# Elastsicsearch: Odd Behaviour on Index Deletion

**URL:** <https://discuss.elastic.co/t/elastsicsearch-odd-behaviour-on-index-deletion/237747>\
**Category:** Elasticsearch\
**Created:** [June 19, 2020, 7:15am UTC](https://discuss.elastic.co/t/elastsicsearch-odd-behaviour-on-index-deletion/237747 "2020-06-19T07:15:23Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [June 19, 2020, 7:15am UTC](https://discuss.elastic.co/t/elastsicsearch-odd-behaviour-on-index-deletion/237747/1 "2020-06-19T07:15:24Z")

</div>

Hi,  
I'm running elasticsearch 6.8.6 and am seeing this odd behaviour on deleting an old filebeat index. Here is the log from the master node which shows what's happening:

```auto
[2020-06-19T07:06:30,899][INFO][o.e.c.m.MetaDataDeleteIndexService] [es-master-001] [filebeat-6.8.6-2020.04.20/IHIZKPT6SRCJDQeJVC1jzg] deleting index
[2020-06-19T07:06:38,645][INFO][o.e.c.m.MetaDataCreateIndexService] [es-master-001] [filebeat-6.8.6-2020.04.20] creating index, cause [auto(bulk api)], templates [filebeat-6.8.6], shards [3]/[1], mappings [doc]
[2020-06-19T07:06:39,081][INFO][o.e.c.r.a.AllocationService] [es-master-001] Cluster health status changed from [YELLOW] to [GREEN] (reason: [shards started [[filebeat-6.8.6-2020.04.20][2], [filebeat-6.8.6-2020.04.20][0]] ...]).
[2020-06-19T07:06:39,128][INFO][o.e.c.m.MetaDataMappingService] [es-master-001] [filebeat-6.8.6-2020.04.20/bXCnP4_VRxqmZf4Lag0n1Q] update_mapping [doc]

```

As you can see, the index is being deleted and then reinstated. Even though the index is very old. Also, it is repopulated with the same data. Is this some kind of cluster or shard state issue? How do I gain insight and fix it?

Thx  
D

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [June 19, 2020, 7:16am UTC](https://discuss.elastic.co/t/elastsicsearch-odd-behaviour-on-index-deletion/237747/2 "2020-06-19T07:16:21Z")

</div>

I've tried restarting all of the data nodes but that hasn't fixed it.

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [June 21, 2020, 10:31am UTC](https://discuss.elastic.co/t/elastsicsearch-odd-behaviour-on-index-deletion/237747/3 "2020-06-21T10:31:54Z")

</div>

Would appreciate some feedback on this topic? Index still does not delete, even after a full cluster restart.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 21, 2020, 1:19pm UTC](https://discuss.elastic.co/t/elastsicsearch-odd-behaviour-on-index-deletion/237747/4 "2020-06-21T13:19:34Z")

</div>

How is your cluster configured? Have you got [minimum\_master-nodes set correctly](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/modules-node.html#split-brain)?

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [June 21, 2020, 1:32pm UTC](https://discuss.elastic.co/t/elastsicsearch-odd-behaviour-on-index-deletion/237747/5 "2020-06-21T13:32:33Z")

</div>

`minimum_master_nodes` is set to `2`. We run 3...

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [June 23, 2020, 9:33am UTC](https://discuss.elastic.co/t/elastsicsearch-odd-behaviour-on-index-deletion/237747/6 "2020-06-23T09:33:19Z")

</div>

Any chance of a response from an elastic team member on this please?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [June 23, 2020, 12:02pm UTC](https://discuss.elastic.co/t/elastsicsearch-odd-behaviour-on-index-deletion/237747/7 "2020-06-23T12:02:30Z")

</div>

There is a client indexing into the `filebeat-6.8.6-2020.04.20` index which creates the index if it does not exist.

> [@dawiro](#):
>
> ```auto
> [2020-06-19T07:06:38,645][INFO][o.e.c.m.MetaDataCreateIndexService] [es-master-001] [filebeat-6.8.6-2020.04.20] creating index, cause [auto(bulk api)], templates [filebeat-6.8.6], shards [3]/[1], mappings [doc]
> 
> ```

I don't think there's anything wrong with Elasticsearch here, you'll need to track down that client.

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [June 30, 2020, 9:04am UTC](https://discuss.elastic.co/t/elastsicsearch-odd-behaviour-on-index-deletion/237747/8 "2020-06-30T09:04:50Z")

</div>

Seems there was data being cached by the logstashes. Had to manually clear down persistent queues to fix it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2020, 9:04am UTC](https://discuss.elastic.co/t/elastsicsearch-odd-behaviour-on-index-deletion/237747/9 "2020-07-28T09:04:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
