# Clear cache API

**URL:** <https://discuss.elastic.co/t/clear-cache-api/48507>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [April 27, 2016, 6:42am UTC](https://discuss.elastic.co/t/clear-cache-api/48507 "2016-04-27T06:42:16Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![us3r](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/us3r/32/4647_2.png) [@us3r](https://discuss.elastic.co/u/us3r)\
**Post date:** [April 27, 2016, 6:42am UTC](https://discuss.elastic.co/t/clear-cache-api/48507/1 "2016-04-27T06:42:16Z")

</div>

Hello

Based on the [documentation](https://www.elastic.co/guide/en/shield/current/shield-rest.html#shield-clear-cache-rest) we should use POST request on \_\_shield/realm/NAME/\_cache/clear to clear evicts users from the user cache.  
However it looks like that this handler doesnt work anymore...

`$ curl -u admin -XPOST http://127.0.0.1:9200/_shield/realm/ldap1/_cache/clear Enter host password for user 'admin': No handler found for uri [/_shield/realm/ldap1/_cache/clear] and method [POST]`

Any advice?

---

<div class="post-metadata">

**Author:** ![michalterbert](https://avatars.discourse-cdn.com/v4/letter/m/848f3c/32.png) [@michalterbert](https://discuss.elastic.co/u/michalterbert)\
**Post date:** [April 27, 2016, 6:45am UTC](https://discuss.elastic.co/t/clear-cache-api/48507/2 "2016-04-27T06:45:01Z")

</div>

Hello Mariusz,

I have the same issue like you.  
Technical documentation of Shield sukcs 😕

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [April 27, 2016, 10:15am UTC](https://discuss.elastic.co/t/clear-cache-api/48507/3 "2016-04-27T10:15:26Z")

</div>

Hi Mariusz,

Can you share the version of shield and elasticsearch that you are using? Also can you share your shield settings from the elasticsearch.yml file?

-Jay

---

<div class="post-metadata">

**Author:** ![us3r](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/us3r/32/4647_2.png) [@us3r](https://discuss.elastic.co/u/us3r)\
**Post date:** [April 27, 2016, 11:27am UTC](https://discuss.elastic.co/t/clear-cache-api/48507/4 "2016-04-27T11:27:08Z")

</div>

Hi, we are using version 2.3.1

> "version": {  
> "number": "2.3.1",  
> "build\_hash": "bd980929010aef404e7cb0843e61d0665269fc39",  
> "build\_timestamp": "2016-04-04T12:25:05Z",  
> "build\_snapshot": false,  
> "lucene\_version": "5.5.0"  
> }

And shield in the same version :

```
license 2.3.1 j  
shield 2.3.1 j  

```

On each host.

Our current configuration (more or less) looks like that:

> cluster.name: {{ cluster }}  
> node.name: ${HOSTNAME}-{{ item.0 }}  
> node.master: {{ item.3 }}  
> node.data: {{ item.4 }}  
> node.rack: ${HOSTNAME}  
> path.data: {{ item.1 }}  
> bootstrap.mlockall: 1  
> network.bind\_host: ${HOSTNAME}  
> network.publish\_host: ${HOSTNAME}  
> network.host: ${HOSTNAME}  
> http.port: {{ item.2 }}  
> discovery.zen.ping.unicast.hosts: {{ hosts }}  
> discovery.zen.minimum\_master\_nodes: 4  
> node.max\_local\_storage\_nodes: 3  
> cluster.routing.allocation.awareness.attributes: rack  
> cluster.routing.allocation.same\_shard.host: 1  
> processors: 13  
> index.merge.scheduler.max\_thread\_count: 1

> shield.ssl.keystore.path: /etc/elasticsearch/node{{ item.0 }}/shield/node.jks  
> shield.ssl.keystore.password: OUR\_SECRET\_PASSWORD 🙂

> shield:  
> authc:  
> realms:  
> ldap1:  
> type: ldap  
> hostname\_verification: 0  
> order: 0  
> url: "ldaps://{{ ldap\_server }}:636"  
> user\_dn\_templates:  
> - "uid={0}, ou=People, o=company"  
> {{ ldap\_users }}  
> group\_search:  
> base\_dn: {{ ldap\_group }}  
> files:  
> role\_mapping: "/etc/elasticsearch/node{{ item.0 }}/shield/role\_mapping.yml

---

<div class="post-metadata">

**Author:** ![michalterbert](https://avatars.discourse-cdn.com/v4/letter/m/848f3c/32.png) [@michalterbert](https://discuss.elastic.co/u/michalterbert)\
**Post date:** [April 27, 2016, 7:13pm UTC](https://discuss.elastic.co/t/clear-cache-api/48507/5 "2016-04-27T19:13:52Z")

</div>

any update?

---

<div class="post-metadata">

**Author:** ![us3r](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/us3r/32/4647_2.png) [@us3r](https://discuss.elastic.co/u/us3r)\
**Post date:** [April 27, 2016, 7:46pm UTC](https://discuss.elastic.co/t/clear-cache-api/48507/6 "2016-04-27T19:46:57Z")

</div>

no ☹  
I still do not know how to accelerate the propagation of the permissions changes. It looks like that you need to be really calm before you upgrade ELK to the newest version.

Maybe better is to wait a little before publish a new "stable" version... updating the whole infra every week is really painfull.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [April 28, 2016, 10:19am UTC](https://discuss.elastic.co/t/clear-cache-api/48507/7 "2016-04-28T10:19:13Z")

</div>

@us3r @michalterbert thank you for bringing this to our attention. In the process of adding a new alias for this API, the prior one was inadvertently removed. As a workaround, you can use the following command:

```auto
curl -u admin -XPOST http://127.0.0.1:9200/_shield/realm/ldap1/_clear_cache

```

I'll ensure the documentation is updated and the pre-existing API is restored for the next release.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:45pm UTC](https://discuss.elastic.co/t/clear-cache-api/48507/8 "2017-07-06T13:45:05Z")

</div>


