# Logstash polling for closed index and stopping the log forwarding

**URL:** <https://discuss.elastic.co/t/logstash-polling-for-closed-index-and-stopping-the-log-forwarding/117208>\
**Category:** Logstash\
**Created:** [January 26, 2018, 2:52pm UTC](https://discuss.elastic.co/t/logstash-polling-for-closed-index-and-stopping-the-log-forwarding/117208 "2018-01-26T14:52:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anjan\_Pratap](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@Anjan\_Pratap](https://discuss.elastic.co/u/Anjan_Pratap)\
**Post date:** [January 26, 2018, 2:52pm UTC](https://discuss.elastic.co/t/logstash-polling-for-closed-index-and-stopping-the-log-forwarding/117208/1 "2018-01-26T14:52:50Z")

</div>

Hi,

I am using logstash 5.6 with filebeat, rsyslog and kafka as inputs. I implemented a script to close the indices older than one month. I am seeing log messages in logstash about the closed indices for long time and suddenly there is no data appearing on Kibana. once I open the closed indices, then only I am able to see data on Kibana.  
adding the info messages wrt closed index. All the logs clustered with these messages.

My observation is , I am seeing these messages only for syslog index.

logstash-plain.log:[2018-01-26T14:40:24,288][INFO][logstash.outputs.elasticsear ch] retrying failed action with response code: 403 ({"type"=\>"index\_closed\_excep tion", "reason"=\>"closed", "index\_uuid"=\>"Veahm9MQRN2Buu66Wlr3OQ", "index"=\>"sta ging-syslog-2017.12.18"})

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [February 2, 2018, 1:57pm UTC](https://discuss.elastic.co/t/logstash-polling-for-closed-index-and-stopping-the-log-forwarding/117208/2 "2018-02-02T13:57:18Z")

</div>

What this means is that some of the data coming in to Logstash is old enough (based on its timestamp) that Logstash is sending it to Elasticsearch, destined for a closed index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2018, 1:57pm UTC](https://discuss.elastic.co/t/logstash-polling-for-closed-index-and-stopping-the-log-forwarding/117208/3 "2018-03-02T13:57:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
