Aria Operations for Logs 8.18.x
When an Aria Operations for Logs cluster is undersized or hitting ingestion limits (EPS), resources (CPU/Memory) are prioritized for ingestion and indexing to prevent data loss. This resource contention can cause the alerting engine to lag or fail to process triggers in real-time, resulting in missed email notifications.
This is an expected behavior when cluster resources are exhausted. To resolve this issue, scale the cluster to match the actual ingestion requirements and Optimize Retention and Filters.
Management → System Monitor.If the ingestion rate exceeds the cluster capacity, perform one of the following options:
Scale Out: Add additional worker nodes to the cluster to distribute the ingestion load. Use the Aria Operations for Logs Sizing Calculator to determine the required node count.
Scale Up: Increase the vCPU and Memory for all existing nodes.
/storage/core partition is not nearing 100% utilization.