# How backup delete indices

**URL:** <https://discuss.elastic.co/t/how-backup-delete-indices/275080>\
**Category:** Kibana\
**Created:** [June 6, 2021, 7:20pm UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080 "2021-06-06T19:20:26Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ilya\_21bA](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@Ilya\_21bA](https://discuss.elastic.co/u/Ilya_21bA)\
**Post date:** [June 6, 2021, 7:20pm UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/1 "2021-06-06T19:20:26Z")

</div>

Hi! System indexes were accidentally deleted, name: .kibana, .kibana\_1, .kibana\_task\_manager, .security, .security-7  
Log text on Elasticsearch:

> [2021-06-02T17:44:32,369][DEBUG][o.e.a.s.TransportSearchAction] [AGILEVLG-SRV-23]  
> [.kibana\_task\_manager][0], node[nZb0BalCR1SI3AtEeN8AXg], [P], s[STARTED], a[id=clGtk95-  
> T3W3lIdqD4gUfg]: Failed to execute [SearchRequest{searchType=QUERY\_THEN\_FETCH, indices=[.kibana, .kibana\_1, .kibana\_task\_manager, .security, .security-7, logstash-pikautotesttc, logstash-pikautotesttc12, logstash-pikautotesttc12and5, logstash-pikautotesttc4, logstash-runstatus, logstash-runstatus12, logstash-runstatus12and5, logstash-runstatus4], indicesOptions=IndicesOptions[ignore\_unavailable=false, allow\_no\_indices=true, expand\_wildcards\_open=true, expand\_wildcards\_closed=false, allow\_aliases\_to\_multiple\_indices=true, forbid\_closed\_indices=true, ignore\_aliases=false, ignore\_throttled=true], types=, routing='null', preference='null', requestCache=null, scroll=null, maxConcurrentShardRequests=0, batchedReduceSize=512, preFilterShardSize=128, allowPartialSearchResults=true, localClusterAlias=null, getOrCreateAbsoluteStartMillis=-1, ccsMinimizeRoundtrips=true, source={"size":1,"query":{"query\_string":{"query":"","fields":,"type":"best\_fields","default\_operator":"or","max\_determinized\_states":10000,"enable\_position\_increments":true,"fuzziness":"AUTO","fuzzy\_prefix\_length":0,"fuzzy\_max\_expansions":50,"phrase\_slop":0,"analyze\_wildcard":false,"escape":false,"auto\_generate\_synonyms\_phrase\_query":true,"fuzzy\_transpositions":true,"boost":1.0}},"sort":[{"@timestamp":{"order":"desc"}}]}}] lastShard [true]  
> org.elasticsearch.transport.RemoteTransportException: [AGILEVLG-SRV-23][127.0.0.1:9300][indices:data/read/search[phase/query]]  
> Caused by: org.elasticsearch.index.query.QueryShardException: No mapping found for [@timestamp] in order to sort on  
> at org.elasticsearch.search.sort.FieldSortBuilder.build(FieldSortBuilder.java:319) ~[elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.search.sort.SortBuilder.buildSort(SortBuilder.java:153) ~[elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.search.SearchService.parseSource(SearchService.java:772) ~[elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.search.SearchService.createContext(SearchService.java:608) ~[elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.search.SearchService.createAndPutContext(SearchService.java:583) ~[elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.search.SearchService.executeQueryPhase(SearchService.java:386) ~[elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.search.SearchService.access$100(SearchService.java:124) ~[elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.search.SearchService$2.onResponse(SearchService.java:358) [elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.search.SearchService$2.onResponse(SearchService.java:354) [elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.search.SearchService$4.doRun(SearchService.java:1069) [elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) [elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.common.util.concurrent.TimedRunnable.doRun(TimedRunnable.java:41) [elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingAbstractRunnable.doRun(ThreadContext.java:751) [elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) [elasticsearch-7.1.1.jar:7.1.1]  
> at java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source) [?:1.8.0\_231]  
> at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source) [?:1.8.0\_231]  
> at java.lang.Thread.run(Unknown Source) [?:1.8.0\_231]

LogStash started writing logs every millisecond in this regard the memory on the PC began to fill up, I decided to re-delete the system (.kibana, .kibana\_1, .kibana\_task\_manager, .security, .security-7) current indexes.  
Is it possible to restore them somehow?  
In view of all this, I get an error:

`> "Kibana server is not ready yet"`

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 7, 2021, 1:32am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/2 "2021-06-07T01:32:50Z")

</div>

> [@Ilya\_21bA](#):
>
> Is it possible to restore them somehow?

Did you back them up?

If not, no. You will need to reconfigure Security and restart Kibana and configure your dashboards again.

---

<div class="post-metadata">

**Author:** ![Ilya\_21bA](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@Ilya\_21bA](https://discuss.elastic.co/u/Ilya_21bA)\
**Post date:** [June 7, 2021, 5:37am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/3 "2021-06-07T05:37:49Z")

</div>

Thank you for your answer. Please tell me the algorithm of these actions. I understand correctly what will need to be adjusted .kibana's yml file?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 7, 2021, 5:49am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/4 "2021-06-07T05:49:26Z")

</div>

You don't need to adjust anything in the config, try restarting Kibana and seeing if it creates the indices it needs.

---

<div class="post-metadata">

**Author:** ![Ilya\_21bA](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@Ilya\_21bA](https://discuss.elastic.co/u/Ilya_21bA)\
**Post date:** [June 7, 2021, 5:53am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/5 "2021-06-07T05:53:01Z")

</div>

In this case, indexes are created that are generated in the logstash configuration file, but not the system indexes.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 7, 2021, 5:54am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/6 "2021-06-07T05:54:42Z")

</div>

Right. And to get back the system indices you will need to restart Kibana, and Elasticsearch./

---

<div class="post-metadata">

**Author:** ![Ilya\_21bA](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@Ilya\_21bA](https://discuss.elastic.co/u/Ilya_21bA)\
**Post date:** [June 7, 2021, 5:55am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/7 "2021-06-07T05:55:09Z")

</div>

if I go directly to the address [http://192.168.34.73:5601/](http://192.168.34.73:5601/), error: Kibana server is not ready yet

---

<div class="post-metadata">

**Author:** ![Ilya\_21bA](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@Ilya\_21bA](https://discuss.elastic.co/u/Ilya_21bA)\
**Post date:** [June 7, 2021, 6:01am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/8 "2021-06-07T06:01:07Z")

</div>

the employee issued the command: curl-DELETE [https://elastic-search-host/.kibana\*](https://elastic-search-host/.kibana*),  
I think that's the problem(((((

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 7, 2021, 6:02am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/9 "2021-06-07T06:02:30Z")

</div>

What do your Elasticsearch and Kibana logs show after the restart?

> [@Ilya\_21bA](#):
>
> the employee issued the command: curl-DELETE [https://elastic-search-host/.kibana](https://elastic-search-host/.kibana)\*,

Do you not have access control setup?

---

<div class="post-metadata">

**Author:** ![Ilya\_21bA](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@Ilya\_21bA](https://discuss.elastic.co/u/Ilya_21bA)\
**Post date:** [June 7, 2021, 6:07am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/10 "2021-06-07T06:07:55Z")

</div>

Logs in Elastic:

[2021-06-07T09:03:31,386][INFO][o.e.e.NodeEnvironment] [AGILEVLG-SRV-23] using [1] data paths, mounts [[(c:)]], net usable\_space [23.4gb], net total\_space [126.6gb], types [NTFS]  
[2021-06-07T09:03:31,402][INFO][o.e.e.NodeEnvironment] [AGILEVLG-SRV-23] heap size [989.8mb], compressed ordinary object pointers [true]  
[2021-06-07T09:03:31,620][INFO][o.e.n.Node] [AGILEVLG-SRV-23] node name [AGILEVLG-SRV-23], node ID [nZb0BalCR1SI3AtEeN8AXg], cluster name [elasticsearch]  
[2021-06-07T09:03:31,620][INFO][o.e.n.Node] [AGILEVLG-SRV-23] version[7.1.1], pid[6304], build[default/zip/7a013de/2019-05-23T14:04:00.380842Z], OS[Windows Server 2012 R2/6.3/amd64], JVM[Oracle Corporation/Java HotSpot(TM) 64-Bit Server VM/1.8.0\_231/25.231-b11]  
[2021-06-07T09:03:31,620][INFO][o.e.n.Node] [AGILEVLG-SRV-23] JVM home [C:\Program Files\Java\jre1.8.0\_231]  
[2021-06-07T09:03:31,620][INFO][o.e.n.Node] [AGILEVLG-SRV-23] JVM arguments [-Xms1g, -Xmx1g, -XX:+UseConcMarkSweepGC, -XX:CMSInitiatingOccupancyFraction=75, -XX:+UseCMSInitiatingOccupancyOnly, -Des.networkaddress.cache.ttl=60, -Des.networkaddress.cache.negative.ttl=10, -XX:+AlwaysPreTouch, -Xss1m, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djna.nosys=true, -XX:-OmitStackTraceInFastThrow, -Dio.netty.noUnsafe=true, -Dio.netty.noKeySetOptimization=true, -Dio.netty.recycler.maxCapacityPerThread=0, -Dlog4j.shutdownHookEnabled=false, -Dlog4j2.disable.jmx=true, -Djava.io.tmpdir=C:\Users\BEZZBT~1\AppData\Local\Temp\elasticsearch, -XX:+HeapDumpOnOutOfMemoryError, -XX:HeapDumpPath=data, -XX:ErrorFile=logs/hs\_err\_pid%p.log, -XX:+PrintGCDetails, -XX:+PrintGCDateStamps, -XX:+PrintTenuringDistribution, -XX:+PrintGCApplicationStoppedTime, -Xloggc:logs/gc.log, -XX:+UseGCLogFileRotation, -XX:NumberOfGCLogFiles=32, -XX:GCLogFileSize=64m, -Dio.netty.allocator.type=unpooled, -Delasticsearch, -Des.path.home=c:\ELK\elasticsearch-7.1.1, -Des.path.conf=c:\ELK\elasticsearch-7.1.1\config, -Des.distribution.flavor=default, -Des.distribution.type=zip, -Des.bundled\_jdk=true, exit, abort, -Xms1024m, -Xmx1024m, -Xss1024k]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [aggs-matrix-stats]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [analysis-common]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [ingest-common]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [ingest-geoip]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [ingest-user-agent]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [lang-expression]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [lang-mustache]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [lang-painless]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [mapper-extras]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [parent-join]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [percolator]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [rank-eval]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [reindex]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [repository-url]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [transport-netty4]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [x-pack-ccr]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [x-pack-core]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [x-pack-deprecation]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [x-pack-graph]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [x-pack-ilm]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [x-pack-logstash]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [x-pack-ml]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [x-pack-monitoring]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [x-pack-rollup]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [x-pack-security]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [x-pack-sql]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] loaded module [x-pack-watcher]  
[2021-06-07T09:03:36,094][INFO][o.e.p.PluginsService] [AGILEVLG-SRV-23] no plugins loaded

---

<div class="post-metadata">

**Author:** ![Ilya\_21bA](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@Ilya\_21bA](https://discuss.elastic.co/u/Ilya_21bA)\
**Post date:** [June 7, 2021, 6:09am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/11 "2021-06-07T06:09:57Z")

</div>

Data from localhost:  
{"error":{"root\_cause":[{"type":"invalid\_index\_name\_exception","reason":"Invalid index name [_indicies], must not start with '_'.","index\_uuid":"_na_","index":"\_indicies"}],"type":"invalid\_index\_name\_exception","reason":"Invalid index name [_indicies], must not start with '_'.","index\_uuid":"_na_","index":"\_indicies"},"status":400}

---

<div class="post-metadata">

**Author:** ![Ilya\_21bA](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@Ilya\_21bA](https://discuss.elastic.co/u/Ilya_21bA)\
**Post date:** [June 7, 2021, 6:11am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/12 "2021-06-07T06:11:23Z")

</div>

Logstash:

[2021-06-07T09:03:23,347][WARN][logstash.runner] SIGINT received. Shutting down.  
[2021-06-07T09:03:24,626][INFO][filewatch.observingtail] QUIT - closing all files and shutting down.  
[2021-06-07T09:03:24,688][INFO][filewatch.observingtail] QUIT - closing all files and shutting down.  
[2021-06-07T09:03:24,704][INFO][filewatch.observingtail] QUIT - closing all files and shutting down.  
[2021-06-07T09:03:24,724][INFO][filewatch.observingtail] QUIT - closing all files and shutting down.  
[2021-06-07T09:03:24,735][INFO][filewatch.observingtail] QUIT - closing all files and shutting down.  
[2021-06-07T09:03:24,735][FATAL][logstash.runner] SIGINT received. Terminating immediately..  
[2021-06-07T09:04:16,455][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2021-06-07T09:04:16,471][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.1.1"}  
[2021-06-07T09:04:37,120][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://logstash\_internal:xxxxxx@localhost:9200/](http://logstash_internal:xxxxxx@localhost:9200/)]}}  
[2021-06-07T09:04:37,932][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://logstash\_internal:xxxxxx@localhost:9200/](http://logstash_internal:xxxxxx@localhost:9200/)"}  
[2021-06-07T09:04:38,073][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>7}  
[2021-06-07T09:04:38,089][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>7}  
[2021-06-07T09:04:38,167][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}  
[2021-06-07T09:04:38,182][INFO][logstash.outputs.elasticsearch] Using default mapping template  
[2021-06-07T09:04:38,260][INFO][logstash.filters.elasticsearch] New ElasticSearch filter client {:hosts=\>["localhost:9200"]}  
[2021-06-07T09:04:38,557][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"index\_patterns"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s", "number\_of\_shards"=\>1}, "mappings"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}  
[2021-06-07T09:04:39,495][INFO][logstash.javapipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>8, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50, "pipeline.max\_inflight"=\>1000, :thread=\>"#\<Thread:0x4760483d run\>"}  
[2021-06-07T09:04:41,214][INFO][logstash.javapipeline] Pipeline started {"pipeline.id"=\>"main"}  
[2021-06-07T09:04:41,292][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2021-06-07T09:04:41,292][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2021-06-07T09:04:41,292][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2021-06-07T09:04:41,292][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2021-06-07T09:04:41,448][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2021-06-07T09:04:41,464][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2021-06-07T09:04:41,464][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2021-06-07T09:04:41,464][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2021-06-07T09:04:42,260][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
[2021-06-07T09:04:46,387][INFO][logstash.filters.elasticsearch] New ElasticSearch filter client {:hosts=\>["localhost:9200"]}  
[2021-06-07T09:04:46,433][INFO][logstash.filters.elasticsearch] New ElasticSearch filter client {:hosts=\>["localhost:9200"]}  
[2021-06-07T09:04:47,417][INFO][logstash.filters.elasticsearch] New ElasticSearch filter client {:hosts=\>["localhost:9200"]}  
[2021-06-07T09:04:47,464][INFO][logstash.filters.elasticsearch] New ElasticSearch filter client {:hosts=\>["localhost:9200"]}  
[2021-06-07T09:04:47,698][INFO][logstash.filters.elasticsearch] New ElasticSearch filter client {:hosts=\>["localhost:9200"]}  
[2021-06-07T09:04:48,010][INFO][logstash.filters.elasticsearch] New ElasticSearch filter client {:hosts=\>["localhost:9200"]}  
[2021-06-07T09:04:48,028][INFO][logstash.filters.elasticsearch] New ElasticSearch filter client {:hosts=\>["localhost:9200"]}  
[2021-06-07T09:04:48,323][INFO][logstash.filters.elasticsearch] New ElasticSearch filter client {:hosts=\>["localhost:9200"]}  
[2021-06-07T09:04:48,995][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 7, 2021, 6:15am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/13 "2021-06-07T06:15:36Z")

</div>

I can't see the Kibana logs sorry?

Please also format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

> [@Ilya\_21bA](#):
>
> version[7.1.1]

Please upgrade, 7.1 has been [EOL](https://www.elastic.co/support/eol) for quite some time now.

---

<div class="post-metadata">

**Author:** ![Ilya\_21bA](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@Ilya\_21bA](https://discuss.elastic.co/u/Ilya_21bA)\
**Post date:** [June 7, 2021, 6:23am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/14 "2021-06-07T06:23:45Z")

</div>

I can't find the kibana logs, they need to be visualized via the console referring to kibana.yml?

---

<div class="post-metadata">

**Author:** ![Ilya\_21bA](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@Ilya\_21bA](https://discuss.elastic.co/u/Ilya_21bA)\
**Post date:** [June 7, 2021, 6:56am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/15 "2021-06-07T06:56:13Z")

</div>

![2021-06-07_09-55-24](https://us1.discourse-cdn.com/elastic/original/3X/c/8/c8c13c3337f5df097a8901e53fd812f3201d6f4f.png)

---

<div class="post-metadata">

**Author:** ![Ilya\_21bA](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@Ilya\_21bA](https://discuss.elastic.co/u/Ilya_21bA)\
**Post date:** [June 7, 2021, 7:01am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/16 "2021-06-07T07:01:13Z")

</div>

```
# Logs queries sent to Elasticsearch. Requires logging.verbose set to true.
elasticsearch.logQueries: true
# Enables you to specify a file where Kibana stores log output.
logging.dest: C:\ELK\kibana-7.1.1-windows-x86_64\bin\logs\kibana.log
# Set the value of this setting to true to log all events, including system usage information
# and all requests.
logging.verbose: true
```

---

<div class="post-metadata">

**Author:** ![Ilya\_21bA](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@Ilya\_21bA](https://discuss.elastic.co/u/Ilya_21bA)\
**Post date:** [June 7, 2021, 8:07am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/17 "2021-06-07T08:07:25Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/b/6/b627fba606227623687d29bd276c5c681be600e0.png)

Sorry, this log in Kibana

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 8, 2021, 12:59am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/18 "2021-06-08T00:59:06Z")

</div>

Please don't post pictures of text or code. They are difficult to read, impossible to search and replicate (if it's code), and some people may not be even able to see them 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2021, 1:00am UTC](https://discuss.elastic.co/t/how-backup-delete-indices/275080/19 "2021-07-06T01:00:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
