# Some indexes have been deleted, now I see indexes called meow?

**URL:** <https://discuss.elastic.co/t/some-indexes-have-been-deleted-now-i-see-indexes-called-meow/242731>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 27, 2020, 10:16am UTC](https://discuss.elastic.co/t/some-indexes-have-been-deleted-now-i-see-indexes-called-meow/242731 "2020-07-27T10:16:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 27, 2020, 10:16am UTC](https://discuss.elastic.co/t/some-indexes-have-been-deleted-now-i-see-indexes-called-meow/242731/1 "2020-07-27T10:16:38Z")

</div>

If you have seen a number of your indices recently "disappear", and then when checking your logs you see they have been deleted, and you can also see other log entries that mention the term `meow`, like this;

```auto
[t19hfzgnp7-meow] creating index, cause [api], templates , shards [5]/[1], mappings 

```

You are likely running a cluster that is exposed to the internet with no protection, and have been hit by the "meow attack".

Your immediate steps should be to **upgrade to at least Elasticsearch 6.8.0 or 7.1.0** , which includes [**free security functionality**](https://www.elastic.co/blog/security-for-elasticsearch-is-now-free), containing;

- TLS for encrypted communications
- File and native realm for creating and managing users
- Role-based access control for controlling user access to cluster APIs and indexes; also allows multi-tenancy for Kibana with security for Kibana Spaces

Setting Security up is very easy to do. [The documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/secure-cluster.html) covers it in detail, and there are blog posts ([access control](https://www.elastic.co/blog/getting-started-with-elasticsearch-security) and [TLS setup](https://www.elastic.co/blog/configuring-ssl-tls-and-https-to-secure-elasticsearch-kibana-beats-and-logstash)) about the process too.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 27, 2020, 10:19am UTC](https://discuss.elastic.co/t/some-indexes-have-been-deleted-now-i-see-indexes-called-meow/242731/2 "2020-07-27T10:19:01Z")

</div>



---

<div class="post-metadata">

**Author:** ![ClubberLang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clubberlang/32/72169_2.png) [@ClubberLang](https://discuss.elastic.co/u/ClubberLang)\
**Post date:** [July 28, 2020, 6:38am UTC](https://discuss.elastic.co/t/some-indexes-have-been-deleted-now-i-see-indexes-called-meow/242731/3 "2020-07-28T06:38:24Z")

</div>

Hi,

I have try to setup basic authentication, with user+password, but my Elastic is down again!

Elastic is also running in a docker container, and only accessible from the "internal" network, so it shouldn't be accessible outside!

I also checked my log and see this message:

[kkdhh](https://swarmpit.socloze.com/#/tasks/kkdhhw8wrczfwght1yagvsmlp?log=1) {"type": "server", "timestamp": "2020-07-27T10:26:15,593Z", "level": "INFO", "component": "o.e.l.LicenseService", "cluster.name": "docker-cluster-es01", "node.name": "es01", "message": "license [bb6f69e3-456a-4cdc-8a2d-bf0c4e05ae22] mode [basic] - valid", "cluster.uuid": "gsJNPQLbQ4eAUvm32DA-Gg", "node.id": "lIx\_pBquQbaTTBxY-pM8Zg" }

[kkdhh](https://swarmpit.socloze.com/#/tasks/kkdhhw8wrczfwght1yagvsmlp?log=1) {"type": "server", "timestamp": "2020-07-27T10:26:15,600Z", "level": "INFO", "component": "o.e.x.s.s.SecurityStatusChangeListener", "cluster.name": "docker-cluster-es01", "node.name": "es01", "message": "Active license is now [BASIC]; Security is disabled", "cluster.uuid": "gsJNPQLbQ4eAUvm32DA-Gg", "node.id": "lIx\_pBquQbaTTBxY-pM8Zg" }

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 28, 2020, 6:41am UTC](https://discuss.elastic.co/t/some-indexes-have-been-deleted-now-i-see-indexes-called-meow/242731/4 "2020-07-28T06:41:42Z")

</div>

It's better if you continue your discussion in this thread - [ElasticSearch is being attacked?](https://discuss.elastic.co/t/elasticsearch-is-being-attacked/242727)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 25, 2020, 6:41am UTC](https://discuss.elastic.co/t/some-indexes-have-been-deleted-now-i-see-indexes-called-meow/242731/5 "2020-08-25T06:41:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
