# Data vanishes a few seconds after indexing

**URL:** <https://discuss.elastic.co/t/data-vanishes-a-few-seconds-after-indexing/11432>\
**Category:** Elasticsearch\
**Created:** [April 3, 2013, 4:18pm UTC](https://discuss.elastic.co/t/data-vanishes-a-few-seconds-after-indexing/11432 "2013-04-03T16:18:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dylan\_Barlett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dylan_barlett/32/2410_2.png) [@Dylan\_Barlett](https://discuss.elastic.co/u/Dylan_Barlett)\
**Post date:** [April 3, 2013, 4:18pm UTC](https://discuss.elastic.co/t/data-vanishes-a-few-seconds-after-indexing/11432/1 "2013-04-03T16:18:48Z")

</div>

For some of our types, indexing appears to work, but data vanishes a few  
seconds later. Specifically:

1. PUT this data [https://gist.github.com/dbarlett/9695d8180da3aeafa65c](https://gist.github.com/dbarlett/9695d8180da3aeafa65c)to [http://localhost:9200/app35/template314/212608](http://localhost:9200/app35/template314/212608) (via our app or the Head  
plugin)
2. Response:  
{  
ok: true  
\_index: app35  
\_type: template314  
\_id: 212608  
\_version: 1  
}
3. GET [http://localhost:9200/app35/template314/212608](http://localhost:9200/app35/template314/212608)
4. Receive expected response[https://gist.github.com/dbarlett/edf7e181f24ed202060f](https://gist.github.com/dbarlett/edf7e181f24ed202060f)
5. Wait a few seconds and GET same URL
6. Data is gone:{

"\_index" : "app35",  
"\_type" : "template314",  
"\_id" : "212608",  
"exists" : false  
}

Environment:

- es 0.20.5
- JVM 1.7.0\_17 64-bit
- Window Server 2008 R2 64-bit
- Four cluster nodes (2 frontends with node.data: false and Jetty  
plugin, 2 backends with node.data: true, all have node.master: true)

There are no error messages in the logs, and other data is retained  
indefintely. We haven't found any meaningful distinction between data that  
stays and data that vanishes. Has anyone seen this before?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Dylan\_Barlett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dylan_barlett/32/2410_2.png) [@Dylan\_Barlett](https://discuss.elastic.co/u/Dylan_Barlett)\
**Post date:** [April 3, 2013, 4:23pm UTC](https://discuss.elastic.co/t/data-vanishes-a-few-seconds-after-indexing/11432/2 "2013-04-03T16:23:44Z")

</div>

The behavior occurs regardless of the node that data is PUT to.

On Wednesday, April 3, 2013 12:18:48 PM UTC-4, Dylan Barlett wrote:

> For some of our types, indexing appears to work, but data vanishes a few  
> seconds later. Specifically:
> 
> 1. PUT this data[https://gist.github.com/dbarlett/9695d8180da3aeafa65c](https://gist.github.com/dbarlett/9695d8180da3aeafa65c)to  
> [http://localhost:9200/app35/template314/212608](http://localhost:9200/app35/template314/212608) (via our app or the  
> Head plugin)
> 2. Response:  
> {  
> ok: true  
> \_index: app35  
> \_type: template314  
> \_id: 212608  
> \_version: 1  
> }
> 3. GET [http://localhost:9200/app35/template314/212608](http://localhost:9200/app35/template314/212608)
> 4. Receive expected response[https://gist.github.com/dbarlett/edf7e181f24ed202060f](https://gist.github.com/dbarlett/edf7e181f24ed202060f)
> 5. Wait a few seconds and GET same URL
> 6. Data is gone:{
> 
> "\_index" : "app35",  
> "\_type" : "template314",  
> "\_id" : "212608",  
> "exists" : false  
> }
> 
> Environment:
> 
> - es 0.20.5
> - JVM 1.7.0\_17 64-bit
> - Window Server 2008 R2 64-bit
> - Four cluster nodes (2 frontends with node.data: false and Jetty  
> plugin, 2 backends with node.data: true, all have node.master: true)
> 
> There are no error messages in the logs, and other data is retained  
> indefintely. We haven't found any meaningful distinction between data that  
> stays and data that vanishes. Has anyone seen this before?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [April 3, 2013, 7:13pm UTC](https://discuss.elastic.co/t/data-vanishes-a-few-seconds-after-indexing/11432/3 "2013-04-03T19:13:04Z")

</div>

Do you have \_ttl enabled by any chance in the mappings for the types where  
records disappear?  
What happens when you run get several times?  
Try running

curl "localhost:9200/app35/\_stats?pretty=true"

while you index data. What happens to counters in count and deleted?

"indices" : {  
"app35" : {  
"primaries" : {  
"docs" : {  
"count" : ????,  
"deleted" : ????

On Wednesday, April 3, 2013 12:23:44 PM UTC-4, Dylan Barlett wrote:

> The behavior occurs regardless of the node that data is PUT to.
> 
> On Wednesday, April 3, 2013 12:18:48 PM UTC-4, Dylan Barlett wrote:
> 
> > For some of our types, indexing appears to work, but data vanishes a few  
> > seconds later. Specifically:
> > 
> > 1. PUT this data[https://gist.github.com/dbarlett/9695d8180da3aeafa65c](https://gist.github.com/dbarlett/9695d8180da3aeafa65c)to  
> > [http://localhost:9200/app35/template314/212608](http://localhost:9200/app35/template314/212608) (via our app or the  
> > Head plugin)
> > 2. Response:  
> > {  
> > ok: true  
> > \_index: app35  
> > \_type: template314  
> > \_id: 212608  
> > \_version: 1  
> > }
> > 3. GET [http://localhost:9200/app35/template314/212608](http://localhost:9200/app35/template314/212608)
> > 4. Receive expected response[https://gist.github.com/dbarlett/edf7e181f24ed202060f](https://gist.github.com/dbarlett/edf7e181f24ed202060f)
> > 5. Wait a few seconds and GET same URL
> > 6. Data is gone:{
> > 
> > "\_index" : "app35",  
> > "\_type" : "template314",  
> > "\_id" : "212608",  
> > "exists" : false  
> > }
> > 
> > Environment:
> > 
> > - es 0.20.5
> > - JVM 1.7.0\_17 64-bit
> > - Window Server 2008 R2 64-bit
> > - Four cluster nodes (2 frontends with node.data: false and Jetty  
> > plugin, 2 backends with node.data: true, all have node.master: true)
> > 
> > There are no error messages in the logs, and other data is retained  
> > indefintely. We haven't found any meaningful distinction between data that  
> > stays and data that vanishes. Has anyone seen this before?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Dylan\_Barlett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dylan_barlett/32/2410_2.png) [@Dylan\_Barlett](https://discuss.elastic.co/u/Dylan_Barlett)\
**Post date:** [April 3, 2013, 7:39pm UTC](https://discuss.elastic.co/t/data-vanishes-a-few-seconds-after-indexing/11432/4 "2013-04-03T19:39:20Z")

</div>

Thanks for cluing me in about \_stats. \_ttl is not enabled.

Before PUT: "count" : 138, "deleted" : 15

Immediately after PUT: "count": 139, "deleted" : 15  
A few seconds after PUT: "count" : 138, "deleted" : 15

On Wednesday, April 3, 2013 3:13:04 PM UTC-4, Igor Motov wrote:

> Do you have \_ttl enabled by any chance in the mappings for the types where  
> records disappear?  
> What happens when you run get several times?  
> Try running
> 
> curl "localhost:9200/app35/\_stats?pretty=true"
> 
> while you index data. What happens to counters in count and deleted?
> 
> "indices" : {  
> "app35" : {  
> "primaries" : {  
> "docs" : {  
> "count" : ????,  
> "deleted" : ????
> 
> On Wednesday, April 3, 2013 12:23:44 PM UTC-4, Dylan Barlett wrote:
> 
> > The behavior occurs regardless of the node that data is PUT to.
> > 
> > On Wednesday, April 3, 2013 12:18:48 PM UTC-4, Dylan Barlett wrote:
> > 
> > > For some of our types, indexing appears to work, but data vanishes a few  
> > > seconds later. Specifically:
> > > 
> > > 1. PUT this data[https://gist.github.com/dbarlett/9695d8180da3aeafa65c](https://gist.github.com/dbarlett/9695d8180da3aeafa65c)to  
> > > [http://localhost:9200/app35/template314/212608](http://localhost:9200/app35/template314/212608) (via our app or the  
> > > Head plugin)
> > > 2. Response:  
> > > {  
> > > ok: true  
> > > \_index: app35  
> > > \_type: template314  
> > > \_id: 212608  
> > > \_version: 1  
> > > }
> > > 3. GET [http://localhost:9200/app35/template314/212608](http://localhost:9200/app35/template314/212608)
> > > 4. Receive expected response[https://gist.github.com/dbarlett/edf7e181f24ed202060f](https://gist.github.com/dbarlett/edf7e181f24ed202060f)
> > > 5. Wait a few seconds and GET same URL
> > > 6. Data is gone:{
> > > 
> > > "\_index" : "app35",  
> > > "\_type" : "template314",  
> > > "\_id" : "212608",  
> > > "exists" : false  
> > > }
> > > 
> > > Environment:
> > > 
> > > - es 0.20.5
> > > - JVM 1.7.0\_17 64-bit
> > > - Window Server 2008 R2 64-bit
> > > - Four cluster nodes (2 frontends with node.data: false and Jetty  
> > > plugin, 2 backends with node.data: true, all have node.master: true)
> > > 
> > > There are no error messages in the logs, and other data is retained  
> > > indefintely. We haven't found any meaningful distinction between data that  
> > > stays and data that vanishes. Has anyone seen this before?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 4, 2013, 6:21am UTC](https://discuss.elastic.co/t/data-vanishes-a-few-seconds-after-indexing/11432/5 "2013-04-04T06:21:27Z")

</div>

Hey,

very strange problem. Can you reduce complexity and still reproduce this  
behaviour?  
Does this happen, when you only use one node?  
Can you remove all plugins to ensure this is a barebones elasticsearch  
problem?

I dont use windows. Are there any mechanisms preventing it to open more  
files/file descriptors at some stage?

Last question: Is the document searchable at any time or are you only able  
to GET it (which means it might not yet be indexed for search)?

On Wed, Apr 3, 2013 at 9:39 PM, Dylan Barlett [dylan.barlett@gmail.com](mailto:dylan.barlett@gmail.com)wrote:

> Thanks for cluing me in about \_stats. \_ttl is not enabled.
> 
> Before PUT: "count" : 138, "deleted" : 15
> 
> Immediately after PUT: "count": 139, "deleted" : 15  
> A few seconds after PUT: "count" : 138, "deleted" : 15
> 
> On Wednesday, April 3, 2013 3:13:04 PM UTC-4, Igor Motov wrote:
> 
> > Do you have \_ttl enabled by any chance in the mappings for the types  
> > where records disappear?  
> > What happens when you run get several times?  
> > Try running
> > 
> > curl "localhost:9200/app35/\_stats?\*\*pretty=true"
> > 
> > while you index data. What happens to counters in count and deleted?
> > 
> > "indices" : {  
> > "app35" : {  
> > "primaries" : {  
> > "docs" : {  
> > "count" : ????,  
> > "deleted" : ????
> > 
> > On Wednesday, April 3, 2013 12:23:44 PM UTC-4, Dylan Barlett wrote:
> > 
> > > The behavior occurs regardless of the node that data is PUT to.
> > > 
> > > On Wednesday, April 3, 2013 12:18:48 PM UTC-4, Dylan Barlett wrote:
> > > 
> > > > For some of our types, indexing appears to work, but data vanishes a  
> > > > few seconds later. Specifically:
> > > > 
> > > > 1. PUT this data[https://gist.github.com/dbarlett/9695d8180da3aeafa65c](https://gist.github.com/dbarlett/9695d8180da3aeafa65c)to  
> > > > [http://localhost:9200/app35/\*\*template314/212608](http://localhost:9200/app35/**template314/212608)[http://localhost:9200/app35/template314/212608](http://localhost:9200/app35/template314/212608)(via our app or the Head plugin)
> > > > 2. Response:  
> > > > {  
> > > > ok: true  
> > > > \_index: app35  
> > > > \_type: template314  
> > > > \_id: 212608  
> > > > \_version: 1  
> > > > }
> > > > 3. GET [http://localhost:9200/app35/\*\*template314/212608](http://localhost:9200/app35/**template314/212608)[http://localhost:9200/app35/template314/212608](http://localhost:9200/app35/template314/212608)
> > > > 4. Receive expected response[https://gist.github.com/dbarlett/edf7e181f24ed202060f](https://gist.github.com/dbarlett/edf7e181f24ed202060f)
> > > > 5. Wait a few seconds and GET same URL
> > > > 6. Data is gone:{
> > > > 
> > > > "\_index" : "app35",  
> > > > "\_type" : "template314",  
> > > > "\_id" : "212608",  
> > > > "exists" : false  
> > > > }
> > > > 
> > > > Environment:
> > > > 
> > > > - es 0.20.5
> > > > - JVM 1.7.0\_17 64-bit
> > > > - Window Server 2008 R2 64-bit
> > > > - Four cluster nodes (2 frontends with node.data: false and Jetty  
> > > > plugin, 2 backends with node.data: true, all have node.master: true)
> > > > 
> > > > There are no error messages in the logs, and other data is retained  
> > > > indefintely. We haven't found any meaningful distinction between data that  
> > > > stays and data that vanishes. Has anyone seen this before?
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google Groups  
> > > "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send an  
> > > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 4, 2013, 7:05am UTC](https://discuss.elastic.co/t/data-vanishes-a-few-seconds-after-indexing/11432/6 "2013-04-04T07:05:39Z")

</div>

Can you try to GET the document from a backend data node instead of frontend node?

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr | @scrutmydocs

Le 4 avr. 2013 à 08:21, Alexander Reelsen [alr@spinscale.de](mailto:alr@spinscale.de) a écrit :

> Hey,
> 
> very strange problem. Can you reduce complexity and still reproduce this behaviour?  
> Does this happen, when you only use one node?  
> Can you remove all plugins to ensure this is a barebones elasticsearch problem?
> 
> I dont use windows. Are there any mechanisms preventing it to open more files/file descriptors at some stage?
> 
> Last question: Is the document searchable at any time or are you only able to GET it (which means it might not yet be indexed for search)?
> 
> On Wed, Apr 3, 2013 at 9:39 PM, Dylan Barlett [dylan.barlett@gmail.com](mailto:dylan.barlett@gmail.com) wrote:  
> Thanks for cluing me in about \_stats. \_ttl is not enabled.
> 
> Before PUT: "count" : 138, "deleted" : 15  
> Immediately after PUT: "count": 139, "deleted" : 15  
> A few seconds after PUT: "count" : 138, "deleted" : 15
> 
> On Wednesday, April 3, 2013 3:13:04 PM UTC-4, Igor Motov wrote:  
> Do you have \_ttl enabled by any chance in the mappings for the types where records disappear?  
> What happens when you run get several times?  
> Try running
> 
> curl "localhost:9200/app35/\_stats?pretty=true"
> 
> while you index data. What happens to counters in count and deleted?
> 
> "indices" : {  
> "app35" : {  
> "primaries" : {  
> "docs" : {  
> "count" : ????,  
> "deleted" : ????
> 
> On Wednesday, April 3, 2013 12:23:44 PM UTC-4, Dylan Barlett wrote:  
> The behavior occurs regardless of the node that data is PUT to.
> 
> On Wednesday, April 3, 2013 12:18:48 PM UTC-4, Dylan Barlett wrote:  
> For some of our types, indexing appears to work, but data vanishes a few seconds later. Specifically:  
> PUT this data to [http://localhost:9200/app35/template314/212608](http://localhost:9200/app35/template314/212608) (via our app or the Head plugin)  
> Response:  
> {  
> ok: true  
> \_index: app35  
> \_type: template314  
> \_id: 212608  
> \_version: 1  
> }  
> GET [http://localhost:9200/app35/template314/212608](http://localhost:9200/app35/template314/212608)  
> Receive expected response  
> Wait a few seconds and GET same URL  
> Data is gone:{
> 
> "\_index" : "app35",
> 
> "\_type" : "template314",
> 
> "\_id" : "212608",
> 
> "exists" : false  
> }
> 
> Environment:
> 
> es 0.20.5  
> JVM 1.7.0\_17 64-bit  
> Window Server 2008 R2 64-bit  
> Four cluster nodes (2 frontends with node.data: false and Jetty plugin, 2 backends with node.data: true, all have node.master: true)  
> There are no error messages in the logs, and other data is retained indefintely. We haven't found any meaningful distinction between data that stays and data that vanishes. Has anyone seen this before?
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:42am UTC](https://discuss.elastic.co/t/data-vanishes-a-few-seconds-after-indexing/11432/7 "2017-07-06T02:42:50Z")

</div>


