# Issue in Elasticsearch 2.0 index

**URL:** <https://discuss.elastic.co/t/issue-in-elasticsearch-2-0-index/35861>\
**Category:** Elasticsearch\
**Created:** [November 30, 2015, 6:29am UTC](https://discuss.elastic.co/t/issue-in-elasticsearch-2-0-index/35861 "2015-11-30T06:29:41Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![asgawali](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@asgawali](https://discuss.elastic.co/u/asgawali)\
**Post date:** [November 30, 2015, 6:29am UTC](https://discuss.elastic.co/t/issue-in-elasticsearch-2-0-index/35861/1 "2015-11-30T06:29:41Z")

</div>

I am using Elasticsearch 2.0 and logstash 1.5.4 for my project, the moment I have upgraded the elasticsearch version from 1.7 to 2.0, its showing some garbage indexes in my elasticsearch.

```
[root@site1 ~]# curl 'localhost:9200/_cat/indices?v'
health status index pri rep docs.count docs.deleted store.size pri.store.size
green open servlet 5 1 0 0 1.5kb 780b
green open topic 5 1 0 0 1.5kb 780b
green open formmail.pl 5 1 0 0 1.5kb 780b
green open account 5 1 0 0 1.5kb 780b
green open vrowea1.html 5 1 0 0 1.5kb 780b
green open login.php 5 1 0 0 1.5kb 780b
green open webui 5 1 0 0 1.5kb 780b
green open recordings 5 1 0 0 1.5kb 780b
green open something 5 1 0 0 1.5kb 780b
green open comersus_backoffice_login.php 5 1 0 0 1.5kb 780b
green open shopsearch.asp 5 1 0 0 1.5kb 780b
green open lcds 5 1 0 0 1.5kb 780b
green open logstash-2015.11.28 5 1 21475 0 19.2mb 9.7mb
green open index.php 5 1 0 0 1.5kb 780b
green open kb.cgi 5 1 0 0 1.5kb 780b
green open admin 5 1 0 0 1.5kb 780b
green open samba 5 1 0 0 1.5kb 780b
green open ngarwg1.html 5 1 0 0 1.5kb 780b
green open nwpgav1.html 5 1 0 0 1.5kb 780b
green open mod.php 5 1 0 0 1.5kb 780b
green open gw 5 1 0 0 1.5kb 780b
green open msadc 5 1 0 0 1.5kb 780b
green open phppath 5 1 0 0 1.5kb 780b
green open blazeds 5 1 0 0 1.5kb 780b
green open formmail 5 1 0 0 1.5kb 780b
green open messagebroker 5 1 0 0 1.5kb 780b
green open spipe 5 1 0 0 1.5kb 780b
green open getpassword.php 5 1 0 0 1.5kb 780b
green open smbshr.pl 5 1 0 0 1.5kb 780b
green open flex2gateway 5 1 0 0 1.5kb 780b
green open perl 5 1 0 0 1.5kb 780b
green open .kibana 1 1 2 0 37.2kb 18.6kb
green open scripts 5 1 0 0 1.5kb 780b
green open pspsgw1.html 5 1 0 0 1.5kb 780b
green open sagrsn1.html 5 1 0 0 1.5kb 780b
green open cgi-bin 5 1 0 0 1.5kb 780b
green open sovgoe1.html 5 1 0 0 1.5kb 780b
green open gwvron1.html 5 1 0 0 1.5kb 780b

```

It is supposed to show only 'logstash-2015.11.28' as a index.

Can anyone advice whats wrong here?

Thanks in advance!!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 30, 2015, 6:49am UTC](https://discuss.elastic.co/t/issue-in-elasticsearch-2-0-index/35861/2 "2015-11-30T06:49:22Z")

</div>

Probably you inserted wrong data?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 30, 2015, 8:01am UTC](https://discuss.elastic.co/t/issue-in-elasticsearch-2-0-index/35861/3 "2015-11-30T08:01:23Z")

</div>

Or the cluster is open to the internet or some other network.

---

<div class="post-metadata">

**Author:** ![ebuildy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebuildy/32/6070_2.png) [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Post date:** [November 30, 2015, 9:19am UTC](https://discuss.elastic.co/t/issue-in-elasticsearch-2-0-index/35861/4 "2015-11-30T09:19:18Z")

</div>

I confirm, it's clearly bot urls (kb.cgi, getpassword.php etc....)

---

<div class="post-metadata">

**Author:** ![asgawali](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@asgawali](https://discuss.elastic.co/u/asgawali)\
**Post date:** [November 30, 2015, 9:22am UTC](https://discuss.elastic.co/t/issue-in-elasticsearch-2-0-index/35861/5 "2015-11-30T09:22:22Z")

</div>

No.. I didnt inserted wrong data

---

<div class="post-metadata">

**Author:** ![asgawali](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@asgawali](https://discuss.elastic.co/u/asgawali)\
**Post date:** [November 30, 2015, 9:23am UTC](https://discuss.elastic.co/t/issue-in-elasticsearch-2-0-index/35861/6 "2015-11-30T09:23:04Z")

</div>

So, what should be done here ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 30, 2015, 9:34am UTC](https://discuss.elastic.co/t/issue-in-elasticsearch-2-0-index/35861/7 "2015-11-30T09:34:36Z")

</div>

Don't expose your cluster on internet. Or secure it.

---

<div class="post-metadata">

**Author:** ![ebuildy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebuildy/32/6070_2.png) [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Post date:** [December 1, 2015, 9:25am UTC](https://discuss.elastic.co/t/issue-in-elasticsearch-2-0-index/35861/8 "2015-12-01T09:25:42Z")

</div>

Your elasticsearch should listen local IP rather then the web opened network interface, HTTP parameters:

[https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-http.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-http.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:34pm UTC](https://discuss.elastic.co/t/issue-in-elasticsearch-2-0-index/35861/9 "2017-07-05T23:34:31Z")

</div>


