# ES are creating indexes for a year ago

**URL:** <https://discuss.elastic.co/t/es-are-creating-indexes-for-a-year-ago/70942>\
**Category:** Elasticsearch\
**Created:** [January 9, 2017, 12:36pm UTC](https://discuss.elastic.co/t/es-are-creating-indexes-for-a-year-ago/70942 "2017-01-09T12:36:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![it2](https://avatars.discourse-cdn.com/v4/letter/i/f14d63/32.png) [@it2](https://discuss.elastic.co/u/it2)\
**Post date:** [January 9, 2017, 12:36pm UTC](https://discuss.elastic.co/t/es-are-creating-indexes-for-a-year-ago/70942/1 "2017-01-09T12:36:26Z")

</div>

Hi there.  
I have ES 1.7.5 cluster with 8 nodes.  
After the New Year, I see that there are indexes like logstash- **2016**.01.04,logstash- **2016**.01.05,logstash- **2016**.01.06 etc  
And they have some data about 200mb.  
They were created on the same day but in the year ahead  
How to understand who is creating them ?  
I see nothing in log file ☹

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 9, 2017, 12:39pm UTC](https://discuss.elastic.co/t/es-are-creating-indexes-for-a-year-ago/70942/2 "2017-01-09T12:39:28Z")

</div>

Well, what's in the indexes? And what version of Logstash are you using?

---

<div class="post-metadata">

**Author:** ![it2](https://avatars.discourse-cdn.com/v4/letter/i/f14d63/32.png) [@it2](https://discuss.elastic.co/u/it2)\
**Post date:** [January 9, 2017, 12:54pm UTC](https://discuss.elastic.co/t/es-are-creating-indexes-for-a-year-ago/70942/3 "2017-01-09T12:54:31Z")

</div>

I'm using Logstash 1.5.2  
and how can I watch data in the index? Sorry, I dont know(

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 9, 2017, 1:02pm UTC](https://discuss.elastic.co/t/es-are-creating-indexes-for-a-year-ago/70942/4 "2017-01-09T13:02:18Z")

</div>

> I'm using Logstash 1.5.2

Then it's most likely the bug below which was fixed in v2.1.0 of the date filter. I haven't looked in which Logstash release that version was included, but Logstash 1.5.2 is definitely too old to include it.

> <https://github.com/logstash-plugins/logstash-filter-date/issues/3>
>
> In logstash-filter-date/lib/logstash/filters/date.rb, this line (163 at the mome…nt):
> 
> \`\`\`
> joda\_parser = org.joda.time.format.DateTimeFormat.forPattern(format).withDefaultYear(Time.new.year)
> \`\`\`
> 
> will cause a problem when current year rolls over, because the filter will continue using the default year based on when the daemon was originally started, and not the current year.

> and how can I watch data in the index?

You're not using Kibana?

---

<div class="post-metadata">

**Author:** ![it2](https://avatars.discourse-cdn.com/v4/letter/i/f14d63/32.png) [@it2](https://discuss.elastic.co/u/it2)\
**Post date:** [January 9, 2017, 1:08pm UTC](https://discuss.elastic.co/t/es-are-creating-indexes-for-a-year-ago/70942/5 "2017-01-09T13:08:56Z")

</div>

))))  
Im using Kibana but I cant found timestamps for 2016 year.)  
So my way is upgrading logstash ?  
Is logstash 2.x works correctly with ES 1.7 ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 9, 2017, 1:27pm UTC](https://discuss.elastic.co/t/es-are-creating-indexes-for-a-year-ago/70942/6 "2017-01-09T13:27:27Z")

</div>

> Im using Kibana but I cant found timestamps for 2016 year.)

Are you saying that you don't get any hits if you select 2016-01-01 to 2016-01-10 as the date range in Kibana?

You can of course also use Elasticsearch's REST API to inspect the contents of indexes.

> So my way is upgrading logstash ?

To fix the problem permanently, yes. For now you can just restart Logstash and it'll snap back to 2017, but the problem will return every new year.

> Is logstash 2.x works correctly with ES 1.7 ?

Yes: [Support Matrix | Elastic](https://www.elastic.co/support/matrix#show_compatibility)

---

<div class="post-metadata">

**Author:** ![it2](https://avatars.discourse-cdn.com/v4/letter/i/f14d63/32.png) [@it2](https://discuss.elastic.co/u/it2)\
**Post date:** [January 9, 2017, 1:38pm UTC](https://discuss.elastic.co/t/es-are-creating-indexes-for-a-year-ago/70942/7 "2017-01-09T13:38:14Z")

</div>

Magnus, sorry, my bad.  
I really see messages when choose the correct timerange.  
And it's time to upgrade my cluster. Thank you for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2017, 1:38pm UTC](https://discuss.elastic.co/t/es-are-creating-indexes-for-a-year-ago/70942/8 "2017-02-06T13:38:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
