Re-indexing uses both CPU and disk bandwidth. If re-indexing of event data partition is performed during peak hours, it might take more time than expected or might add load on the existing jobs. Hence, we recommend you to perform re-indexing during a scheduled maintenance time or during off-peak hours.
If there are many event data partitions to re-index, to optimize the time taken to re-index, select the date range for event data partitions which contain events that need to be searchable and reportable for priority operations. You can re-index the rest of the event data partitions as per your requirement.
(Conditional) If event visualization is enabled in the Sentinel, before scheduling re-indexing task you must ensure that, the elasticsearch is left intact. See Mapping Conflict Warning in the Kibana Search for more information.