UiPath incident
Orchestrator logs from robot jobs are visible with a delay in the US and Delayed US regions
UiPath experienced a minor incident on July 21, 2026 affecting Orchestrator and Orchestrator and 1 more component, lasting 13h 58m. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- investigating Jul 21, 2026, 02:18 PM UTC
We are investigating reports of missing robot logs in the US region. Our teams are working to identify the cause and will share more details as the investigation progresses.
- investigating Jul 21, 2026, 02:37 PM UTC
We are investigating reports of missing robot logs in the US region. Our teams are working to identify the cause and will share more details as the investigation progresses.
- monitoring Jul 21, 2026, 03:00 PM UTC
Mitigation has been applied. We are monitoring closely to ensure stability.
- investigating Jul 21, 2026, 04:07 PM UTC
We are still investigating the reports of delayed ingestion of robot logs. Our teams are working to identify the cause and will share more details as the investigation progresses.
- identified Jul 21, 2026, 05:05 PM UTC
We have identified and applied new mitigation and recovery is estimated to take several more hours.
- identified Jul 21, 2026, 06:12 PM UTC
We have identified and applied new mitigation and recovery is estimated to take several more hours.
- identified Jul 21, 2026, 06:24 PM UTC
We have identified and applied new mitigation and recovery is estimated to take several more hours.
- identified Jul 21, 2026, 06:35 PM UTC
We have identified impact in the US Delayed environment as well, and are continuing mitigation activities.
- identified Jul 21, 2026, 07:38 PM UTC
We are continuing mitigation activities, the delayed US region is showing improvements.
- identified Jul 21, 2026, 08:54 PM UTC
We are continuing mitigation activities, the delayed US region is showing improvements.
- identified Jul 21, 2026, 09:55 PM UTC
We are continuing mitigation activities, the delayed US region is showing improvements.
- identified Jul 21, 2026, 11:14 PM UTC
We are continuing mitigation activities, the delayed US region is showing improvements.
- identified Jul 22, 2026, 12:25 AM UTC
We are continuing mitigation activities, the delayed US region is showing improvements.
- identified Jul 22, 2026, 01:38 AM UTC
We are continuing mitigation activities, the delayed US region is showing improvements.
- identified Jul 22, 2026, 02:41 AM UTC
We are continuing mitigation activities, the delayed US region is showing improvements.
- identified Jul 22, 2026, 03:58 AM UTC
We are continuing mitigation activities, the delayed US region is showing improvements.
- identified Jul 22, 2026, 04:15 AM UTC
We are continuing mitigation activities and the impacted regions are showing improvements.
- resolved Jul 22, 2026, 04:17 AM UTC
Our mitigation efforts are completed and impacted services are fully stable now. We will post a detailed summary of incident soon.
- postmortem Aug 05, 2026, 07:42 AM UTC
## Customer impact Between July 21, 2026 at 1:58 pm UTC and July 22, 2026 at approximately 1:00 am UTC, Orchestrator robot job logs in the US and Delayed US region were delayed. Customers could run jobs, but recent robot logs were not immediately available in the Orchestrator interface, affecting real-time monitoring and troubleshooting. No data was lost. Delayed logs continued to be processed and became visible once the system caught up. The customer-facing impact lasted approximately 11 hours. ## Root cause A server in the search infrastructure that Orchestrator uses to store robot logs became unavailable and could not restart automatically because its access credentials had expired. Once the server was manually restored, the search system began redistributing data across the remaining servers. This redistribution consumed significant system capacity and slowed the processing of new robot logs, creating a backlog before logs became visible in Orchestrator. Usually, adding a server to the cluster does not cause processing constraints, but in this instance, the system proceeded to redistribute about 30% of the data between servers, instead of populating only the newly added server. ## Detection An automated service alert fired at 1:58 pm UTC on July 21, 2026, and an incident was opened for investigation. Customer reports quickly confirmed the impact, with delayed or missing robot logs observed across multiple accounts in the US region. ## Response At 2:37 pm UTC on July 21, we posted an update confirming we were investigating reports of missing robot logs in the US region. By 3:07 pm UTC, the unavailable server had been restored, and by 3:20 pm UTC, event processing capacity was increased as an additional mitigation. Despite these measures, log delays persisted. At 6:08 pm UTC, our engineering team adjusted search system settings to reduce the load from writing newly processed logs. At 6:29 pm UTC, the team moved the most active log data off an overburdened server, and at 6:53 pm UTC, internal data redistribution was temporarily paused because it was competing with log processing recovery. By 7:11 pm UTC, all available mitigations had been applied and the remaining recovery depended on the system working through the backlog. Logs caught up around 1:00 am UTC on July 22, 2026, and the incident was marked resolved at 4:17 am UTC after continued monitoring confirmed stability. ## Follow up 1. Optimize the data rebalancing limits so that they do not impact ingestion of new data. 2. Increase spare capacity in the cluster, so that even massive data reshuffling does not cause processing constraints. 3. Replace the expiring access credential mechanism and apply the corrected configuration across all search infrastructure to prevent recurrence. 4. Improve automated alerting so that an unavailable search server that is not recovered within a short period triggers a higher-severity alert for faster response.