# Please help - ES 2.1.1 cluster randomly crashing

**URL:** <https://discuss.elastic.co/t/please-help-es-2-1-1-cluster-randomly-crashing/38861>\
**Category:** Elasticsearch\
**Created:** [January 11, 2016, 10:02am UTC](https://discuss.elastic.co/t/please-help-es-2-1-1-cluster-randomly-crashing/38861 "2016-01-11T10:02:55Z")\
**Posts on this page:** 1\
**Showing post:** 14

<div class="post-metadata">

**Author:** ![plonka2000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/plonka2000/32/5077_2.png) [@plonka2000](https://discuss.elastic.co/u/plonka2000)\
**Post date:** [January 14, 2016, 2:47pm UTC](https://discuss.elastic.co/t/please-help-es-2-1-1-cluster-randomly-crashing/38861/14 "2016-01-14T14:47:15Z")

</div>

@dadoonet and @Christian_Dahlqvist you've helped me a lot. **_Thanks!_**

I've rebuilt my cluster, and it's now running much faster (Although I cant speak for stability yet).  
I did this by setting my elasticsearch output `index => "logstash-%{+YYYY.MM}"` to a single index, rather than let it build a new index for each day.

My updated status:  
-3 indices  
-22 shards  
-490,000 documents (currently)  
-Heap usage is between 20% and 50%

So far it looks good, but I've discovered a strange issue of duplicate events.  
I don't want to hijack this thread, so I created another [here](https://discuss.elastic.co/t/duplicate-logs-logstash-input-s3/39231) to explain the issue.

Maybe you might be able to have a look in there if you're interested.

Thanks.

---

_[View the full topic](https://discuss.elastic.co/t/please-help-es-2-1-1-cluster-randomly-crashing/38861)._
