You can log all warnings and errors from your OpenSearch cluster to the external OpenSearch cluster. On the external cluster, you can configure alerts for this type of warning.
I’ll need a 2nd OpenSearch cluster just to catch errors from the 1st one… This approach looks like a huge overkill.
BTW, what logs should I check to find that errors? The only place I saw that error was in the Kibana GUI under Alerts. I checked Kibana logs as well as OpenSearch by “Email size larger than 10000” search string and found nothing.