# Elasticsearch giving creating index, cause \[auto(bulk api)\]

**URL:** <https://discuss.elastic.co/t/elasticsearch-giving-creating-index-cause-auto-bulk-api/286560>\
**Category:** Elasticsearch\
**Created:** [October 13, 2021, 2:12am UTC](https://discuss.elastic.co/t/elasticsearch-giving-creating-index-cause-auto-bulk-api/286560 "2021-10-13T02:12:34Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aashish\_Goyal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aashish_goyal/32/78726_2.png) [@Aashish\_Goyal](https://discuss.elastic.co/u/Aashish_Goyal)\
**Post date:** [October 13, 2021, 2:12am UTC](https://discuss.elastic.co/t/elasticsearch-giving-creating-index-cause-auto-bulk-api/286560/1 "2021-10-13T02:12:34Z")

</div>

I am facing issues that old indices are getting created automatically, as I am using fluentd as a log shipper to Elasticsearch. I am facing this issue since 2 days, dig very much for this but no result till now. I delete old indices but again it gets created, even I deleted fluentd also but after deploying it again it creates old indices again. Here are the following info -

Elasticsearch version - 7.8.1 and 7.15.0  
Fluentd version - 1.10.4

I am deploying fluentd as a daemonset into AWS EKS.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 13, 2021, 2:14am UTC](https://discuss.elastic.co/t/elasticsearch-giving-creating-index-cause-auto-bulk-api/286560/2 "2021-10-13T02:14:07Z")

</div>

Welcome to our community! 😃

Please don't post pictures of text or code. They are difficult to read, impossible to search and replicate (if it's code), and some people may not be even able to see them 🙂

---

<div class="post-metadata">

**Author:** ![Aashish\_Goyal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aashish_goyal/32/78726_2.png) [@Aashish\_Goyal](https://discuss.elastic.co/u/Aashish_Goyal)\
**Post date:** [October 13, 2021, 2:15am UTC](https://discuss.elastic.co/t/elasticsearch-giving-creating-index-cause-auto-bulk-api/286560/3 "2021-10-13T02:15:24Z")

</div>

Ok I will take care for next time.

---

<div class="post-metadata">

**Author:** ![Aashish\_Goyal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aashish_goyal/32/78726_2.png) [@Aashish\_Goyal](https://discuss.elastic.co/u/Aashish_Goyal)\
**Post date:** [October 13, 2021, 2:17am UTC](https://discuss.elastic.co/t/elasticsearch-giving-creating-index-cause-auto-bulk-api/286560/4 "2021-10-13T02:17:14Z")

</div>

@warkolm , can you please help me in this issue.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 13, 2021, 2:20am UTC](https://discuss.elastic.co/t/elasticsearch-giving-creating-index-cause-auto-bulk-api/286560/5 "2021-10-13T02:20:12Z")

</div>

I can't read that image, so no sorry.

---

<div class="post-metadata">

**Author:** ![Aashish\_Goyal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aashish_goyal/32/78726_2.png) [@Aashish\_Goyal](https://discuss.elastic.co/u/Aashish_Goyal)\
**Post date:** [October 13, 2021, 2:21am UTC](https://discuss.elastic.co/t/elasticsearch-giving-creating-index-cause-auto-bulk-api/286560/6 "2021-10-13T02:21:45Z")

</div>

I am sharing the logs here -

{"type": "server", "timestamp": "2021-10-13T01:58:11,332Z", "level": "INFO", "component": "o.e.c.m.MetadataCreateIndexService", "cluster.name": "k8s-logs", "node.name": "es-cluster-1", "message": "[logstash-2021.09.13] creating index, cause [auto(bulk api)], templates [qa-es-lifecycle-template], shards [1]/[1], mappings [\_doc]", "cluster.uuid": "Sy35VNmeQ\_mNZZIDq7NKtg", "node.id": "BdPqGKWiTh6MNkpnXtE9FQ" }

{"type": "server", "timestamp": "2021-10-13T01:59:24,658Z", "level": "INFO", "component": "o.e.c.m.MetadataCreateIndexService", "cluster.name": "k8s-logs", "node.name": "es-cluster-1", "message": "[logstash-2021.09.14] creating index, cause [auto(bulk api)], templates [qa-es-lifecycle-template], shards [1]/[1], mappings [\_doc]", "cluster.uuid": "Sy35VNmeQ\_mNZZIDq7NKtg", "node.id": "BdPqGKWiTh6MNkpnXtE9FQ" }

{"type": "server", "timestamp": "2021-10-13T02:08:41,299Z", "level": "INFO", "component": "o.e.c.m.MetadataCreateIndexService", "cluster.name": "k8s-logs", "node.name": "es-cluster-1", "message": "[logstash-2021.09.15] creating index, cause [auto(bulk api)], templates [qa-es-lifecycle-template], shards [1]/[1], mappings [\_doc]", "cluster.uuid": "Sy35VNmeQ\_mNZZIDq7NKtg", "node.id": "BdPqGKWiTh6MNkpnXtE9FQ" }

{"type": "server", "timestamp": "2021-10-13T02:14:36,146Z", "level": "INFO", "component": "o.e.c.m.MetadataCreateIndexService", "cluster.name": "k8s-logs", "node.name": "es-cluster-1", "message": "[logstash-2021.09.16] creating index, cause [auto(bulk api)], templates [qa-es-lifecycle-template], shards [1]/[1], mappings [\_doc]", "cluster.uuid": "Sy35VNmeQ\_mNZZIDq7NKtg", "node.id": "BdPqGKWiTh6MNkpnXtE9FQ" }

{"type": "server", "timestamp": "2021-10-13T02:20:37,327Z", "level": "INFO", "component": "o.e.c.m.MetadataCreateIndexService", "cluster.name": "k8s-logs", "node.name": "es-cluster-1", "message": "[logstash-2021.09.17] creating index, cause [auto(bulk api)], templates [qa-es-lifecycle-template], shards [1]/[1], mappings [\_doc]", "cluster.uuid": "Sy35VNmeQ\_mNZZIDq7NKtg", "node.id": "BdPqGKWiTh6MNkpnXtE9FQ" }

---

<div class="post-metadata">

**Author:** ![Aashish\_Goyal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aashish_goyal/32/78726_2.png) [@Aashish\_Goyal](https://discuss.elastic.co/u/Aashish_Goyal)\
**Post date:** [October 13, 2021, 2:25am UTC](https://discuss.elastic.co/t/elasticsearch-giving-creating-index-cause-auto-bulk-api/286560/7 "2021-10-13T02:25:02Z")

</div>

@warkolm , can you help me now as I have shared proper logs here.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 13, 2021, 2:29am UTC](https://discuss.elastic.co/t/elasticsearch-giving-creating-index-cause-auto-bulk-api/286560/8 "2021-10-13T02:29:20Z")

</div>

I'm not super familiar with fluentd, but I believe that it uses a timestamp to figure out which index to send to. I guess it must be receiving data that has that older timestamp, which is why these indices are being created.

---

<div class="post-metadata">

**Author:** ![Aashish\_Goyal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aashish_goyal/32/78726_2.png) [@Aashish\_Goyal](https://discuss.elastic.co/u/Aashish_Goyal)\
**Post date:** [October 13, 2021, 2:32am UTC](https://discuss.elastic.co/t/elasticsearch-giving-creating-index-cause-auto-bulk-api/286560/9 "2021-10-13T02:32:27Z")

</div>

How I can solved this to not get older timestamp logs here?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 13, 2021, 2:57am UTC](https://discuss.elastic.co/t/elasticsearch-giving-creating-index-cause-auto-bulk-api/286560/10 "2021-10-13T02:57:05Z")

</div>

That would be a fluentd question I think.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 10, 2021, 2:57am UTC](https://discuss.elastic.co/t/elasticsearch-giving-creating-index-cause-auto-bulk-api/286560/11 "2021-11-10T02:57:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
