# ELK Container Restores Old Index

**URL:** <https://discuss.elastic.co/t/elk-container-restores-old-index/196446>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [August 23, 2019, 5:22am UTC](https://discuss.elastic.co/t/elk-container-restores-old-index/196446 "2019-08-23T05:22:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![VicXue](https://avatars.discourse-cdn.com/v4/letter/v/a9a28c/32.png) [@VicXue](https://discuss.elastic.co/u/VicXue)\
**Post date:** [August 23, 2019, 5:22am UTC](https://discuss.elastic.co/t/elk-container-restores-old-index/196446/1 "2019-08-23T05:22:56Z")

</div>

I'm currently using this docker container (v7.2.1 [source](https://hub.docker.com/r/sebp/elk/)) to monitor my dockerized .Net Core 2.1 API. My API has the Serilog.Elasticsearch.Sink installed in order to communicate with the ELK container. I ran these two containers on different VMs using host network and they can be accessed by all machines in the local network. They were able to communicate with each other at the beginning. However, after I tried to debug my API in Visual Studio using IIS and connected it with the ELK, the ELK container start malfunctioning. I used `docker system prune -a -f` in order to reset everything, but for some reason the ELK container still managed to restore old logstash index whenever I try to connect it with either my API container or IIS service. Also, it stops receiving new logging data from both container and IIS service. I used `REST request URI http://IP-To-ELK:9200/_search?pretty` to inspect and sometimes the hit count increases but only old data from time period in the past shows up in the Discover panel.

I'm new to ELK and I'm not sure what exactly caused this issue. However, if any suggestion in regard to this issue would be appreciated. Additionally, can anyone tell me where the data searched by using the REST request URI is located and why ELK container is able to retrieve it even after a 'docker system prune'?

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [August 30, 2019, 1:41pm UTC](https://discuss.elastic.co/t/elk-container-restores-old-index/196446/2 "2019-08-30T13:41:39Z")

</div>

Is it possible that you stored actual index data outside of the container as described [here](https://elk-docker.readthedocs.io/#persisting-log-data)?

---

<div class="post-metadata">

**Author:** ![VicXue](https://avatars.discourse-cdn.com/v4/letter/v/a9a28c/32.png) [@VicXue](https://discuss.elastic.co/u/VicXue)\
**Post date:** [September 1, 2019, 9:56pm UTC](https://discuss.elastic.co/t/elk-container-restores-old-index/196446/3 "2019-09-01T21:56:22Z")

</div>

It's indeed due to the volume. After a `docker system prune -a -f --volume`, everything is normal again. Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2019, 9:56pm UTC](https://discuss.elastic.co/t/elk-container-restores-old-index/196446/4 "2019-09-29T21:56:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
