# Incorrect indice creation date

**URL:** <https://discuss.elastic.co/t/incorrect-indice-creation-date/298539>\
**Category:** Elasticsearch\
**Created:** [March 1, 2022, 4:56pm UTC](https://discuss.elastic.co/t/incorrect-indice-creation-date/298539 "2022-03-01T16:56:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Helicube](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helicube/32/102464_2.png) [@Helicube](https://discuss.elastic.co/u/Helicube)\
**Post date:** [March 1, 2022, 4:56pm UTC](https://discuss.elastic.co/t/incorrect-indice-creation-date/298539/1 "2022-03-01T16:56:08Z")

</div>

Hello,

I have an issue with the Index Rotation. My Graylog server automatically create a new Indice every day (Index rotation). But sometimes, the creation date entered in Elasticsearch is not correct. The date entered goes back several months before the real date of creation. This is not systematic, but it has happened several days in a row lately. This really bothers me because I use this date to take snapshots of the indexes.

**Expected Behavior**

The date display by this API request should look like this :  
`curl -X GET 'my-elastic.server.com:9200/_cat/indices?h=i,cds'`  
[...]  
graylog\_120 ... 2022-02-16T00:00:03.168Z  
graylog\_121 ... 2022-02-17T00:00:01.124Z  
graylog\_122 ... 2022-02-18T00:00:04.020Z  
graylog\_123 ... 2022-02-19T00:00:01.236Z  
graylog\_124 ... 2022-02-20T00:00:01.937Z  
graylog\_125 ... 2022-02-21T00:00:02.432Z  
graylog\_126 ... 2022-02-22T00:00:01.796Z  
graylog\_127 ... 2022-02-23T00:00:01.874Z

**Current Behavior**

They actually look like this 😥 :  
graylog\_120 ... 2021-11-10T08:36:50.168Z  
graylog\_121 ... 2021-11-10T08:36:51.124Z  
graylog\_122 ... 2021-11-10T08:36:51.020Z  
graylog\_123 ... 2021-11-10T08:36:50.236Z  
graylog\_124 ... 2021-11-10T08:36:50.937Z  
graylog\_125 ... 2022-02-21T09:19:38.432Z  
graylog\_126 ... 2021-11-10T08:36:47.796Z  
graylog\_127 ... 2022-02-21T09:19:43.874Z

Also, I noticed that the date was often the same, at very close times : 2021-11-10T08:36:XX.xxxZ

I use this creation date to make a snapshot of the indice created the day before. I use a script which do API request to do the snapshot, and then, I use third-party software to store it somewehre else.  
Manual index rotation seems to work, but I'm not 100% sure.  
There also seems to be the same problem with the snapshot creation date, which I use for monitoring.

**My Environment**

- 1 Elasticsearch Server :

- 1 Graylog server :

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 1, 2022, 8:47pm UTC](https://discuss.elastic.co/t/incorrect-indice-creation-date/298539/2 "2022-03-01T20:47:18Z")

</div>

Elasticsearch will create the index that is requested via the API call. So this is something that you will need to ask graylog.

---

<div class="post-metadata">

**Author:** ![Helicube](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helicube/32/102464_2.png) [@Helicube](https://discuss.elastic.co/u/Helicube)\
**Post date:** [March 2, 2022, 8:17am UTC](https://discuss.elastic.co/t/incorrect-indice-creation-date/298539/3 "2022-03-02T08:17:45Z")

</div>

Thank you for your reply,  
however, I asked the same question on the Graylog forum and got the following answer:  
"Graylog doesn't set the creation date of indices at index rotation. This is done automatically by ES."  
([Index rotation : Index creation date incorrect · Issue #12183 · Graylog2/graylog2-server · GitHub](https://github.com/Graylog2/graylog2-server/issues/12183))

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 3, 2022, 12:52am UTC](https://discuss.elastic.co/t/incorrect-indice-creation-date/298539/4 "2022-03-03T00:52:46Z")

</div>

It's correct that Elasticsearch does set the creation timestamp, and that timestamp is recorded when the request is received.

Where did the "Expected behaviour" output come from?

---

<div class="post-metadata">

**Author:** ![Helicube](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helicube/32/102464_2.png) [@Helicube](https://discuss.elastic.co/u/Helicube)\
**Post date:** [March 3, 2022, 1:50pm UTC](https://discuss.elastic.co/t/incorrect-indice-creation-date/298539/5 "2022-03-03T13:50:09Z")

</div>

Ok, I understand. So what does it mean ? I suppose the request is sent every days, at midnight, so what is wrong.

Also, I invented the "Expected behavior" output from the few real results I got in the previous months. Here are some real output examples of correct creation date :

graylog\_73 ... 2022-01-01T00:00:10.126Z  
graylog\_74 ... 2022-01-02T00:00:10.121Z  
graylog\_75 ... 2022-01-03T00:00:10.123Z  
graylog\_76 ... 2022-01-04T00:00:10.126Z  
graylog\_77 ... 2022-01-05T00:00:10.123Z  
graylog\_78 ... 2022-01-06T00:00:10.123Z

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 3, 2022, 9:35pm UTC](https://discuss.elastic.co/t/incorrect-indice-creation-date/298539/6 "2022-03-03T21:35:45Z")

</div>

> [@Helicube](#):
>
> Here are some real output examples of correct creation date

They look correct then?

---

<div class="post-metadata">

**Author:** ![Helicube](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helicube/32/102464_2.png) [@Helicube](https://discuss.elastic.co/u/Helicube)\
**Post date:** [March 4, 2022, 3:15pm UTC](https://discuss.elastic.co/t/incorrect-indice-creation-date/298539/7 "2022-03-04T15:15:42Z")

</div>

No, what I mean is that sometimes the creation date is correct, and sometimes not:

graylog\_80 ... 2022-01-08T00:00:10.121Z - CORRECT  
graylog\_81 ... 2022-01-09T00:00:18.193Z - CORRECT  
graylog\_82 ... 2022-01-10T00:00:10.125Z - CORRECT  
graylog\_83 ... 2022-01-11T00:00:10.126Z - CORRECT  
graylog\_84 ... 2022-01-12T00:00:00.313Z - CORRECT  
**graylog\_85 ... 2022-01-11T00:00:18.666Z - INCORRECT**  
**graylog\_86 ... 2021-11-10T08:36:51.048Z - INCORRECT**  
**graylog\_87 ... 2021-11-10T08:36:50.856Z - INCORRECT**  
**graylog\_88 ... 2021-11-10T08:36:50.921Z - INCORRECT**  
graylog\_89 ... 2022-01-17T00:00:10.127Z - CORRECT

But lately, they are mostly incorrect.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2022, 3:16pm UTC](https://discuss.elastic.co/t/incorrect-indice-creation-date/298539/8 "2022-04-01T15:16:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
