Data missing after ES restart

i got now a log data from ES but is 2 big for pastebin. How can i send to u?

hmm now i get this and ES is gone... :))

[2015-09-02 13:49:55,407][DEBUG][action.bulk              ] [logstash_prod] observer: timeout notification from cluster service. timeout setting [1m], time since start [1m]

After ES update the error is the same...:frowning:

hi, im a newbie and i ve also similar issue with @Tigryss :slight_smile:

In my case, i m using rsyslog+ES+Kibana for loggin and everything s fine then I ve restarted ES and kibana asked me to create new index pattern. so i created an index pattern with same as previous pattern. But after this step i could not view any old log records with kibana. I checked the old files from local cmdline they re still exist but kibana doesnt load any of them. i checked my nodes, i ve only one. But i ve some concerns about my elasticsearch.yml file.
could you please guide me to solve this issue.

here s my indices dir
elasticsearch/nodes/0/indices# ls -altrh
total 156K
drwxr-xr-x 4 elasticsearch elasticsearch 4.0K Dec 29 15:17 ..
drwxr-xr-x 4 elasticsearch elasticsearch 4.0K Dec 29 15:17 .kibana
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Dec 29 15:26 logstash-2015.12.29
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Dec 30 00:17 logstash-2015.12.30
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Dec 31 00:17 logstash-2015.12.31
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 2 06:42 logstash-2016.01.02
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 3 06:35 logstash-2016.01.03
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 4 06:52 logstash-2016.01.04
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 5 06:50 logstash-2016.01.05
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 6 06:54 logstash-2016.01.06
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 7 06:26 logstash-2016.01.07
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 8 06:38 logstash-2016.01.08
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 9 06:47 logstash-2016.01.09
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 10 06:43 logstash-2016.01.10
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 11 06:30 logstash-2016.01.11
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 12 06:36 logstash-2016.01.12
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 13 06:36 logstash-2016.01.13
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 14 00:00 logstash-2016.01.14
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 15 00:01 logstash-2016.01.15
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 16 00:01 logstash-2016.01.16
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 17 00:00 logstash-2016.01.17
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 18 00:00 logstash-2016.01.18
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 19 00:00 logstash-2016.01.19
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 20 00:00 logstash-2016.01.20
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 21 00:03 logstash-2016.01.21
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 22 01:34 logstash-2016.01.22
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 23 00:19 logstash-2016.01.23
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 24 00:28 logstash-2016.01.24
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 25 01:30 logstash-2016.01.25
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 26 00:01 logstash-2016.01.26
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 27 02:00 logstash-2016.01.27
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 28 02:00 logstash-2016.01.28
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 29 02:00 logstash-2016.01.29
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 30 02:00 logstash-2016.01.30
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Jan 31 02:00 logstash-2016.01.31
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Feb 1 05:02 logstash-2016.02.01
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Feb 2 05:40 logstash-2016.02.02
drwxr-xr-x 39 elasticsearch elasticsearch 4.0K Feb 3 06:19 .
drwxr-xr-x 8 elasticsearch elasticsearch 4.0K Feb 3 06:19 logstash-2016.02.03

my nodes dir
/elasticsearch/nodes# ls -altrh
total 12K
drwxr-xr-x 3 elasticsearch elasticsearch 4.0K Dec 29 15:17 ..
drwxr-xr-x 3 elasticsearch elasticsearch 4.0K Dec 29 15:17 .
drwxr-xr-x 4 elasticsearch elasticsearch 4.0K Dec 29 15:17 0

and my elasticseach.yml - i uncommented only these two lines in network section all other lines are commented

network.host: localhost
http.port: 9200

It'd be better if you created your own thread :slight_smile:

Hi can you send me the start parameters. :smiley:

Try this,
and check you es.yml for index store type.

DAEMON_ARGS="-d --node.name=$NODENAME -Des.config=$CONFIG_FILE -Des.path.home=$ES_HOME -Des.path.logs=$LOG_DIR -Des.logger.level=DEBUG -Des.path.data=$DATA_DIR -Des.path.work=$WORK_DIR"