# Deleting Elasticsearch indices without breaking Kibana visualizations

**URL:** <https://discuss.elastic.co/t/deleting-elasticsearch-indices-without-breaking-kibana-visualizations/249872>\
**Category:** Kibana\
**Tags:** ilm-index-lifecycle-management\
**Created:** [September 24, 2020, 6:59pm UTC](https://discuss.elastic.co/t/deleting-elasticsearch-indices-without-breaking-kibana-visualizations/249872 "2020-09-24T18:59:47Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![helenp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helenp/32/76176_2.png) [@helenp](https://discuss.elastic.co/u/helenp)\
**Post date:** [September 24, 2020, 6:59pm UTC](https://discuss.elastic.co/t/deleting-elasticsearch-indices-without-breaking-kibana-visualizations/249872/1 "2020-09-24T18:59:47Z")

</div>

Hello,

How do you prevent Kibana visualizations from breaking due to deleted indices (as described in [this thread](https://discuss.elastic.co/t/kibana-visualizations-broken-after-deleting-index-pattern-modifying-object-does-not-work/237088))? I deleted some of my indices in Elasticsearch and afterwards saw the _missing index pattern_ error in each visualization in my Kibana dashboard. I found the easiest way to resolve the errors was to export and import the visualizations, but I am hoping there is a proper way to delete the indices.

Thanks.

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [September 24, 2020, 7:38pm UTC](https://discuss.elastic.co/t/deleting-elasticsearch-indices-without-breaking-kibana-visualizations/249872/2 "2020-09-24T19:38:51Z")

</div>

One thing you might consider if you aren't doing this already is using [index aliases](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-add-alias.html) and building your visualizations & index patterns based off of those.

An index alias will let you point to one or more underlying "concrete" indices, and you can update an alias at any time to add/remove the backing indices it represents.

Assuming the indices backing your alias aren't removing the fields your visualizations rely on, you should be able to delete them behind the scenes without visualizations knowing anything has changed.

---

<div class="post-metadata">

**Author:** ![helenp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helenp/32/76176_2.png) [@helenp](https://discuss.elastic.co/u/helenp)\
**Post date:** [September 24, 2020, 8:14pm UTC](https://discuss.elastic.co/t/deleting-elasticsearch-indices-without-breaking-kibana-visualizations/249872/3 "2020-09-24T20:14:43Z")

</div>

Thanks for responding. I'll try using an index alias, but I didn't delete the index pattern, just a subset of the indices that followed the pattern, so I'm not clear on why the particular error (i.e., _Could not locate that index-pattern (id: ...), click here to re-create it_) I mentioned displayed on all of my visualizations. This sounds like a bug because I would expect the data associated with the remaining indices to display for the visualizations.

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [September 24, 2020, 8:41pm UTC](https://discuss.elastic.co/t/deleting-elasticsearch-indices-without-breaking-kibana-visualizations/249872/4 "2020-09-24T20:41:17Z")

</div>

> [@helenp](#):
>
> I didn't delete the index pattern, just a subset of the indices that followed the pattern

Ah interesting -- then yes in that case I would expect it to still work.

After testing this a bit, I'm having trouble reproducing the issue you describe. Here's what I'm doing; let me know if it lines up with what you did:

```auto
PUT /logs-a

PUT /logs-b

POST /logs-a/_doc
{
  "hello": "world"
}

POST /logs-b/_doc
{
  "hello": "universe"
}

PUT /logs-a/_alias/c

PUT /logs-b/_alias/c

```

So now we have indices `logs-a` and `logs-b`. I also created an alias `c` which points to these indices for testing purposes.

Then I created two index patterns: `logs-*` and `c`.

Next I created and saved a visualization & dashboard for each index pattern (simple datatable doing a terms aggregation on `hello.keyword`).

Then I deleted `logs-b`:

```auto
DELETE /logs-b

```

Afterwards, I opened all of the dashboards & visualizations, and everything worked. Refreshed the fields in both index patterns; everything still worked.

What am I missing to make thie error happen?

In the thread you point to about visualizations breaking due to deleted indices, the OP wasn't experiencing problems because the indices were deleted per se, but rather because a new index pattern was created later (with a new ID).

Assuming you don't delete & recreate an index pattern, I would expect everything to continue working, even when an index is deleted.

---

<div class="post-metadata">

**Author:** ![helenp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helenp/32/76176_2.png) [@helenp](https://discuss.elastic.co/u/helenp)\
**Post date:** [September 24, 2020, 9:19pm UTC](https://discuss.elastic.co/t/deleting-elasticsearch-indices-without-breaking-kibana-visualizations/249872/5 "2020-09-24T21:19:02Z")

</div>

The main difference, I am guessing, is that I didn't manually create the indices, they were automatically created in Elasticsearch (in AWS.) In Kibana, under Dev Tools, I just deleted a a few of the indices using:

`DELETE /index-name`

And when I loaded the dashboard, that's when I saw the error in each visualization.

I added the index alias, but I will have to wait until next week to attempt another index deletion and will let you know. Do I need to set the Default index (`defaultIndex`) to the alias' ID, as well?

Thanks.

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [September 24, 2020, 9:40pm UTC](https://discuss.elastic.co/t/deleting-elasticsearch-indices-without-breaking-kibana-visualizations/249872/6 "2020-09-24T21:40:57Z")

</div>

> [@helenp](#):
>
> Do I need to set the Default index ( `defaultIndex` ) to the alias' ID, as well?

No you shouldn't -- in my test cases I had a different default index and everything still worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2020, 9:41pm UTC](https://discuss.elastic.co/t/deleting-elasticsearch-indices-without-breaking-kibana-visualizations/249872/7 "2020-10-22T21:41:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
