◆ Elasticsearch

Use Elasticsearch percolator queries

This is real work, not a feature someone invented — it comes from real job ads and real questions people asked. Below are four ready AI prompts: get it done, make it easy for the next person to say yes to, work out the right move when you are stuck, and stop it coming back.

4prompts

The same task, four prompts

today's deadline · the next reviewer · the stuck moment · the pattern
AExecute — do the immediate taskI need to set up a system that can continuously monitor incoming log data for specific error…+
I need to set up a system that can continuously monitor incoming log data for specific error patterns and immediately flag them. Configure the percolator queries to match these known critical exceptions and route alerts to the operations team.
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
BImprove — make it easier to acceptBefore we push this new service to production, I need to ensure our percolator queries are…+
Before we push this new service to production, I need to ensure our percolator queries are robust enough to catch emerging issues, not just the known ones. Can you refine them to be more resilient to variations in log messages, maybe using fuzzy matching or broader regex, without generating excessive noise for the SRE team?
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
CDecide — diagnose the stuck momentThe new service just went live, and the percolator queries are firing 'unknown error' alerts…+
The new service just went live, and we're seeing a flood of 'unknown error' alerts from the percolator, but the application logs show nothing specific.
The new service just went live, and the percolator queries are firing 'unknown error' alerts constantly, but the application logs don't show any matching specifics. I'm afraid we're either missing a critical configuration or the queries are too broad, overwhelming the on-call team. What's the most likely cause, and how should I triage this without causing a false alarm incident?
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
DBecome — change the patternWe consistently struggle to write percolator queries that are both precise enough to be useful…+
We keep writing percolator queries that are either too noisy or too specific to be useful long-term.
We consistently struggle to write percolator queries that are both precise enough to be useful and flexible enough to handle minor log format changes. This leads to constant rework and missed alerts. What habit should I change in how we approach defining these queries, to make them more adaptable and less fragile from the start?
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?

Questions people actually ask

honest answers, no sign-up

Every task here was seen in the real world. Someone doing the job named it, a real job ad asked for it, or a lot of people asked about it online.

If nothing real showed a task, it is not on the page. That is the whole rule.

They are the same job approached four ways, because what you need depends on where you are.

Get it done today. Make it easy for the next person to say yes to. Work out the right move when you are stuck. Learn the pattern so the job stops coming back.

For most of these jobs it can carry the heavy thinking - draft it, sort it, check it, rehearse it with you.

It cannot sit in your chair, take the blame when a number is wrong, or notice what nobody wrote down. Let it do the first 80%. Keep the last 20% that is truly yours.

No. Copy any prompt and paste it into the AI you already use. No account, no score, no wall in the way.

Any of them. The prompts describe the work rather than naming a product, so they are not tied to one assistant.

That is also why they keep working when you switch.

Change it freely. Every prompt is a starting line, not a rule.

Put in your real numbers, your real names and your real deadline. The more you make it yours, the better the answer comes back.

The tasks come from real job ads, published job data and the questions people ask in public forums.

The steps come from Elasticsearch's own documentation, with practitioner sources for the traps the manual does not mention.

Push once. Ask it to sharpen the weakest part and to say what it assumed.

Most wrong answers come from a missing detail rather than a bad prompt - tell it the thing it could not know.