# Find the cause of document deletes

**URL:** <https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743>\
**Category:** Elasticsearch\
**Created:** [November 14, 2018, 9:41pm UTC](https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743 "2018-11-14T21:41:08Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [November 14, 2018, 9:41pm UTC](https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743/1 "2018-11-14T21:41:08Z")

</div>

In an elasticsearch 5.x cluster, the team is using day-wise indices and deleting indices that are older than 150 days. However, `GET _cat/indices` shows that `document deletions` are happening for each of the day-wise indices.

```
GET _cat/indices?v&h=health,index,pri,rep,docs.count,docs.deleted,store.size,pri.store.size&s=pri.store.size:desc
 
health index pri rep docs.count docs.deleted store.size pri.store.size
green test-2018.11.06 5 1 15290978 438 34gb 17gb
green test-2018.11.11 5 1 15392110 76 33.8gb 16.9gb
green test-2018.11.10 5 1 15328574 76 33.7gb 16.8gb
green test-2018.11.09 5 1 15320059 44 33.6gb 16.8gb
green test-2018.11.08 5 1 15143309 126 33.3gb 16.6gb
green test-2018.10.03 5 1 15066421 11 33.3gb 16.6gb
green test-2018.10.26 5 1 15032894 45 33.2gb 16.6gb
green test-2018.11.07 5 1 15021818 60 33.1gb 16.5gb
green test-2018.10.17 5 1 14888749 21 33gb 16.5gb
green test-2018.10.10 5 1 14871967 69 33gb 16.5gb

```

Chances are the audit logs may not log everything. How can I know the source/cause that triggers the deletion of these indices?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 14, 2018, 9:54pm UTC](https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743/2 "2018-11-14T21:54:20Z")

</div>

If you are specifying document ids before indexing, updates will show up as deletes.

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [November 15, 2018, 1:26pm UTC](https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743/3 "2018-11-15T13:26:14Z")

</div>

Hi @Christian_Dahlqvist, can you help me reproduce it?

I created a test index and indexed a document into it using the following:

```
PUT test_index/test_type/1
{
  "name" : "Elastic"
}

```

`GET _cat/indices/test_index` shows

```
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
green open test_index jnzP2XyaSAy8y0dg0QOq0A 5 0 1 0 3.9kb 3.9kb

```

Next, wrote a small script to update it `100` times.

```
#!/bin/bash
max=100
for i in `seq 1 $max`; do
	curl -u elastic:changeme -XPOST "http://localhost:9200/test_index/test_type/1/_update" -H "Content-Type: application/json" -d"
	{
	  \"doc\": {
	    \"name\" : \"Elastic_${i}\"
	  }
	}"
done

```

Post the update, ran `GET test_index/_search`:

```
{
  "took": 0,
   ....
    "hits": [
      {
        "_index": "test_index",
        "_type": "test_type",
        "_id": "1",
        "_score": 1,
        "_source": {
          "name": "Elastic_100"
        }
      }
    ]
  }
}

```

`GET _cat/indices/test_index?v` still doesn't show any `non-zero` value in `docs.deleted`

```
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
green open test_index jnzP2XyaSAy8y0dg0QOq0A 5 0 1 0 4kb 4kb

```

What could I be missing? This is local ES 5.x cluster on my macbook

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [November 15, 2018, 3:02pm UTC](https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743/4 "2018-11-15T15:02:54Z")

</div>

Able to reproduce it now @Christian_Dahlqvist. What I did was instead of just `1` document, indexed `1000` documents.

And then updated `300` documents. The `docs.deleted` showed `20`. Then updated `100` more documents. `docs.deleted` showed `120`.

```
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
green open test_index jnzP2XyaSAy8y0dg0QOq0A 5 0 1000 120 338.8kb 338.8kb

```

Could you kindly explain:

- 
  1. Why indexing more documents, I could reproduce it?

- 
  1. After indexing 1000 documents:  
a. When I updated just `3` docs, `docs.deleted` showed `2` (id 1 to 3)  
b. When I updated `300` docs, `docs.deleted` showed `20` (id 1 to 300)  
c. When I updated `100` docs, `docs.deleted` showed `120`(id 300 to 400)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 15, 2018, 3:09pm UTC](https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743/5 "2018-11-15T15:09:44Z")

</div>

I believe it depends on how segments are merged in the background. Once deleted documents have been merged out as segments are merged they should no longer show up in statistics.

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [November 15, 2018, 4:48pm UTC](https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743/6 "2018-11-15T16:48:49Z")

</div>

Thanks. That pretty much explains. But how come that I could only reproduce it after I added sizeable no of docs (`1000` in this case). Why I couldn't reproduce it with just 1 doc and updating that one doc 100,1000, 3000 times also didn't show any value in `docs.deleted`? Can you shed some light on this?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 15, 2018, 4:50pm UTC](https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743/7 "2018-11-15T16:50:08Z")

</div>

It might be that a small amount of documents cause merging to happen quicker.

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [November 15, 2018, 4:50pm UTC](https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743/8 "2018-11-15T16:50:47Z")

</div>

Thanks @Christian_Dahlqvist for all your help and support!

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [November 15, 2018, 5:09pm UTC](https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743/9 "2018-11-15T17:09:36Z")

</div>

As expected, running `POST test_index/_forcemerge?max_num_segments=1` resets the `docs.deleted` to `0`.

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [November 19, 2018, 2:44pm UTC](https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743/10 "2018-11-19T14:44:28Z")

</div>

@Christian_Dahlqvist - an update. Turns out that for the scenario, there are `NO UPDATES` happening. This is metric data thus no updates. So why does `docs.deleted` count show non-zero? Due to `segment merging` and `segment deletions`?

If that's so, then for another ES 5.5.x cluster, I've day-wise indices and for all of them, `docs.deleted` shows `0`.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 19, 2018, 3:02pm UTC](https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743/11 "2018-11-19T15:02:53Z")

</div>

Elasticsearch does not delete documents automatically. If you are specifying the document ID before indexing, it could be updates due to retries at the indexing layer.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2018, 3:02pm UTC](https://discuss.elastic.co/t/find-the-cause-of-document-deletes/156743/12 "2018-12-17T15:02:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
