# Restoring deleted elasticsearch indices

**URL:** https://discuss.elastic.co/t/restoring-deleted-elasticsearch-indices/259017
**Category:** Elasticsearch
**Created:** [December 17, 2020, 4:58pm UTC](https://discuss.elastic.co/t/restoring-deleted-elasticsearch-indices/259017 "2020-12-17T16:58:32Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![abi.mc](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@abi.mc](https://discuss.elastic.co/u/abi.mc)
#### Post date: [December 17, 2020, 4:58pm UTC](https://discuss.elastic.co/t/restoring-deleted-elasticsearch-indices/259017/1 "2020-12-17T16:58:32Z")

</div>

In kibana (two node cluster ) following indices got deleted from the file system and now kibana is not accessible :

```
bxexbuIpRXqA0n4VyXiDQA - .security-7
3R2woj_jRVCf58Q8b9--Yg - .apm-agent-configuration
RGR9AneMRx6nnQGHF0HqKg - .apm-custom-link
sA-j0eQBQf2po6HhP6AtMg - .async-search
NQ9QQDKnSEGZ9lUHu-Ezpw - .kibana_task_manager_1
_NVAa6tnTluggE2Q2x4vdw - .kibana_1
2Uw2D0vlQjiMQhZaPUkJQg - .kibana-event-log-7.8.0-000002

```

Status

```
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
yellow open .apm-custom-link RGR9AneMRx6nnQGHF0HqKg 1 1                                               
red open .kibana_task_manager_1 NQ9QQDKnSEGZ9lUHu-Ezpw 1 1                                               
yellow open .security-7 bxexbuIpRXqA0n4VyXiDQA 1 1                                               
yellow open .async-search sA-j0eQBQf2po6HhP6AtMg 1 1                                               
yellow open .apm-agent-configuration 3R2woj_jRVCf58Q8b9--Yg 1 1                                               
yellow open .kibana-event-log-7.8.0-000002 2Uw2D0vlQjiMQhZaPUkJQg 1 1                                               
red open .kibana_1 _NVAa6tnTluggE2Q2x4vdw 1 1

```

Seems .kibana\_1 contains all the kibana settings, dashboards, etc..

Getting following error when accessing kibana in browser

`{"statusCode":503,"error":"Service Unavailable","message":"No shard available for [get [.kibana][_doc][space:default]: routing [null]]: [no_shard_available_action_exception] No shard available for [get [.kibana][_doc][space:default]: routing [null]]"}`

Our elasticsearch holds around 400 GB of application log indices, which are working fine. I mean application log shipping and indexing and its access via ES API is working fine. Only issue is the kibana accessibility.  
Is there any way to recover these indices from file system backups ? There are no snapshot backups currently. We are having file system backup of the above indices. Is the below steps will work ? or what is the best approach to making kibana to be accessible.

- Delete the above indices from elasticsearch using curl
- Stop kibana
- Restore the corresponding indices to the indices location on the file system on both elastic search nodes
- Start kibana

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [December 17, 2020, 6:05pm UTC](https://discuss.elastic.co/t/restoring-deleted-elasticsearch-indices/259017/2 "2020-12-17T18:05:32Z")

</div>

Filesystem backups [have no value](https://www.elastic.co/guide/en/elasticsearch/reference/current/backup-cluster.html) but if you're sure those indices are gone then I think you can delete them using `curl` and then restart Kibana, without restoring anything, and it should create the missing indices again.

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [December 17, 2020, 6:18pm UTC](https://discuss.elastic.co/t/restoring-deleted-elasticsearch-indices/259017/3 "2020-12-17T18:18:52Z")

</div>

Note that you should only delete the `red` health indices, the `yellow` ones are fine and should go `green` eventually.

---

<div class="post-metadata">

### Author: ![abi.mc](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@abi.mc](https://discuss.elastic.co/u/abi.mc)
#### Post date: [December 21, 2020, 7:29am UTC](https://discuss.elastic.co/t/restoring-deleted-elasticsearch-indices/259017/4 "2020-12-21T07:29:32Z")

</div>

Thanks for your reply. We have deleted the red indices and restarted kibana on both nodes.

```auto
curl -X DELETE -k "https://127.0.0.1:9200/.kibana_1?pretty" -u xxxx
curl -X DELETE -k "https://127.0.0.1:9200/.kibana_task_manager_1?pretty" -u xxxx

```

Fortunately we had a json export of the kibana dashboards, visualizations etc which we were able to import and restore.

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [December 21, 2020, 7:44am UTC](https://discuss.elastic.co/t/restoring-deleted-elasticsearch-indices/259017/5 "2020-12-21T07:44:20Z")

</div>

> [@abi.mc](#):
>
> Fortunately we had a json export of the kibana dashboards, visualizations etc which we were able to import and restore.

That's a relief 🙂

Recommend you set up proper snapshots ASAP in case next time you lose something more irreplaceable. Also don't ever delete anything from the data path by hand - this can lead to losing the whole node.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 18, 2021, 7:44am UTC](https://discuss.elastic.co/t/restoring-deleted-elasticsearch-indices/259017/6 "2021-01-18T07:44:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
