# Cluster\_health rule \[missing replica shards\] too much susceptible

**URL:** <https://discuss.elastic.co/t/cluster-health-rule-missing-replica-shards-too-much-susceptible/314183>\
**Category:** Elasticsearch\
**Created:** [September 12, 2022, 10:35am UTC](https://discuss.elastic.co/t/cluster-health-rule-missing-replica-shards-too-much-susceptible/314183 "2022-09-12T10:35:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rschirin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rschirin/32/45283_2.png) [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Post date:** [September 12, 2022, 10:35am UTC](https://discuss.elastic.co/t/cluster-health-rule-missing-replica-shards-too-much-susceptible/314183/1 "2022-09-12T10:35:11Z")

</div>

Hey there,  
I have a 7.17 ES cluster with the embedded infrastructure `rules & alerts` enabled and the usage of `ILM` for specific kind of indices.  
I have enabled the "`Cluster_health`" rule and I saw that when my ILM policy will shrink a specific index (monthly, from 3 shards to 1), the alert rule will be triggered with the message:

> Cluster health alert is firing for xxx. Current health is yellow. Allocate missing replica shards.

So, I manually test the shrink phase and I saw that if I execute the command:

`POST /test/_shrink/test_shrinked`

the test\_shrinked index will inherit the field `"index.routing.allocation.require._name": "node-2"`  
This will cause the missing replica since both primary and replica shards of the test\_shrinked index will be allocated on the same node (obviously this will not possible so replica will be unassigned).  
On another hand, I used also another `_shrink` command following official doc:

```auto
POST /test/_shrink/test_shrink
{
  "settings": {
    "index.routing.allocation.require._name": null, 
    "index.blocks.write": null 
  }
}

```

So, in the latter scenario I will not see "missing replica shards" message but at the beginning, the replica shard will be in "INITIALIZING" state so `cluster_health` will be yellow and alert will be triggered anyway.

Is there any method to make the rule less susceptible or to avoid this behavior? For example, is there a method to trigger the alert only after 10 minutes?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 10, 2022, 10:35am UTC](https://discuss.elastic.co/t/cluster-health-rule-missing-replica-shards-too-much-susceptible/314183/2 "2022-10-10T10:35:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
