# Reindex just one specific index in datastrem

**URL:** <https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079>\
**Category:** Elasticsearch\
**Created:** [October 20, 2022, 7:58am UTC](https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079 "2022-10-20T07:58:15Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Oleksandr\_Isniuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oleksandr_isniuk/32/106217_2.png) [@Oleksandr\_Isniuk](https://discuss.elastic.co/u/Oleksandr_Isniuk)\
**Post date:** [October 20, 2022, 7:58am UTC](https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079/1 "2022-10-20T07:58:15Z")

</div>

We changed field mappings in our template. After rollover new index file works with correct field types. We supposed that we can use smaller time ranges to be sure that all data was read fro the new file. But it is not enough. It is fields from newly introduced data. So we need just to reindex one previous index. Are there any ways to do so and avoid reindexing of whole Data Stream?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 23, 2022, 11:19pm UTC](https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079/2 "2022-10-23T23:19:46Z")

</div>

Welcome to our community! 😃

If you know the names of the underlying indices you can run a manual reindex back into the datastream, and then delete the old indices.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 24, 2022, 1:27am UTC](https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079/3 "2022-10-24T01:27:21Z")

</div>

If you reindex old data into the data stream, will that not mess up the retention period for that data?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 24, 2022, 1:50am UTC](https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079/4 "2022-10-24T01:50:36Z")

</div>

Retention is based on index age, so it will change it a bit yes as a newer index will hold older data.

I guess it comes back to how important it is to have that data around and if they are able to hold it for a bit longer.

---

<div class="post-metadata">

**Author:** ![Oleksandr\_Isniuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oleksandr_isniuk/32/106217_2.png) [@Oleksandr\_Isniuk](https://discuss.elastic.co/u/Oleksandr_Isniuk)\
**Post date:** [October 27, 2022, 12:56pm UTC](https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079/5 "2022-10-27T12:56:16Z")

</div>

@warkolm thanks for the recommendation. I guess idea is to clone an index I need to reindex in some separate space. And reindex afterward directly into the data stream as new data but with old timestamps in log entries. Am I got you right?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 29, 2022, 5:36am UTC](https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079/6 "2022-10-29T05:36:08Z")

</div>

That still won't change the retention of the data, because the index itself will be newer than the original timestamps.

---

<div class="post-metadata">

**Author:** ![Oleksandr\_Isniuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oleksandr_isniuk/32/106217_2.png) [@Oleksandr\_Isniuk](https://discuss.elastic.co/u/Oleksandr_Isniuk)\
**Post date:** [November 4, 2022, 12:02pm UTC](https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079/9 "2022-11-04T12:02:24Z")

</div>

@warkolm thanks. It mostly works for me. The previous try was on a testing data stream. And I tried to reindex opened index. That's why I supposed a cloning step. But I encountered an error.

```auto
{
  "completed" : true,
  "task" : {
    "node" : "my-node-id",
    "id" : 31873238,
    "type" : "transport",
    "action" : "indices:data/write/reindex",
    "status" : {
      "total" : 91856040,
      "updated" : 0,
      "created" : 45873998,
      "deleted" : 0,
      "batches" : 45874,
      "version_conflicts" : 0,
      "noops" : 0,
      "retries" : {
        "bulk" : 0,
        "search" : 0
      },
      "throttled_millis" : 0,
      "requests_per_second" : -1.0,
      "throttled_until_millis" : 0
    },
    "description" : "reindex from [.myindex] to [mydatastream][_doc]",
    "start_time_in_millis" : 1667470198137,
    "running_time_in_nanos" : 74895189349592,
    "cancellable" : true,
    "cancelled" : false,
    "headers" : { }
  },
  "response" : {
    "took" : 74895188,
    "timed_out" : false,
    "total" : 91856040,
    "updated" : 0,
    "created" : 45873998,
    "deleted" : 0,
    "batches" : 45874,
    "version_conflicts" : 0,
    "noops" : 0,
    "retries" : {
      "bulk" : 0,
      "search" : 0
    },
    "throttled" : "0s",
    "throttled_millis" : 0,
    "requests_per_second" : -1.0,
    "throttled_until" : "0s",
    "throttled_until_millis" : 0,
    "failures" : [
      {
        "index" : ".newindex",
        "type" : "_doc",
        "id" : "mydocid",
        "cause" : {
          "type" : "mapper_parsing_exception",
          "reason" : "failed to parse",
          "caused_by" : {
            "type" : "illegal_argument_exception",
            "reason" : "Limit of total fields [1000] has been exceeded while adding new fields [2]"
          }
        },
        "status" : 400
      },
      {
        "index" : ".myindex",
        "type" : "_doc",
        "id" : "mydocid",
        "cause" : {
          "type" : "mapper_parsing_exception",
          "reason" : "failed to parse",
          "caused_by" : {
            "type" : "illegal_argument_exception",
            "reason" : "Limit of total fields [1000] has been exceeded while adding new fields [2]"
          }
        },
        "status" : 400
      }
    ]
  }
}

```

Is there any chance to continue on error and just log them? I reindexed just about 180Gb of 280Gb index. And this was not the first error. I previously deleted old data from new indexes(evaluated as duplicated), made some changes to field mappings and started new reindex task.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 7, 2022, 3:19am UTC](https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079/10 "2022-11-07T03:19:48Z")

</div>

Your best option there would be to increase the mapping limit for the index so you can you complete the reindex. Otherwise you could try [ignore\_malformed | Elasticsearch Guide [8.5] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.5/ignore-malformed.html).

---

<div class="post-metadata">

**Author:** ![Oleksandr\_Isniuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oleksandr_isniuk/32/106217_2.png) [@Oleksandr\_Isniuk](https://discuss.elastic.co/u/Oleksandr_Isniuk)\
**Post date:** [November 10, 2022, 3:58pm UTC](https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079/11 "2022-11-10T15:58:35Z")

</div>

@warkolm thank you. You helped a lot.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2022, 3:59pm UTC](https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079/12 "2022-12-08T15:59:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
