# Elastic search Delete API

**URL:** <https://discuss.elastic.co/t/elastic-search-delete-api/135144>\
**Category:** Elasticsearch\
**Created:** [June 8, 2018, 11:52am UTC](https://discuss.elastic.co/t/elastic-search-delete-api/135144 "2018-06-08T11:52:56Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohana01](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@Mohana01](https://discuss.elastic.co/u/Mohana01)\
**Post date:** [June 8, 2018, 11:52am UTC](https://discuss.elastic.co/t/elastic-search-delete-api/135144/1 "2018-06-08T11:52:57Z")

</div>

I am working on ELK development Project.  
When i try to delete the index am getting {acknowledged:true}  
But after sometime the deleted index is getting created automatically.  
Really not sure what is the cause of the problem.  
Am following default settings (Primary shards : 5; replica: 1)  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [June 8, 2018, 3:48pm UTC](https://discuss.elastic.co/t/elastic-search-delete-api/135144/2 "2018-06-08T15:48:37Z")

</div>

Do you have other systems that write into the Elasticsearch cluster? When a document is written to a non-existing / deleted index, the index gets automatically created.

---

<div class="post-metadata">

**Author:** ![Mohana01](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@Mohana01](https://discuss.elastic.co/u/Mohana01)\
**Post date:** [June 11, 2018, 4:47am UTC](https://discuss.elastic.co/t/elastic-search-delete-api/135144/3 "2018-06-11T04:47:25Z")

</div>

Logs are written from file beat only.  
For ex If we have index abc\_15\_03\_2018 ,abc\_16\_03\_2018 .abc\_17\_03\_2018  
we are trying to delete the index abc\_15\_03\_2018 .

---

<div class="post-metadata">

**Author:** ![Mohana01](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@Mohana01](https://discuss.elastic.co/u/Mohana01)\
**Post date:** [June 12, 2018, 11:13am UTC](https://discuss.elastic.co/t/elastic-search-delete-api/135144/4 "2018-06-12T11:13:52Z")

</div>

Hi  
Any solution for this issue.  
Bcz as we are in production deleted index is keep on creating.  
what we thought is it might be bcz of replica 1 .But no luck even after making replica as 0 and created new index but still deleted index is coming back ☹

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [June 14, 2018, 5:19pm UTC](https://discuss.elastic.co/t/elastic-search-delete-api/135144/5 "2018-06-14T17:19:04Z")

</div>

When an index is deleted in Elasticsearch, it does not simply re-appear unless new data is written into it. Replicas shards get deleted together with the primary shards.

Please check if the data you're sending contains timestamps from e.g. 2018-03-15, that would therefore be written to an index containing this date in the index pattern. Filebeat will use the timestamps to determine the index name.

---

<div class="post-metadata">

**Author:** ![Mohana01](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@Mohana01](https://discuss.elastic.co/u/Mohana01)\
**Post date:** [June 19, 2018, 12:28pm UTC](https://discuss.elastic.co/t/elastic-search-delete-api/135144/6 "2018-06-19T12:28:04Z")

</div>

We tried even deleting the index folder from the data path also . After some time index is coming back again.  
When we try deleting the logs which are from (Fluentd --\> Kafka --\> Logstash ---\> ES ) Those index are not creating any issue .  
as we dont have access to stop filebeat , we tried stopping Logstash instance and deleted the indices. Still Indices are recreated.  
We are running ELK stack as docker images

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 19, 2018, 1:31pm UTC](https://discuss.elastic.co/t/elastic-search-delete-api/135144/7 "2018-06-19T13:31:12Z")

</div>

What @Magnus_Kessler said is true. Logstash doesn't _create_ indices. It sends a document through to Elasticsearch with the bulk API instruction of, "Add this document to the index named _blahblah_", and Elasticsearch will create the index if it doesn't exist. The same is true of all of the Beats. If an index is being created, documents are being fed to it from somewhere.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2018, 1:31pm UTC](https://discuss.elastic.co/t/elastic-search-delete-api/135144/8 "2018-07-17T13:31:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
