# Elasticsearch restart deleted all indices

**URL:** <https://discuss.elastic.co/t/elasticsearch-restart-deleted-all-indices/17829>\
**Category:** Elasticsearch\
**Created:** [May 30, 2014, 9:07am UTC](https://discuss.elastic.co/t/elasticsearch-restart-deleted-all-indices/17829 "2014-05-30T09:07:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![erbdex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erbdex/32/1520_2.png) [@erbdex](https://discuss.elastic.co/u/erbdex)\
**Post date:** [May 30, 2014, 9:07am UTC](https://discuss.elastic.co/t/elasticsearch-restart-deleted-all-indices/17829/1 "2014-05-30T09:07:42Z")

</div>

1. When i restarted a node yesterday, this happened (logs follow)-
2. i lost 96 days worth of my logs. df before and after the restart  
indicated that i had lost ~260G of indices post install.
3. After this, the node started syncing logs from the very beginning from  
the rest of the cluster.
4. Specs- Elasticsearch 1.1.1 on Amazon aws. i use aws-cloud plugin for  
node discovery.

What could have caused this?

[2014-05-29 13:35:37,824][INFO][node] [Pyro]  
version[1.1.1], pid[4005], build[f1585f0/2014-04-16T14:27:12Z]  
[2014-05-29 13:35:37,824][INFO][node] [Pyro]  
initializing ...  
[2014-05-29 13:35:37,851][INFO][plugins] [Pyro] loaded  
[river-jdbc, cloud-aws], sites [whatson, head, bigdesk, paramedic]  
[2014-05-29 13:35:41,166][INFO][node] [Pyro]  
initialized  
[2014-05-29 13:35:41,167][INFO][node] [Pyro] starting  
...  
[2014-05-29 13:35:41,306][INFO][transport] [Pyro]  
bound\_address {inet[/0:0:0:0:0:0:0:0:9300]}, publish\_address  
{inet[/10.0.0.135:9300]}  
[2014-05-29 13:35:45,802][INFO][cluster.service] [Pyro]  
new\_master  
[Pyro][sWs8aTYHSx-j-ywO45vQ1Q][ip-10-0-0-135][inet[/10.0.0.135:9300]],  
reason: zen-disco-join (elected\_as\_master)  
[2014-05-29 13:35:45,826][INFO][discovery] [Pyro]  
jarvis/sWs8aTYHSx-j-ywO45vQ1Q  
[2014-05-29 13:35:46,019][INFO][http] [Pyro]  
bound\_address {inet[/0:0:0:0:0:0:0:0:9200]}, publish\_address  
{inet[/10.0.0.135:9200]}  
[2014-05-29 13:35:47,328][INFO][gateway] [Pyro] _recovered  
[96] indices into cluster\_state_  
[2014-05-29 13:35:47,335][INFO][node] [Pyro] started  
[2014-05-29 13:36:03,102][INFO][node] [Pyro] stopping  
...  
[2014-05-29 13:36:03,401][WARN][cluster.service] [Pyro] failed  
to apply updated cluster state:  
version [109], source [shard-started ([logstash-2014.02.27][4],  
node[sWs8aTYHSx-j-ywO45vQ1Q], [P], s[INITIALIZING]), reason [after recovery  
from gateway]]  
nodes:  
[Pyro][sWs8aTYHSx-j-ywO45vQ1Q][ip-10-0-0-135][inet[/10.0.0.135:9300]],  
local, master  
routing\_table:  
-- index [logstash-2014.03.22]  
----shard\_id [logstash-2014.03.22][4]  
--------[logstash-2014.03.22][4], node[sWs8aTYHSx-j-ywO45vQ1Q], [P],  
s[STARTED]  
--------[logstash-2014.03.22][4], node[null], [R], s[UNASSIGNED]  
----shard\_id [logstash-2014.03.22][0]  
--------[logstash-2014.03.22][0], node[null], [P], s[UNASSIGNED]  
--------[logstash-2014.03.22][0], node[null], [R], s[UNASSIGNED]  
----shard\_id [logstash-2014.03.22][3]  
--------[logstash-2014.03.22][3], node[null], [P], s[UNASSIGNED]  
--------[logstash-2014.03.22][3], node[null], [R], s[UNASSIGNED]  
----shard\_id [logstash-2014.03.22][1]  
--------[logstash-2014.03.22][1], node[sWs8aTYHSx-j-ywO45vQ1Q], [P],  
s[STARTED]  
--------[logstash-2014.03.22][1], node[null], [R], s[UNASSIGNED]  
----shard\_id [logstash-2014.03.22][2]  
--------[logstash-2014.03.22][2], node[sWs8aTYHSx-j-ywO45vQ1Q], [P],  
s[STARTED]  
--------[logstash-2014.03.22][2], node[null], [R], s[UNASSIGNED]

-- index [logstash-2014.03.21]  
----shard\_id [logstash-2014.03.21][2]  
--------[logstash-2014.03.21][2], node[sWs8aTYHSx-j-ywO45vQ1Q], [P],  
s[STARTED]  
--------[logstash-2014.03.21][2], node[null], [R], s[UNASSIGNED]  
----shard\_id [logstash-2014.03.21][0]  
--------[logstash-2014.03.21][0], node[null], [P], s[UNASSIGNED]  
--------[logstash-2014.03.21][0], node[null], [R], s[UNASSIGNED]  
----shard\_id [logstash-2014.03.21][3]  
--------[logstash-2014.03.21][3], node[sWs8aTYHSx-j-ywO45vQ1Q], [P],  
s[STARTED]  
--------[logstash-2014.03.21][3], node[null], [R], s[UNASSIGNED]  
----shard\_id [logstash-2014.03.21][1]  
--------[logstash-2014.03.21][1], node[null], [P], s[UNASSIGNED]  
--------[logstash-2014.03.21][1], node[null], [R], s[UNASSIGNED]  
----shard\_id [logstash-2014.03.21][4]  
--------[logstash-2014.03.21][4], node[sWs8aTYHSx-j-ywO45vQ1Q], [P],  
s[STARTED]  
--------[logstash-2014.03.21][4], node[null], [R], s[UNASSIGNED]

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/66b1c0f6-400c-4d57-82e9-c1704cc5ade4%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/66b1c0f6-400c-4d57-82e9-c1704cc5ade4%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:25am UTC](https://discuss.elastic.co/t/elasticsearch-restart-deleted-all-indices/17829/2 "2017-07-06T01:25:52Z")

</div>


