# My\_index/\_stats/indexing (high number of "index\_failed" operations)

**URL:** <https://discuss.elastic.co/t/my-index-stats-indexing-high-number-of-index-failed-operations/270152>\
**Category:** Elasticsearch\
**Created:** [April 14, 2021, 9:17pm UTC](https://discuss.elastic.co/t/my-index-stats-indexing-high-number-of-index-failed-operations/270152 "2021-04-14T21:17:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Logan\_H](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/logan_h/32/87065_2.png) [@Logan\_H](https://discuss.elastic.co/u/Logan_H)\
**Post date:** [April 14, 2021, 9:17pm UTC](https://discuss.elastic.co/t/my-index-stats-indexing-high-number-of-index-failed-operations/270152/1 "2021-04-14T21:17:09Z")

</div>

I'm supporting a cluster with an index that is seeing a high number in "indexed\_failed" operations as shown by the indexing stats. I'm trying to understand what type of scenarios would cause this counter to increment up. What exactly is considered a "indexed\_failed" operation and what might the causes be?

Logstash indexing to \> Elasticsearch 5.6.4 and seeing an excessive amount io wait time and poor performance overall.

```auto
GET my_index/_stats/indexing 
{
  "_shards" : {
    "total" : 360,
    "successful" : 360,
    "failed" : 0
  },
  "_all" : {
    "primaries" : {
      "indexing" : {
        "index_total" : 39546274,
        "index_time_in_millis" : 32693876,
        "index_current" : 0,
        "index_failed" : 17762193,
        "delete_total" : 1059084,
        "delete_time_in_millis" : 216423,
        "delete_current" : 0,
        "noop_update_total" : 0,
        "is_throttled" : false,
        "throttle_time_in_millis" : 0
      }
    },
    "total" : {
      "indexing" : {
        "index_total" : 108377320,
        "index_time_in_millis" : 117903886,
        "index_current" : 6,
        "index_failed" : 17762193,
        "delete_total" : 3072604,
        "delete_time_in_millis" : 965006,
        "delete_current" : 0,
        "noop_update_total" : 0,
        "is_throttled" : false,
        "throttle_time_in_millis" : 0
      }
    }
  },
  "indices" : {
    "my_index" : {
      "primaries" : {
        "indexing" : {
          "index_total" : 39546274,
          "index_time_in_millis" : 32693876,
          "index_current" : 0,
          "index_failed" : 17762193,
          "delete_total" : 1059084,
          "delete_time_in_millis" : 216423,
          "delete_current" : 0,
          "noop_update_total" : 0,
          "is_throttled" : false,
          "throttle_time_in_millis" : 0
        }
      },
      "total" : {
        "indexing" : {
          "index_total" : 108377320,
          "index_time_in_millis" : 117903886,
          "index_current" : 6,
          "index_failed" : 17762193,
          "delete_total" : 3072604,
          "delete_time_in_millis" : 965006,
          "delete_current" : 0,
          "noop_update_total" : 0,
          "is_throttled" : false,
          "throttle_time_in_millis" : 0
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 14, 2021, 11:08pm UTC](https://discuss.elastic.co/t/my-index-stats-indexing-high-number-of-index-failed-operations/270152/2 "2021-04-14T23:08:04Z")

</div>

Welcome to our community! 😃

> [@Logan\_H](#):
>
> Elasticsearch 5.6.4

5.6 has been [EOL](https://www.elastic.co/support/eol) for 2 years now, you really need to upgrade as a matter of urgency.

> [@Logan\_H](#):
>
> `"total" : 360,`

Why do you have so many shards?

---

<div class="post-metadata">

**Author:** ![Logan\_H](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/logan_h/32/87065_2.png) [@Logan\_H](https://discuss.elastic.co/u/Logan_H)\
**Post date:** [April 15, 2021, 12:13am UTC](https://discuss.elastic.co/t/my-index-stats-indexing-high-number-of-index-failed-operations/270152/3 "2021-04-15T00:13:03Z")

</div>

I couldn't agree with you more that the version is old and this is a lot of shards. We're actively working on upgrading to the latest version but need to solve the problem in order to clear a path to get there. The index has a 937GB pri.store.size with 60 primary shards and (5 replicas at the moment for testing).

But what I'm trying to understand is exactly what causes the "index\_failed" count to be incremented and how concerned I should be that the index\_failed count is nearly 50% of the index\_total count.

The exact meaning of the counter isn't documented well anywhere that I can find. It's not documented in 5.4 and the 7.x docs say that it's the "Number of failed indexing operations" Which doesn't help me to understand what causes that to happen. I don't see any errors in Logstash and we don't see to be missing any documents.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 15, 2021, 3:25am UTC](https://discuss.elastic.co/t/my-index-stats-indexing-high-number-of-index-failed-operations/270152/4 "2021-04-15T03:25:17Z")

</div>

The could be failures that Logstash has automatically retried for you.

---

<div class="post-metadata">

**Author:** ![Logan\_H](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/logan_h/32/87065_2.png) [@Logan\_H](https://discuss.elastic.co/u/Logan_H)\
**Post date:** [April 17, 2021, 4:16pm UTC](https://discuss.elastic.co/t/my-index-stats-indexing-high-number-of-index-failed-operations/270152/5 "2021-04-17T16:16:44Z")

</div>

Update. I was able to confirm what was causing the the "index\_failed" counts. Logstash was configured to use external version numbers but there was a flaw in our config that was causing it to use the same version number multiple times. This was causing updates in Elasticsearch to return a 409 error due to a version conflict which increments the index\_failed counter in the index stats.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2021, 4:17pm UTC](https://discuss.elastic.co/t/my-index-stats-indexing-high-number-of-index-failed-operations/270152/6 "2021-05-15T16:17:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
