# New shards for logstash indices remain unassigned - org.apache.lucene.index.CorruptIndexException: codec footer mismatch

**URL:** <https://discuss.elastic.co/t/new-shards-for-logstash-indices-remain-unassigned-org-apache-lucene-index-corruptindexexception-codec-footer-mismatch/69184>\
**Category:** Elasticsearch\
**Created:** [December 15, 2016, 3:23pm UTC](https://discuss.elastic.co/t/new-shards-for-logstash-indices-remain-unassigned-org-apache-lucene-index-corruptindexexception-codec-footer-mismatch/69184 "2016-12-15T15:23:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![itkovian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itkovian/32/7269_2.png) [@itkovian](https://discuss.elastic.co/u/itkovian)\
**Post date:** [December 15, 2016, 3:23pm UTC](https://discuss.elastic.co/t/new-shards-for-logstash-indices-remain-unassigned-org-apache-lucene-index-corruptindexexception-codec-footer-mismatch/69184/1 "2016-12-15T15:23:08Z")

</div>

After updating to ES 5.1.1 and upgrading the machine OS to CentOS 7.2, I am seeing the cluster turn to RED, with the most recent logstash index having unassigned shards.

[ageorges@tangela2 ~]$ curl -XGET '192.168.24.1:9200/\_cat/health'  
1481815088 16:18:08 tangela red 2 2 921 476 0 2 31 0 - 96.5%

[ageorges@tangela2 ~]$ curl -XGET '192.168.24.1:9200/\_cat/shards?pretty' 2\>/dev/null | grep -v STARTED  
logstash-2016.12.15 4 p UNASSIGNED  
logstash-2016.12.15 4 r UNASSIGNED

The file referred to below in the trace lines

[2016-12-15T08:03:40,589][INFO][o.e.c.r.a.AllocationService] [[tangela1.ugent.be](http://tangela1.ugent.be)] Cluster health status changed from [YELLOW] to [RED] (reason: [shards failed [[logstash-2016.12.15][4]] ...]).  
[2016-12-15T13:36:44,191][WARN][o.e.c.a.s.ShardStateAction] [[tangela1.ugent.be](http://tangela1.ugent.be)] [logstash-2016.12.15][3] received shard failed for shard id [[logstash-2016.12.15][3]], allocation id [JOxwRSAYQtG-5wEMONJkNA], primary term [0], message [shard failure, reason [refresh failed]], failure [CorruptIndexException[compound sub-files must have a valid codec header and footer: file is too small (0 bytes) (resource=BufferedChecksumIndexInput(MMapIndexInput(path="/var/lib/elasticsearch/tangela/nodes/0/indices/AtvVrqs\_RP6Asrc7d14T\_w/3/index/\_1oq.dii")))]]  
org.apache.lucene.index.CorruptIndexException: compound sub-files must have a valid codec header and footer: file is too small (0 bytes) (resource=BufferedChecksumIndexInput(MMapIndexInput(path="/var/lib/elasticsearch/tangela/nodes/0/indices/AtvVrqs\_RP6Asrc7d14T\_w/3/index/\_1oq.dii")))

And

[root@tangela1 ~]# ls -l /var/lib/elasticsearch/tangela/nodes/0/indices/AtvVrqs\_RP6Asrc7d14T\_w/3/index/\_1oq.dii  
ls: cannot access /var/lib/elasticsearch/tangela/nodes/0/indices/AtvVrqs\_RP6Asrc7d14T\_w/3/index/\_1oq.dii: No such file or directory

For the logs, see [https://gist.github.com/itkovian/ead08bbd229ac6509cdd5cc82220a046](https://gist.github.com/itkovian/ead08bbd229ac6509cdd5cc82220a046)

-- Andy

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2017, 3:23pm UTC](https://discuss.elastic.co/t/new-shards-for-logstash-indices-remain-unassigned-org-apache-lucene-index-corruptindexexception-codec-footer-mismatch/69184/2 "2017-01-12T15:23:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
