# Remove random indexes

**URL:** <https://discuss.elastic.co/t/remove-random-indexes/331066>\
**Category:** Elasticsearch\
**Created:** [April 28, 2023, 2:48pm UTC](https://discuss.elastic.co/t/remove-random-indexes/331066 "2023-04-28T14:48:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marcelo\_Moro\_Brondan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcelo_moro_brondan/32/120388_2.png) [@Marcelo\_Moro\_Brondan](https://discuss.elastic.co/u/Marcelo_Moro_Brondan)\
**Post date:** [April 28, 2023, 2:48pm UTC](https://discuss.elastic.co/t/remove-random-indexes/331066/1 "2023-04-28T14:48:02Z")

</div>

remove random indexesremove random indexesHello!

I have an elasticsearch 5.6 in centOS 7 and it is behaving unexpectedly. Random indexes are being created. I am not able to identify the origin and apply a configuration that can block/remove these indexes.

Example:  
curl -XGET HOST:9200/\_cat/indices  
#output:  
index.action  
index.cfm  
index.html  
index.cgi  
index.do  
index.htm  
index.aspx  
index.asp  
index.jsp  
index.py  
index.pl  
index.php

I can temporarily fix it like this:

# Delete unmapped indexes:

curl -X DELETE "HOST:9200/index.\*

# configuring number of replicas:

curl -X PUT -H 'Content-Type: application/json' 'HOST:9200/\_settings' -d '{"number\_of\_replicas":0}'

How can we resolve this? Is there a way to configure it in a file?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2023, 2:48pm UTC](https://discuss.elastic.co/t/remove-random-indexes/331066/2 "2023-04-28T14:48:03Z")

</div>

elasticsearch 5.6 is [EOL](https://www.elastic.co/support/eol) and no longer supported. Please upgrade ASAP.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 28, 2023, 2:59pm UTC](https://discuss.elastic.co/t/remove-random-indexes/331066/3 "2023-04-28T14:59:17Z")

</div>

This typically indicates that your cluster does not have any security enabled and is accessible either from the internet or some internal vulnerability scanning tool.

The version you are running is very old and EOL, so I would recommend upgrading to the latest version where basic security is available out of the box. Enabling security would resolve this issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2023, 3:00pm UTC](https://discuss.elastic.co/t/remove-random-indexes/331066/4 "2023-05-26T15:00:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
