Strange indicies

Hello everyone!
I have a ES cluster - 1master(with logstash) and 3 data nodes.
Few days ago I noticed strange thing.
In KOPF strange indicies began to appear: http://prntscr.com/80m51b
I delete them, but next day they back again!
Can anyone tell me what the * is going on? :slight_smile:
Thanks!

It looks like your ES cluster is wide open to the Internet or that there's malicious software on your internal network. Find the hole and close it.

There is no NAT for cluster.
I will scan my system, its strange.

How is this related to network address translation?

My cluster works in LAN. And to Internet we go through NAT.
How it can be wide open else? Maybe I dont understand something(

There must be curl requests somewhere to create these indices.
Am I right?