# Index alias is broken every night by auto(bulk api)

**URL:** <https://discuss.elastic.co/t/index-alias-is-broken-every-night-by-auto-bulk-api/199185>\
**Category:** Beats\
**Tags:** heartbeat\
**Created:** [September 12, 2019, 7:08am UTC](https://discuss.elastic.co/t/index-alias-is-broken-every-night-by-auto-bulk-api/199185 "2019-09-12T07:08:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jesus\_Munoz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jesus_munoz/32/54034_2.png) [@Jesus\_Munoz](https://discuss.elastic.co/u/Jesus_Munoz)\
**Post date:** [September 12, 2019, 7:08am UTC](https://discuss.elastic.co/t/index-alias-is-broken-every-night-by-auto-bulk-api/199185/1 "2019-09-12T07:08:00Z")

</div>

I use heartbeat 7.3.0 to send data to a 7.3.0 ES hosted in elastic cloud.  
I have one docker heartbeat deployed in EKS 1.13, with default values.

Everything runs fine until every night at 1:00AM UTC, in which auto(bulk api) deletes and recreates the index, losing the write alias, deleting all data, and creating a new alias with a shortname:

BEFORE:  
GET \_alias  
"heartbeat-7.3.0-2019.09.12-000001" : {  
"aliases" : {  
"heartbeat-7.3.0" : {  
"is\_write\_index" : true  
}  
}

AFTER:  
GET \_alias  
"heartbeat-7.3.0" : {  
"aliases" : {}  
}

All my dashboards are then broken and also the watchers, with a message "Fielddata is disabled on text fields by default. Set fielddata=true in [monitor.id] bla bla bla".  
If I delete the shortname index (heartbeat-7.3.0) and the alias, and then restart the heartbeat, everything is running fine again until next day.

I've tried everything but I can't avoid the disaster every night.

[![Imgur](https://us1.discourse-cdn.com/elastic/original/3X/b/3/b3703a237a22a713aea5482bdd732485172c46b6.jpeg "Imgur") ](https://imgur.com/vGMCc3M)  
[![Imgur](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f38a352a1618cc14c62cf3ce07b52ac82081748.jpeg "Imgur") ](https://imgur.com/78Qyog8)  
[![Imgur](https://us1.discourse-cdn.com/elastic/original/3X/a/e/aeaadd329a30a590c666a0d0bb86f7f27dded5b1.jpeg "Imgur") ](https://imgur.com/MhOBZor)

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [September 12, 2019, 7:57pm UTC](https://discuss.elastic.co/t/index-alias-is-broken-every-night-by-auto-bulk-api/199185/2 "2019-09-12T19:57:08Z")

</div>

Sorry to hear about this, this sounds quite painful.

Do you have any idea what's deleting the alias? That's not normal behavior, and beats doesn't do that itself.

---

<div class="post-metadata">

**Author:** ![Jesus\_Munoz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jesus_munoz/32/54034_2.png) [@Jesus\_Munoz](https://discuss.elastic.co/u/Jesus_Munoz)\
**Post date:** [September 13, 2019, 6:43am UTC](https://discuss.elastic.co/t/index-alias-is-broken-every-night-by-auto-bulk-api/199185/3 "2019-09-13T06:43:09Z")

</div>

My eyes are on this scheduled nightly job called 'auto (bulk api)'. As it can be seen in one of the screenshots, the job deletes indexes and then create them again.  
The thing is that the index has initially a patten `heartbeat-{version}-{dd/mm/yyyy}-{sequence}`, and then my guess is that something goes wrong and the index end with the pattern`heartbeat-{version}` form, so the deleting+recreating process is not running clean.

I have no way to debug or access the details of that process, and unfortunately elastic support told me that this is out of my support tier.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2019, 6:43am UTC](https://discuss.elastic.co/t/index-alias-is-broken-every-night-by-auto-bulk-api/199185/4 "2019-10-11T06:43:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
