Cluster & Cost Review

Find out what your cluster should cost — and why it doesn't.

Most Elasticsearch and OpenSearch bills grow by accretion: another data stream here, a defensive replica there, daily indices nobody rolled over, a hot tier holding data nobody has queried in months. The cluster keeps working, so nobody looks — until the invoice or an outage forces the question.

A cluster and cost review answers it systematically.

What we examine

  • Shard strategy — shard counts and sizes against data volume and node heap; oversharding and undersharding both show up here, and both cost you.
  • Index lifecycle — ILM (or ISM on OpenSearch) policies, rollover conditions, data tier allocation, and whether warm/cold/frozen tiers are configured, misconfigured, or missing entirely.
  • Ingest efficiency — pipeline design, mapping bloat (every unneeded indexed field costs disk and heap), refresh intervals, and bulk sizing.
  • Retention reality — what each data stream is kept for, versus what its consumers actually query. The gap is usually the single biggest line item.
  • Deployment and license posture — self-managed vs Elastic Cloud vs Amazon OpenSearch Service, license tier against the features you actually use, and node sizing against the workload.
  • Stability risks — cluster state size, hot node hotspots, snapshot health, version and plugin currency.

What you get

A prioritized findings report. Each finding names the problem, the evidence from your cluster, the specific fix — a setting, an ILM policy, a reindex, an architecture change — and its expected effect on cost or stability. Quick wins are separated from structural work so your team can start the same week.

We can stop there, or stay to implement the findings with your team — same engineers, same hourly terms.

How it runs

The review is read-only against your cluster APIs and configuration; we work with your team over screen-share or with scoped access you control. Most reviews conclude within a few working sessions, depending on estate size — we'll estimate the hours honestly in the initial conversation.

Tell us your cluster size, versions, and what triggered the question — bill, latency, or a bad week on call.
Request a review