# Cluster with all system indices in RED status

**URL:** <https://discuss.elastic.co/t/cluster-with-all-system-indices-in-red-status/319285>\
**Category:** Elasticsearch\
**Created:** [November 18, 2022, 10:23am UTC](https://discuss.elastic.co/t/cluster-with-all-system-indices-in-red-status/319285 "2022-11-18T10:23:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [November 18, 2022, 10:23am UTC](https://discuss.elastic.co/t/cluster-with-all-system-indices-in-red-status/319285/1 "2022-11-18T10:23:25Z")

</div>

Hello,

I have a cluster where i lost some nodes that are storing primaries & replicas of all system indices.

| index | shard | prirep | state |
| --- | --- | --- | --- |
| .reporting-2022-09-18 | 0 | p | UNASSIGNED |
| .reporting-2022-09-18 | 0 | r | UNASSIGNED |
| .kibana-event-log-8.3.3-000002 | 0 | p | UNASSIGNED |
| .kibana-event-log-8.3.3-000002 | 0 | r | UNASSIGNED |
| .ds-.slm-history-5-2022.11.06-000003 | 0 | p | UNASSIGNED |
| .ds-.slm-history-5-2022.11.06-000003 | 0 | r | UNASSIGNED |
| .ds-ilm-history-5-2022.09.02-000001 | 0 | p | UNASSIGNED |
| .ds-ilm-history-5-2022.09.02-000001 | 0 | r | UNASSIGNED |
| .async-search | 0 | p | UNASSIGNED |
| .async-search | 0 | r | UNASSIGNED |
| .kibana-event-log-8.3.3-000001 | 0 | p | UNASSIGNED |
| .kibana-event-log-8.3.3-000001 | 0 | r | UNASSIGNED |
| .ds-.logs-deprecation.elasticsearch-default-2022.10.02-000002 | 0 | p | UNASSIGNED |
| .ds-.logs-deprecation.elasticsearch-default-2022.10.02-000002 | 0 | r | UNASSIGNED |
| .tasks | 0 | p | UNASSIGNED |
| .tasks | 0 | r | UNASSIGNED |
| .kibana-event-log-8.3.3-000003 | 0 | p | UNASSIGNED |
| .kibana-event-log-8.3.3-000003 | 0 | r | UNASSIGNED |
| .security-7 | 0 | p | UNASSIGNED |
| .security-7 | 0 | r | UNASSIGNED |
| .apm-agent-configuration | 0 | p | UNASSIGNED |
| .apm-agent-configuration | 0 | r | UNASSIGNED |
| .kibana\_8.3.3\_001 | 0 | p | UNASSIGNED |
| .kibana\_8.3.3\_001 | 0 | r | UNASSIGNED |
| .transform-internal-007 | 0 | p | UNASSIGNED |
| .transform-internal-007 | 0 | r | UNASSIGNED |
| .ds-ilm-history-5-2022.10.02-000002 | 0 | p | UNASSIGNED |
| .ds-ilm-history-5-2022.10.02-000002 | 0 | r | UNASSIGNED |
| .ds-.logs-deprecation.elasticsearch-default-2022.11.01-000003 | 0 | p | UNASSIGNED |
| .ds-.logs-deprecation.elasticsearch-default-2022.11.01-000003 | 0 | r | UNASSIGNED |
| .ds-.slm-history-5-2022.10.07-000002 | 0 | p | UNASSIGNED |
| .ds-.slm-history-5-2022.10.07-000002 | 0 | r | UNASSIGNED |
| .ds-ilm-history-5-2022.11.01-000003 | 0 | p | UNASSIGNED |
| .ds-ilm-history-5-2022.11.01-000003 | 0 | r | UNASSIGNED |
| .transform-notifications-000002 | 0 | p | UNASSIGNED |
| .transform-notifications-000002 | 0 | r | UNASSIGNED |
| .geoip\_databases | 0 | p | UNASSIGNED |
| .geoip\_databases | 0 | r | UNASSIGNED |
| .kibana\_task\_manager\_8.3.3\_001 | 0 | p | UNASSIGNED |
| .kibana\_task\_manager\_8.3.3\_001 | 0 | r | UNASSIGNED |
| .apm-custom-link | 0 | p | UNASSIGNED |
| .apm-custom-link | 0 | r | UNASSIGNED |
| .ds-.slm-history-5-2022.09.07-000001 | 0 | p | UNASSIGNED |
| .ds-.slm-history-5-2022.09.07-000001 | 0 | r | UNASSIGNED |
| .reporting-2022-11-06 | 0 | p | UNASSIGNED |
| .reporting-2022-11-06 | 0 | r | UNASSIGNED |
| .kibana\_security\_session\_1 | 0 | p | UNASSIGNED |
| .kibana\_security\_session\_1 | 0 | r | UNASSIGNED |

Is there any way to delete these system indexes and restart cluster/kibana to get them created newly

I tried to create an emergency user to be able to access cluster 🙂

`bin/elasticsearch-users useradd restore_user -p e ****** -r superuser`

But not able to delete them

```auto
curl -k -u restore_user: *****-X DELETE "https://******* :9200/.security-7?pretty"
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "action [indices:admin/delete] is unauthorized for user [restore_kbn] with roles [kibana_system] on restricted indices [.security-7], this action is granted by the index privileges [delete_index,manage,all]"
      }
    ],
    "type" : "security_exception",
    "reason" : "action [indices:admin/delete] is unauthorized for user [restore_user] with roles [kibana_system] on restricted indices [.security-7], this action is granted by the index privileges [delete_index,manage,all]"
  },
  "status" : 403
}

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 21, 2022, 1:51am UTC](https://discuss.elastic.co/t/cluster-with-all-system-indices-in-red-status/319285/2 "2022-11-21T01:51:03Z")

</div>

> [@ylasri](#):
>
> `bin/elasticsearch-users useradd restore_user -p e ****** -r superuser`

Did this work ok? What was the response from Elasticsearch for it?

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [November 21, 2022, 6:26am UTC](https://discuss.elastic.co/t/cluster-with-all-system-indices-in-red-status/319285/3 "2022-11-21T06:26:14Z")

</div>

Yes the `useradd` worked and output was

```auto
{
  "created": true 
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 19, 2022, 6:27am UTC](https://discuss.elastic.co/t/cluster-with-all-system-indices-in-red-status/319285/4 "2022-12-19T06:27:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
