# Metricbeat Aggs fail after adding Index Routing

**URL:** <https://discuss.elastic.co/t/metricbeat-aggs-fail-after-adding-index-routing/86491>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [May 19, 2017, 9:32pm UTC](https://discuss.elastic.co/t/metricbeat-aggs-fail-after-adding-index-routing/86491 "2017-05-19T21:32:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ritchierich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ritchierich/32/4329_2.png) [@ritchierich](https://discuss.elastic.co/u/ritchierich)\
**Post date:** [May 19, 2017, 9:32pm UTC](https://discuss.elastic.co/t/metricbeat-aggs-fail-after-adding-index-routing/86491/1 "2017-05-19T21:32:22Z")

</div>

Earlier this week, I updated my v 5.3.2 cluster configuration for Hot/Warm Architecture. I added "index.routing.allocation.require.box\_type": "hot" to all existing daily indices then updated my logstash and metricbeat templates.

**First Day** : metricbeat-mongo-2017.05.18 index created without any issues.  
**Second Day:** metricbeat-mongo-2017.05.19 index created but...

- Aggs would return empty in both Kibana Visualization and directly querying Elasticsearch.
- All Data was visible in Kibana Discovery
- Tried refreshing index field list in Kibana Management

My solution:

1. Delete metricbeat template
2. Stopping all log indexing
3. Reindex existing metricbeat indices to New Indices
4. Delete Old Index
5. Start all log indexing
6. Aggregation worked

Meticbeat Template snippet if where I added Index Routing:

```
{
  "mappings": {
    "_default_": {
	 .... }
  },
 "order": 0,
  "settings": {
    "index.mapping.total_fields.limit": 10000,
    "index.refresh_interval": "5s",
    "index.routing.allocation.require.box_type": "hot"
  },
  "template": "metricbeat-*"
}

```

Am I missing something on adding the Index Routing?

Thanks in advance!

Cheers,  
Rich

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [May 22, 2017, 11:42am UTC](https://discuss.elastic.co/t/metricbeat-aggs-fail-after-adding-index-routing/86491/2 "2017-05-22T11:42:25Z")

</div>

Hi Rich

My first gut feeling is that there could be something wrong with the template. Are you sure the right template was loaded? Or were both templates loaded and now conflict with each others? Could you check how many templates you have in ES?

How do you load the template? Do you let Metricbeat doing it or do you load it manually?

---

<div class="post-metadata">

**Author:** ![ritchierich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ritchierich/32/4329_2.png) [@ritchierich](https://discuss.elastic.co/u/ritchierich)\
**Post date:** [May 30, 2017, 6:00pm UTC](https://discuss.elastic.co/t/metricbeat-aggs-fail-after-adding-index-routing/86491/3 "2017-05-30T18:00:59Z")

</div>

@ruflin Thanks for the response. I haven't had the opportunity to test further. My workaround is to manually set routing after the daily index is created.

I'll do some process of elimination with the metricbeat template to see if I can figure it out.

Cheers,  
Rich

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [June 2, 2017, 8:09pm UTC](https://discuss.elastic.co/t/metricbeat-aggs-fail-after-adding-index-routing/86491/4 "2017-06-02T20:09:56Z")

</div>

Thanks, keep us posted.

---

<div class="post-metadata">

**Author:** ![ritchierich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ritchierich/32/4329_2.png) [@ritchierich](https://discuss.elastic.co/u/ritchierich)\
**Post date:** [June 27, 2017, 5:38am UTC](https://discuss.elastic.co/t/metricbeat-aggs-fail-after-adding-index-routing/86491/5 "2017-06-27T05:38:35Z")

</div>

I haven't had the opportunity to test yet. My solution so far has been to manually set box\_type for metricbeat indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2017, 5:38am UTC](https://discuss.elastic.co/t/metricbeat-aggs-fail-after-adding-index-routing/86491/6 "2017-07-25T05:38:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
