# Elasticsearch Cluster health is yellow

**URL:** <https://discuss.elastic.co/t/elasticsearch-cluster-health-is-yellow/45780>\
**Category:** Elasticsearch\
**Created:** [March 30, 2016, 11:08am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-yellow/45780 "2016-03-30T11:08:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mshar039](https://avatars.discourse-cdn.com/v4/letter/m/47e85d/32.png) [@mshar039](https://discuss.elastic.co/u/mshar039)\
**Post date:** [March 30, 2016, 11:08am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-yellow/45780/1 "2016-03-30T11:08:22Z")

</div>

My elasticsearch cluster "graylog2" health status is showing yellow, but in web-interface it is showing green.

I could see the following lines in Graylog web-interface.

"1 indices with a total of 26 messages under management, current write-active index is graylog2\_0.

Elasticsearch cluster is green. Shards: 1 active, 0 initializing, 0 relocating, 0 unassigned"

[http://127.0.0.1:9200/\_cluster/health?pretty=true](http://127.0.0.1:9200/_cluster/health?pretty=true)  
{  
"cluster\_name" : "graylog2",  
"status" : "yellow",  
"timed\_out" : false,  
"number\_of\_nodes" : 2,  
"number\_of\_data\_nodes" : 1,  
"active\_primary\_shards" : 6,  
"active\_shards" : 6,  
"relocating\_shards" : 0,  
"initializing\_shards" : 0,  
"unassigned\_shards" : 5,  
"delayed\_unassigned\_shards" : 0,  
"number\_of\_pending\_tasks" : 0,  
"number\_of\_in\_flight\_fetch" : 0  
}

[http://127.0.0.1:9200/\_cat/indices?v](http://127.0.0.1:9200/_cat/indices?v)  
health status index pri rep docs.count docs.deleted store.size pri.store.size  
yellow open logstash-2016.03.17 5 1 27 0 37.4kb 37.4kb  
green open graylog2\_0 1 0 26 0 24.7kb 24.7kb

Can anyone please answer some of my questions

1. why logstash index status is yellow even with a very little data in it?
2. why the elasticsearch cluster's health is yellow?
3. How to fix it.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 30, 2016, 11:23am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-yellow/45780/2 "2016-03-30T11:23:12Z")

</div>

You only have one data node and your logstash-2016.03.17 index has one replica. Those replica shards can never get allocated since primary and replica shards can't reside on the same node. You either need two data nodes or you need to reduce the number of replicas to zero.

---

<div class="post-metadata">

**Author:** ![mshar039](https://avatars.discourse-cdn.com/v4/letter/m/47e85d/32.png) [@mshar039](https://discuss.elastic.co/u/mshar039)\
**Post date:** [March 30, 2016, 12:21pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-yellow/45780/3 "2016-03-30T12:21:00Z")

</div>

Thanks for the reply @magnusbaeck.  
I tried reducing the number of replicas to zero using the setting in elasticsearch.yml.  
index.number\_of\_replicas: 0 and restarted the elasticsearch service.

But still on checking the indices, logstash index is showing configured replica shards as 1.  
How to tell logstash that the number of replica shards is 0 now?

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 30, 2016, 12:25pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-yellow/45780/4 "2016-03-30T12:25:31Z")

</div>

The setting in elasticsearch.yml only affects the default number of replicas. It won't change the number of replicas that existing indexes have. You need to use the [index settings update API](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-update-settings.html).

---

<div class="post-metadata">

**Author:** ![mshar039](https://avatars.discourse-cdn.com/v4/letter/m/47e85d/32.png) [@mshar039](https://discuss.elastic.co/u/mshar039)\
**Post date:** [April 4, 2016, 6:27am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-yellow/45780/5 "2016-04-04T06:27:11Z")

</div>

Thanks for the help @magnusbaeck. Wanted to know one more thing..  
In the graylog/server/server.conf, the settings for graylog node is as follows by default.

#we don't want the graylog2 server to store any data, or be master node  
#elasticsearch\_node\_master = false  
#elasticsearch\_node\_data = false

i.e. this node would not store any data in it.  
So, how is it that graylog2\_0 index has some documents in its shard?

Please help me!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 4, 2016, 7:11am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-yellow/45780/6 "2016-04-04T07:11:30Z")

</div>

I don't know anything about Graylog. Does it run its own ES node that's connected to your cluster? I'm assuming yes.

> So, how is it that graylog2\_0 index has some documents in its shard?

Whether the ES node that's part of Graylog stores any data has nothing to do with the presence of the graylog2\_0 index or whether it contains any data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:02pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-yellow/45780/7 "2017-07-05T23:02:44Z")

</div>


