Answer to the Core Questions
Recommended upper limit for search.defaultTimeout: 30 seconds. This value is the default in Kibana 8.x and balances responsiveness against the risk of runaway queries. Setting it higher than 30 s can lead to excessive resource consumption on the Elasticsearch cluster and degrade overall performance.
Server‑side cancellation on client disconnect: Kibana does not automatically abort an in‑progress search when the browser tab is closed. The HTTP client that Kibana uses will keep the request alive until the search timeout expires or the underlying transport connection fails. To mitigate this, configure the HTTP client timeout (see elasticsearch.client.timeout) and enable Kibana’s retry logic.
Monitoring prolonged resource usage: Use Kibana’s own metrics or external monitoring tools (Prometheus, Elastic Monitoring) to watch for queries that hit the timeout. Log entries such as search timeout exceeded or elasticsearch client connection error are useful indicators.
Why 30 seconds?
- It is the default value shipped with Kibana 8.x, so most installations already use it.
- Typical Elasticsearch queries on healthy clusters finish well under this limit.
- Longer values can mask underlying performance problems and make cluster‑wide latency harder to diagnose.
How to Configure Timeouts
Open kibana.yml (usually in /etc/kibana or $KIBANA_HOME/config).
Set or confirm the search timeout:
search.defaultTimeout: 30s
Configure the HTTP client timeout to match or exceed the search timeout. This ensures the transport layer fails fast when Elasticsearch is unreachable.
elasticsearch.client.timeout: 30s
Restart Kibana to apply changes.
Run a deliberately long query (e.g., match_all on a large index) and observe that Kibana cancels it after 30 s, logging a search timeout exceeded message.
Verify that the UI shows a “no results” or loading indicator instead of hanging.
Handling Client Disconnects
- While Kibana cannot cancel a server‑side search on tab close, the HTTP client will drop the connection if the browser terminates the request. The
elasticsearch.client.timeout setting ensures that the client does not wait indefinitely.
- For long‑running visualizations, consider using
search.advanced.maxConcurrentSearches to limit the number of simultaneous queries and reduce the risk of one client hogging resources.
- Use Kibana’s
search.autoRefresh or search.refreshInterval settings to control how often the UI re‑issues queries, preventing accidental buildup of pending requests.
Monitoring & Mitigation
- Enable the
elasticsearch.client.connection_error log level to capture dropped connections.
- Set up alerts on the
search_timeout metric in Elastic Monitoring.
- Periodically review the
search.defaultTimeout value against actual query performance metrics; adjust only if you see consistent failures or unnecessary cancellations.
Missing Diagnostic Detail
To fine‑tune these settings, it would help to know the average round‑trip latency from Kibana to Elasticsearch in your environment. If latency is consistently above 200 ms, you might consider a slightly higher timeout (e.g., 45 s) but still keep it well below 60 s.