# Failed to delete index

**URL:** <https://discuss.elastic.co/t/failed-to-delete-index/88403>\
**Category:** Elasticsearch\
**Created:** [June 6, 2017, 10:52am UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403 "2017-06-06T10:52:11Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![qin](https://avatars.discourse-cdn.com/v4/letter/q/91b2a8/32.png) [@qin](https://discuss.elastic.co/u/qin)\
**Post date:** [June 6, 2017, 10:52am UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/1 "2017-06-06T10:52:11Z")

</div>

when in a node delete index, this index and from other nodes synchronization

```auto
curl -XDELETE http://192.168.31.25:9292/logstash-task-33091-20170531

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 6, 2017, 11:04am UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/2 "2017-06-06T11:04:51Z")

</div>

I am not sure I understand what you are asking. Did the delete of this index fail? If so, was there an error message or did it just time out?

Based on the name of your index it looks like you have have a lot of indices, which can be very inefficient. How many indices and shards do you have in the cluster? How much data? What is the size of the cluster?

---

<div class="post-metadata">

**Author:** ![qin](https://avatars.discourse-cdn.com/v4/letter/q/91b2a8/32.png) [@qin](https://discuss.elastic.co/u/qin)\
**Post date:** [June 6, 2017, 11:25am UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/3 "2017-06-06T11:25:01Z")

</div>

![](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b5d763345a8c38cbc449b9920c2ebe205bb5ba47.jpg)  
this img is in master

cluster: 2  
index: 278  
shards/cluster: 278

---

<div class="post-metadata">

**Author:** ![qin](https://avatars.discourse-cdn.com/v4/letter/q/91b2a8/32.png) [@qin](https://discuss.elastic.co/u/qin)\
**Post date:** [June 6, 2017, 11:27am UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/4 "2017-06-06T11:27:16Z")

</div>

can you see the picture?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 6, 2017, 11:32am UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/5 "2017-06-06T11:32:53Z")

</div>

Yes, that seems to be a reasonable number of indices. What error do you get? Is there anything in the Elasticsearch logs?

---

<div class="post-metadata">

**Author:** ![qin](https://avatars.discourse-cdn.com/v4/letter/q/91b2a8/32.png) [@qin](https://discuss.elastic.co/u/qin)\
**Post date:** [June 6, 2017, 12:21pm UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/6 "2017-06-06T12:21:14Z")

</div>

nothing...

```auto

[2017-06-06T20:20:00,570][INFO][o.e.c.m.MetaDataCreateIndexService] [es-01] [logstash-task-521874-20170531] creating index, cause [auto(bulk api)], templates [logstash], shards [1]/[1], mappings [_default_]
[2017-06-06T20:20:00,786][INFO][o.e.c.r.a.AllocationService] [es-01] Cluster health status changed from [YELLOW] to [GREEN] (reason: [shards started [[logstash-task-521874-20170531][0]] ...]).
[2017-06-06T20:20:01,415][INFO][o.e.c.m.MetaDataMappingService] [es-01] [logstash-task-521874-20170531/ekwOc4OsRXucCaCjChod7g] create_mapping [logs]

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 6, 2017, 1:11pm UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/7 "2017-06-06T13:11:11Z")

</div>

What was the response from your curl request?

---

<div class="post-metadata">

**Author:** ![qin](https://avatars.discourse-cdn.com/v4/letter/q/91b2a8/32.png) [@qin](https://discuss.elastic.co/u/qin)\
**Post date:** [June 6, 2017, 1:53pm UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/8 "2017-06-06T13:53:08Z")

</div>

```auto
[root@es-01 elasticsearch]# curl -v -XDELETE http://xxx.xxx.25.82:9292/logstash-task-521874-20170531
* About to connect() to xxx.xxx.25.82 port 9292 (#0)
* Trying xxx.xxx.25.82...
* Connected to xxx.xxx.25.82 (xxx.xxx.25.82) port 9292 (#0)
> DELETE /logstash-task-521874-20170531 HTTP/1.1
> User-Agent: curl/7.29.0
> Host: xxx.xxx.25.82:9292
> Accept: */*
> 
< HTTP/1.1 200 OK
< content-type: application/json; charset=UTF-8
< content-length: 21
< 
* Connection #0 to host xxx.xxx.25.82 left intact
{"acknowledged":true}

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 6, 2017, 1:55pm UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/9 "2017-06-06T13:55:38Z")

</div>

That seems to have worked. What do you get if you run `curl http://xxx.xxx.25.82:9292/_cat/indices | grep logstash-task-521874-20170531` ?

---

<div class="post-metadata">

**Author:** ![qin](https://avatars.discourse-cdn.com/v4/letter/q/91b2a8/32.png) [@qin](https://discuss.elastic.co/u/qin)\
**Post date:** [June 6, 2017, 1:58pm UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/10 "2017-06-06T13:58:26Z")

</div>

```auto
[root@es-01 elasticsearch]# curl -v -XDELETE http://10.173.25.82:9292/logstash-task-521874-20170531
* About to connect() to 10.173.25.82 port 9292 (#0)
* Trying 10.173.25.82...
* Connected to 10.173.25.82 (10.173.25.82) port 9292 (#0)
> DELETE /logstash-task-521874-20170531 HTTP/1.1
> User-Agent: curl/7.29.0
> Host: 10.173.25.82:9292
> Accept: */*
> 
< HTTP/1.1 200 OK
< content-type: application/json; charset=UTF-8
< content-length: 21
< 
* Connection #0 to host 10.173.25.82 left intact
{"acknowledged":true}[root@es-01 elasticsearch]# 
[root@es-01 elasticsearch]# curl http://10.173.25.82:9292/_cat/indices | grep logstash-task-521874-20170531        
  % Total % Received % Xferd Average Speed Time Time Time Current
                                 Dload Upload Total Spent Left Speed
100 25676 100 25676 0 0 106k 0 --:--:-- --:--:-- --:--:-- 106k
green open logstash-task-521874-20170531 3FQrGE4qRjCVS-ZEuJUhow 1 1 223 0 133.1kb 66.4kb

```

---

<div class="post-metadata">

**Author:** ![qin](https://avatars.discourse-cdn.com/v4/letter/q/91b2a8/32.png) [@qin](https://discuss.elastic.co/u/qin)\
**Post date:** [June 6, 2017, 2:06pm UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/11 "2017-06-06T14:06:48Z")

</div>

In addition to logstash index in this cluster, there are other indices. other indices can be deleted

---

<div class="post-metadata">

**Author:** ![qin](https://avatars.discourse-cdn.com/v4/letter/q/91b2a8/32.png) [@qin](https://discuss.elastic.co/u/qin)\
**Post date:** [June 6, 2017, 2:10pm UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/12 "2017-06-06T14:10:02Z")

</div>

**this logstash's template**

```auto
{
    "template": "logstash-*",
    "settings": {
      "index.number_of_shards" : 1,  
      "number_of_replicas" : 1,  
      "index": {
        "refresh_interval": "5s"
      }
    },
    "mappings": {
      "_default_": {
        "dynamic_templates": [
          {
            "message_field": {
              "path_match": "message",
              "mapping": {
                "norms": false,
                "type": "text"
              },
              "match_mapping_type": "string"
            }
          },
          {
            "string_fields": {
              "mapping": {
                "norms": false,
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword"
                  }
                }
              },
              "match_mapping_type": "string",
              "match": "*"
            }
          }
        ],
        "_all": {
          "norms": false,
          "enabled": true
        },
        "properties": {
          "@timestamp": {
            "include_in_all": false,
            "type": "date"
          },
          "geoip": {
            "dynamic": true,
            "properties": {
              "ip": {
                "type": "ip"
              },
              "latitude": {
                "type": "half_float"
              },
              "location": {
                "type": "geo_point"
              },
              "longitude": {
                "type": "half_float"
              }
            }
          },
          "@version": {
            "include_in_all": false,
            "type": "keyword"
          }
        }
      }
    },
    "aliases": {}
}

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 6, 2017, 2:52pm UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/13 "2017-06-06T14:52:47Z")

</div>

Do you have anything indexing into this index, which would cause it to be recreated? Does it have the same hash identifier before and after deleting it? Is there anything in the Elasticsearch logs about this index? What do you get if you run `curl http://10.173.25.82:9292/_cat/nodes` ?

---

<div class="post-metadata">

**Author:** ![qin](https://avatars.discourse-cdn.com/v4/letter/q/91b2a8/32.png) [@qin](https://discuss.elastic.co/u/qin)\
**Post date:** [June 7, 2017, 1:41am UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/14 "2017-06-07T01:41:08Z")

</div>

```auto
[root@cc ~]# curl http://10.173.25.82:9292/_cat/nodes
10.173.25.82 64 96 77 1.23 1.33 1.39 mdi * es-01
10.44.13.39 59 95 46 1.26 1.94 2.17 di - es-02

```

No any other exception，the picture above shows the operation is continuous, these indices also didn't do other operations

---

<div class="post-metadata">

**Author:** ![qin](https://avatars.discourse-cdn.com/v4/letter/q/91b2a8/32.png) [@qin](https://discuss.elastic.co/u/qin)\
**Post date:** [June 7, 2017, 2:10am UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/15 "2017-06-07T02:10:42Z")

</div>

well, We have cleaning indices‘s program, I found that can normal cleaning in the morning today.  
**however, why?**

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 7, 2017, 3:42am UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/16 "2017-06-07T03:42:47Z")

</div>

If they are returning after a delete, then Logstash is recreating them because it is receiving data that it sees should be in that index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 3:42am UTC](https://discuss.elastic.co/t/failed-to-delete-index/88403/17 "2017-07-05T03:42:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
