74.3% (Maximum stat)") — it must match the statistic named in that check's spec. Before finishing, count the matrix rows: if the count is not exactly 24, the report is incomplete — fix it before responding.
Structure the report as:
# OpenSearch Domain Health Assessment
## Domain: {domain_name}
**Region:** {region} | **Engine:** {engine_version} | **Assessed:** {timestamp}
## Summary
| Category | Status | Findings |
|----------|--------|----------|
| Cluster Health | 🟢/🟡/🔴 | {one-line summary} |
| Storage & Shards | 🟢/🟡/🔴 | {one-line summary} |
| Performance | 🟢/🟡/🔴 | {one-line summary} |
| Security | 🟢/🟡/🔴 | {one-line summary} |
| Cost Optimization | 🟢/🟡/⚪ | {one-line summary} |
## Detailed Findings
### 🔴 Critical (act now)
{findings}
### ⚠️ Warnings (plan action)
{findings}
### ℹ️ Informational
{findings}
### ✅ Passing Checks
{list of checks that passed}
## Recommendations (prioritized)
1. {highest priority}
2. ...
## Raw Data Reference
{key metrics and config values for verification}
## Check Coverage Matrix (REQUIRED — one row per check, all 24, in order)
| Check | Verdict | Observed value | Threshold applied |
|-------|---------|----------------|-------------------|
| 1.1 Cluster status | 🟢/⚠️/🔴 | {value} | {rule} |
| 1.2 Node/AZ balance | ... | ... | ... |
| ... (every check through 5.3 — SKIPPED rows must state the reason) |DescribeDomainHealth returns Processing → domain is being modified. Report current state with caveat.AccessDeniedException → report which check was skipped and what permission is needed.© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files (references) in skills/analytics-opensearch-expertise of aws/tools-for-devops-agent.
Open the folder on GitHubat commit ddda70b
Analytics Opensearch Expertise next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Analytics Opensearch Expertise this skillaws/tools-for-devops-agent | 102 | — | ~6.9k | Automated safety check: Pass | Apache-2.0 | |
| Amazon Opensearch Serviceaws/agent-toolkit-for-aws | 2.8k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Opensearch Personalize Caching Strategiespproenca/dot-skills | 215 | — | ~4.8k | Automated safety check: Pass | MIT | |
| Docker Compose Testsjillesvangurp/kt-search | 155 | — | ~295 | Automated safety check: Pass | MIT | |
| Cloud Provisioningelastic/agent-skills | 592 | — | ~5.4k | Automated safety check: Pass | Apache-2.0 | |
| Detecting Insider Threat With Uebamukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~738 | Automated safety check: Pass | Apache-2.0 |
aws/agent-toolkit-for-aws
Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…
pproenca/dot-skills
Caching strategies in front of AWS OpenSearch (Elasticsearch) or AWS Personalize — search, recommenders, multi-recommender pages, anon vs logged-in traffic.
jillesvangurp/kt-search
Use Gradle Compose tasks to prepare and recover local Elasticsearch/OpenSearch test infrastructure in kt-search.
elastic/agent-skills
Provision and operate Elastic Cloud infrastructure: create, connect to, update, and delete Serverless projects (Elasticsearch, Observability, Security); manage traffic filters (IP and AWS…
mukul975/Anthropic-Cybersecurity-Skills
Implement User and Entity Behavior Analytics (UEBA) using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and alert on insider threat…
pproenca/dot-skills
Search relevance and ranking on OpenSearch/Elasticsearch for a two-sided marketplace — candidate retrieval (hybrid BM25 + kNN, RRF, two-tower EBR), base relevance (BM25F, multimatch, LambdaMART)…
aws/tools-for-devops-agent
A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.
aws/tools-for-devops-agent
ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.
aws/tools-for-devops-agent
AWS Database Migration Service (DMS) operational review and troubleshooting skill.
aws/tools-for-devops-agent
Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…
aws/tools-for-devops-agent
Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.
aws/tools-for-devops-agent
Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.
Amazon OpenSearch Service domain health assessment. An agent skill from aws/tools-for-devops-agent. Analytics Opensearch Expertise is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Amazon OpenSearch Service domain health assessment.
Analytics Opensearch Expertise fits situations like: tasks that involve Search implementation; tasks that involve OKRs and executive reporting.
Run `npx skills add aws/tools-for-devops-agent --skill analytics-opensearch-expertise -a claude-code`. Or copy the skill folder (skills/analytics-opensearch-expertise in aws/tools-for-devops-agent) into .claude/skills/analytics-opensearch-expertise in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/tools-for-devops-agent --skill analytics-opensearch-expertise -a codex`. Or copy the skill folder (skills/analytics-opensearch-expertise in aws/tools-for-devops-agent) into .agents/skills/analytics-opensearch-expertise in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill analytics-opensearch-expertise -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analytics-opensearch-expertise, .gemini/skills/analytics-opensearch-expertise, .github/skills/analytics-opensearch-expertise and .opencode/skills/analytics-opensearch-expertise in your project.
SKILL.md names no scripts, command-line tools or credentials: Analytics Opensearch Expertise is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Analytics Opensearch Expertise is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.9k tokens (SKILL.md is roughly 28k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Analytics Opensearch Expertise: Amazon Opensearch Service (aws/agent-toolkit-for-aws, 2.8k stars), Opensearch Personalize Caching Strategies (pproenca/dot-skills, 215 stars), Docker Compose Tests (jillesvangurp/kt-search, 155 stars) and Cloud Provisioning (elastic/agent-skills, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 102 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 8, 2026.
Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.