# Rollover Index issue with Elasticsearch 6.2

**URL:** <https://discuss.elastic.co/t/rollover-index-issue-with-elasticsearch-6-2/123852>\
**Category:** Elasticsearch\
**Created:** [March 14, 2018, 7:23am UTC](https://discuss.elastic.co/t/rollover-index-issue-with-elasticsearch-6-2/123852 "2018-03-14T07:23:03Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![somnath.guthula](https://avatars.discourse-cdn.com/v4/letter/s/b38774/32.png) [@somnath.guthula](https://discuss.elastic.co/u/somnath.guthula)\
**Post date:** [March 14, 2018, 7:23am UTC](https://discuss.elastic.co/t/rollover-index-issue-with-elasticsearch-6-2/123852/1 "2018-03-14T07:23:03Z")

</div>

Hi guys, I am having an issue with rolling over indices.

So, We were trying a rollover indice with our newly setup cluster with Elasticsearch 6.2

When we are trying to rollover the indice, It gives the following error.

```
{
  "error": {
    "root_cause": [
      {
        "type": "illegal_argument_exception",
        "reason": "Rollover alias [active-fusion-logs] can point to multiple indices, found duplicated alias [[search-fusion-logs, active-fusion-logs]] in index template [fusion-logs]"
      }
    ],
    "type": "illegal_argument_exception",
    "reason": "Rollover alias [active-fusion-logs] can point to multiple indices, found duplicated alias [[search-fusion-logs, active-fusion-logs]] in index template [fusion-logs]"
  },
  "status": 400
}

```

Please find details below of the template that we are having and steps that I used. This can be fairly used to reproduce the issue.

Template name : fusion-logs

```
PUT _template/fusion-logs
{
  "template": "fusion-logs-*",
  "settings": {
    "number_of_shards": 2,
    "number_of_replicas": 1,
    "routing.allocation.include.box_type": "hot"
  },
  "aliases": {
    "active-fusion-logs": {},
    "search-fusion-logs": {}
  },
  "mappings": {
    "logs": {
      "properties": {
        "host": {
          "type": "keyword"
        },
        "job_id": {
          "type": "keyword"
        },
        "job_result": {
          "type": "keyword"
        }
      }
    }
  }
}

```

We inserted a 1000 documents in the above active-fusion-logs index and then used the following to roll over the index

```
POST active-fusion-logs/_rollover
{
  "conditions": {
    "max_docs": 1000
  }
}

```

The above API gives us an error when we are trying to rollover

Some other info about the cluster.

1. There is no other index other than the above index.
2. active-fusion-logs is aliased to just one write index
3. search-fusion-logs is aliased to multiple indexes

Also, I had tried the same thing with Elasticsearch 5.3.2 and it worked as expected without the error.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 14, 2018, 7:54am UTC](https://discuss.elastic.co/t/rollover-index-issue-with-elasticsearch-6-2/123852/2 "2018-03-14T07:54:49Z")

</div>

The thing is that your write alias can indeed point by definition to multiple indices here.

When you rollover the alias, it will create another index with the same prefix.  
So at some point you will have:

- the old index with the write alias on it
- the new index with the write alias on it (because it's in the template)

This can lead to inconsistency.

I'm not surprised by this behavior then which protects you from that.

My 2 cents

---

<div class="post-metadata">

**Author:** ![somnath.guthula](https://avatars.discourse-cdn.com/v4/letter/s/b38774/32.png) [@somnath.guthula](https://discuss.elastic.co/u/somnath.guthula)\
**Post date:** [March 14, 2018, 8:06am UTC](https://discuss.elastic.co/t/rollover-index-issue-with-elasticsearch-6-2/123852/3 "2018-03-14T08:06:57Z")

</div>

Thanks for the quick response.

I was referring to the following article.

> **[And the big one said "Rollover" — Managing Elasticsearch time-based indices...](https://www.elastic.co/blog/managing-time-based-indices-efficiently)**
>
> Introducing the new Rollover Pattern, and the APIs which support it, which is a simpler, more efficient way of managing time-based indices in Elasticsearch.

Please correct me if I am wrong, but whenever we roll an index, isn't the write alias shifted from the old indice to the new indice that is rolled over?

The above works perfectly fine with Elasticsearch 5.3.2. When I rollover, the write alias is shifted automatically to the new rolled index.

If this is not the case with Elasticsearch 6.2, could you please help me with what am I missing here? How do I rollover?

Thanks in advance! 🙂

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 14, 2018, 3:22pm UTC](https://discuss.elastic.co/t/rollover-index-issue-with-elasticsearch-6-2/123852/4 "2018-03-14T15:22:40Z")

</div>

> [@somnath.guthula](#):
>
> isn't the write alias shifted from the old indice to the new indice that is rolled over?

That's true.

What is happening here "I think" is that your template sets it as well. Practically you should write your template as:

```auto
PUT _template/fusion-logs
{
  "template": "fusion-logs-*",
  "settings": {
    "number_of_shards": 2,
    "number_of_replicas": 1,
    "routing.allocation.include.box_type": "hot"
  },
  "aliases": {
    "search-fusion-logs": {}
  },
  "mappings": {
    "logs": {
      "properties": {
        "host": {
          "type": "keyword"
        },
        "job_id": {
          "type": "keyword"
        },
        "job_result": {
          "type": "keyword"
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![justin.purdy](https://avatars.discourse-cdn.com/v4/letter/j/59ef9b/32.png) [@justin.purdy](https://discuss.elastic.co/u/justin.purdy)\
**Post date:** [March 24, 2018, 7:16pm UTC](https://discuss.elastic.co/t/rollover-index-issue-with-elasticsearch-6-2/123852/5 "2018-03-24T19:16:08Z")

</div>

Just upgraded to 6.2.3 myself, and this issue is hitting me as well. Am I understanding correctly that prefixes are effectively the same as aliases for the purposes of the rollover API as of 6.2.x?

---

<div class="post-metadata">

**Author:** ![nhat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nhat/32/22170_2.png) [@nhat](https://discuss.elastic.co/u/nhat)\
**Post date:** [March 25, 2018, 1:26am UTC](https://discuss.elastic.co/t/rollover-index-issue-with-elasticsearch-6-2/123852/6 "2018-03-25T01:26:14Z")

</div>

@dadoonet has explained this really well. I would like to add more information here. We fail a rollover request in v6.2.0 if the rollover alias found in the index templates. Having the same rollover alias in index templates can cause the rollover alias point to multiple indices. Rollover action consists of two separate steps: (1) Create a new index and wait for that index to be ready; (2) Updates the alias to point to the new index. If the index template's aliases contain the rollover alias, the rollover alias will point to two indices between step 1 and step 2.

CL: [https://github.com/elastic/elasticsearch/pull/28110](https://github.com/elastic/elasticsearch/pull/28110)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 22, 2018, 1:26am UTC](https://discuss.elastic.co/t/rollover-index-issue-with-elasticsearch-6-2/123852/7 "2018-04-22T01:26:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
