# Indices don't have primary shards while trying to take a snapshot

**URL:** <https://discuss.elastic.co/t/indices-dont-have-primary-shards-while-trying-to-take-a-snapshot/168812>\
**Category:** Elasticsearch\
**Created:** [February 18, 2019, 10:57am UTC](https://discuss.elastic.co/t/indices-dont-have-primary-shards-while-trying-to-take-a-snapshot/168812 "2019-02-18T10:57:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![muthualagappan](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@muthualagappan](https://discuss.elastic.co/u/muthualagappan)\
**Post date:** [February 18, 2019, 10:57am UTC](https://discuss.elastic.co/t/indices-dont-have-primary-shards-while-trying-to-take-a-snapshot/168812/1 "2019-02-18T10:57:48Z")

</div>

Hi Team,

We have a old elasticsearch cluster running on 1.4.5. We wanted to take a snapshot of the data and delete the cluster. But we have some issues.

**While taking the snapshot, we get the status as FAILED.**  
"state" : "FAILED",  
"reason" : "Indices don't have primary shards +[[logstash-2019.10.22, logstash-2019.12.11, logstash-2019.02.12, logstash-2019.07.14, logstash-2019.11.09, logstash-2018.11.04, logstash-2019.10.08, logstash-2018.11.05, logstash-2019.12.31]]"

**The cluster health is RED because there are some unassigned shards**

{  
"cluster\_name" : "XXX",  
"status" : "red",  
"timed\_out" : false,  
"number\_of\_nodes" : 7,  
"number\_of\_data\_nodes" : 5,  
"active\_primary\_shards" : 6261,  
"active\_shards" : 17582,  
"relocating\_shards" : 2,  
"initializing\_shards" : 0,  
"unassigned\_shards" : 180  
}

We guess we had lost one data node and and unable to fix the unassigned\_shards.

We need the help in

(i) Fixing the unassigned shards. The reason for the unassigned shards are not known. The sample output for the below command "/\_cat/shards?h=index,shard,prirep,state,unassigned.reason| grep UNASSIGNED"

logstash-2019.02.12 2 r UNASSIGNED  
logstash-2019.02.12 2 r UNASSIGNED

(ii) Even if we are unable to fix the unassigned\_shards, we need to take the snapshot of the other shards just leaving those faulty 180 unassigned shards.

Kindly assist and let me know if you require further details.

Regards,  
Muthu.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 18, 2019, 12:00pm UTC](https://discuss.elastic.co/t/indices-dont-have-primary-shards-while-trying-to-take-a-snapshot/168812/2 "2019-02-18T12:00:45Z")

</div>

OMG.

17582 on a 5 nodes cluster?  
Using a 1.4 version?

Yes, I can definitely confirm that you are/will be into trouble...

I don't really know how to fix that in the short term as this is a very old not maintained version.  
I'd probably look at some few things:

- Remove all non needed indices. I guess that you are not using all the data available from the 17582 shards... So Remove old data with the Delete Index API.
- Start new indices with only 1 shard (well depending on your daily volume)

If possible, start a new cluster with 6.6.0 and start collecting the data in this new cluster. Once you don't need the old one, remove the old cluster.

Finally, I suggest you look at the following resources about sizing:

[https://www.elastic.co/elasticon/conf/2016/sf/quantitative-cluster-sizing](https://www.elastic.co/elasticon/conf/2016/sf/quantitative-cluster-sizing)

> **[How many shards should I have in my Elasticsearch cluster?
	  	 | Elastic](https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster)**
>
> Elasticsearch is a very versatile platform, that supports a variety of use cases, and provides great flexibility around data organisation and replication strategies. This flexibility can however somet...

> **[NetSecureDay: Managing your Black Friday Logs](https://speakerdeck.com/elastic/netsecureday-managing-your-black-friday-logs)**
>
> Surveiller une application complexe n’est pas une tâche aisée, mais avec les bons outils, ce n’est pas si sorcier. Néanmoins, des périodes fortes telles que les opérations de type « Black Friday » (Vendredi noir) ou période de Noël peuvent pousser...

And [https://www.elastic.co/webinars/using-rally-to-get-your-elasticsearch-cluster-size-right](https://www.elastic.co/webinars/using-rally-to-get-your-elasticsearch-cluster-size-right)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2019, 12:00pm UTC](https://discuss.elastic.co/t/indices-dont-have-primary-shards-while-trying-to-take-a-snapshot/168812/3 "2019-03-18T12:00:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
