# Ilm rollover error on datastream index

**URL:** <https://discuss.elastic.co/t/ilm-rollover-error-on-datastream-index/346164>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [October 31, 2023, 10:38pm UTC](https://discuss.elastic.co/t/ilm-rollover-error-on-datastream-index/346164 "2023-10-31T22:38:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Russell\_Fulton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russell_fulton/32/62888_2.png) [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Post date:** [October 31, 2023, 10:38pm UTC](https://discuss.elastic.co/t/ilm-rollover-error-on-datastream-index/346164/1 "2023-10-31T22:38:47Z")

</div>

I one index of a datastream showing an ILM error:

```auto
java.lang.IllegalStateException: no rollover info found for [.ds-sec-events-2023.08.12-000015] with rollover target [sec-events], the index has not yet rolled over with that target
	at org.elasticsearch.xpack.core.ilm.UpdateRolloverLifecycleDateStep.performAction(UpdateRolloverLifecycleDateStep.java:62)
	at org.elasticsearch.xpack.ilm.ExecuteStepsUpdateTask.doExecute(ExecuteStepsUpdateTask.java:112)
	at org.elasticsearch.xpack.ilm.IndexLifecycleClusterStateUpdateTask.execute(IndexLifecycleClusterStateUpdateTask.java:46)
	at org.elasticsearch.xpack.ilm.IndexLifecycleRunner.lambda$static$0(IndexLifecycleRunner.java:64)
	at org.elasticsearch.cluster.service.MasterService.executeTasks(MasterService.java:840)
	at org.elasticsearch.cluster.service.MasterService.calculateTaskOutputs(MasterService.java:407)
	at org.elasticsearch.cluster.service.MasterService.runTasks(MasterService.java:243)
	at org.elasticsearch.cluster.service.MasterService.access$100(MasterService.java:63)
	at org.elasticsearch.cluster.service.MasterService$Batcher.run(MasterService.java:170)
	at org.elasticsearch.cluster.service.TaskBatcher.runIfNotProcessed(TaskBatcher.java:146)
	at org.elasticsearch.cluster.service.TaskBatcher$BatchedTask.run(TaskBatcher.java:202)
	at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:718)
	at org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.runAndClean(PrioritizedEsThreadPoolExecutor.java:262)
	at org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.run(PrioritizedEsThreadPoolExecutor.java:225)
	at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1144)
	at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:642)
	at java.base/java.lang.Thread.run(Thread.java:1623)

```

when I try to use `_ilm/explain` it get:

```auto
rful011@secesprd01:~$ curl -s --noproxy \* -u elastic -XGET 'https://secesprd02.its.auckland.ac.nz:9200/.ds-sec-events-2023.08.12-000015/_iml/explain' 
Enter host password for user 'elastic':
{"_index":".ds-sec-events-2023.08.12-000015","_type":"_iml","_id":"explain","found":false}

```

which I assume means it can't find the index ?? Is it because it is a backing index for a datastream?

what is weird is that the data stream appears to have rolled over and other indexes have been generated:  
 ![Screenshot 2023-11-01 at 11.25.53 AM](https://us1.discourse-cdn.com/elastic/original/3X/8/7/874602369b8f5a27d37ca6f6901bb4c935b520ec.png)

something clearly came unstuck -- we had issues with the cluster back then.

the index is still "hot" and 000016 is now cold.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 1, 2023, 12:58am UTC](https://discuss.elastic.co/t/ilm-rollover-error-on-datastream-index/346164/2 "2023-11-01T00:58:05Z")

</div>

> [@Russell\_Fulton](#):
>
> `_iml`

> [@Russell\_Fulton](#):
>
> `https://secesprd02.its.auckland.ac.nz:9200/.ds-sec-events-2023.08.12-000015/_iml/explain`

Typo

`_ilm`

---

<div class="post-metadata">

**Author:** ![Russell\_Fulton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russell_fulton/32/62888_2.png) [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Post date:** [November 1, 2023, 2:30am UTC](https://discuss.elastic.co/t/ilm-rollover-error-on-datastream-index/346164/3 "2023-11-01T02:30:10Z")

</div>

Thanks! sigh... I am hopeless at spotting typos!

OK the \_ilm/explain returned the error message above along with the general information about the index.

I think the fundamental problem here is I lost one shard of this index when it was the head of the data datastream . To recover it I had to delete it forcing the datasteam to start a new head, then restored the the index from backup and linked it back into the datastream (with help from this forum -- probably @stephenb : ).

I suspect this left the index as an orphan as far as the ilm process is concerned.

Any thoughts on how to correct this? Does it matter?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2023, 2:30am UTC](https://discuss.elastic.co/t/ilm-rollover-error-on-datastream-index/346164/4 "2023-11-29T02:30:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
