# My flux capacitor is broke - I.E. Elasticsearch index is in the future

**URL:** <https://discuss.elastic.co/t/my-flux-capacitor-is-broke-i-e-elasticsearch-index-is-in-the-future/24095>\
**Category:** Elasticsearch\
**Created:** [June 22, 2015, 1:48pm UTC](https://discuss.elastic.co/t/my-flux-capacitor-is-broke-i-e-elasticsearch-index-is-in-the-future/24095 "2015-06-22T13:48:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Don\_Pich](https://avatars.discourse-cdn.com/v4/letter/d/b487fb/32.png) [@Don\_Pich](https://discuss.elastic.co/u/Don_Pich)\
**Post date:** [June 22, 2015, 1:48pm UTC](https://discuss.elastic.co/t/my-flux-capacitor-is-broke-i-e-elasticsearch-index-is-in-the-future/24095/1 "2015-06-22T13:48:47Z")

</div>

My cluster has been suffering for a while. It will go through the rebuild process and then it will end up in a red state. In diagnosing the issue, I looked through the indexes. I was amazed to find a bunch of indexes with future dates:

```
"logstash-syslog-events-2015.11.29": {
    "settings": {
        "index": {
            "creation_date": "1425324264913",
            "routing": {
                "allocation": {
                    "disable_allocation": "false"
                }
            },
            "uuid": "1Ftatk9GS5eNM07sXHwrHw",
            "number_of_replicas": "1",
            "number_of_shards": "5",
            "refresh_interval": "5s",
            "version": {
                "created": "1040499"
            }
        }
    }
},

```

Any recommendations on what could be doing this, or is this a huge problem? The dates on the server are correct and are responding properly with NTP.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 22, 2015, 2:00pm UTC](https://discuss.elastic.co/t/my-flux-capacitor-is-broke-i-e-elasticsearch-index-is-in-the-future/24095/2 "2015-06-22T14:00:22Z")

</div>

The evidence certainly suggests that Logstash has received messages whose parsed `@timestamp` was 2015-11-29. What messages _are_ in that index? Do you still have the original log files so you can check the source data? Or, if you keep the raw input message around in Elasticsearch that obviously works too.

---

<div class="post-metadata">

**Author:** ![Don\_Pich](https://avatars.discourse-cdn.com/v4/letter/d/b487fb/32.png) [@Don\_Pich](https://discuss.elastic.co/u/Don_Pich)\
**Post date:** [June 22, 2015, 2:22pm UTC](https://discuss.elastic.co/t/my-flux-capacitor-is-broke-i-e-elasticsearch-index-is-in-the-future/24095/3 "2015-06-22T14:22:55Z")

</div>

So that being said, Elasticsearch is just doing what it is supposed to do and creating an index based on what it is receiving. I can accept that.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 22, 2015, 2:34pm UTC](https://discuss.elastic.co/t/my-flux-capacitor-is-broke-i-e-elasticsearch-index-is-in-the-future/24095/4 "2015-06-22T14:34:28Z")

</div>

It's Logstash that creates the indexes based on the `@timestamp` field, but yes. Garbage in, garbage out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:06am UTC](https://discuss.elastic.co/t/my-flux-capacitor-is-broke-i-e-elasticsearch-index-is-in-the-future/24095/5 "2017-07-06T00:06:08Z")

</div>


