# Template for .monitoring\* indices

**URL:** <https://discuss.elastic.co/t/template-for-monitoring-indices/161636>\
**Category:** Elasticsearch\
**Created:** [December 20, 2018, 7:43am UTC](https://discuss.elastic.co/t/template-for-monitoring-indices/161636 "2018-12-20T07:43:00Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hari\_Prasad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hari_prasad/32/56784_2.png) [@Hari\_Prasad](https://discuss.elastic.co/u/Hari_Prasad)\
**Post date:** [December 20, 2018, 7:43am UTC](https://discuss.elastic.co/t/template-for-monitoring-indices/161636/1 "2018-12-20T07:43:00Z")

</div>

Hi,  
In my setup I am using template from Logstash to set the configuration for various indices that are being created in Elasticsearch. But I am not able to do the same for the monitoring indices, that is .monitoring-es\*, .monitoring-logstash\*, etc.  
I found that I can set them with REST calls but I would like the settings to be applied automatically without executing any queries. Need help for the same.

Thank you in advance

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 20, 2018, 7:52am UTC](https://discuss.elastic.co/t/template-for-monitoring-indices/161636/2 "2018-12-20T07:52:29Z")

</div>

Why do you want to change those template?

---

<div class="post-metadata">

**Author:** ![Hari\_Prasad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hari_prasad/32/56784_2.png) [@Hari\_Prasad](https://discuss.elastic.co/u/Hari_Prasad)\
**Post date:** [December 20, 2018, 8:28am UTC](https://discuss.elastic.co/t/template-for-monitoring-indices/161636/3 "2018-12-20T08:28:46Z")

</div>

I would like to increase the replica count. This is mainly because there are multiple occasions where the shards are failing over a restart and the cluster is in unusable state

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 20, 2018, 8:37am UTC](https://discuss.elastic.co/t/template-for-monitoring-indices/161636/4 "2018-12-20T08:37:34Z")

</div>

Why does the cluster get into an unusable state? How many master-eligible nodes do you have in the cluster? What is `discovery.zen.minimum_master_nodes` set to?

---

<div class="post-metadata">

**Author:** ![Hari\_Prasad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hari_prasad/32/56784_2.png) [@Hari\_Prasad](https://discuss.elastic.co/u/Hari_Prasad)\
**Post date:** [December 20, 2018, 9:13am UTC](https://discuss.elastic.co/t/template-for-monitoring-indices/161636/5 "2018-12-20T09:13:51Z")

</div>

Master eligible nodes are 2. (I know this setting is to be an odd number)  
I am getting error like below

.monitoring-logstash-6-2018.12.12/PJ98ndmCTl-R1c1qUTGpng]] can not be imported as a dangling index, as an index with the same name and UUID exist in the index tombstones. This situation is likely caused by copying over the data directory for an index that was previously deleted.

(DATA folder was not copied or deleted. Only restarted )

org.elasticsearch.action.UnavailableShardsException: [.monitoring-es-6-2018.12.20][0] primary shard is not active Timeout: [1m], request: [BulkShardRequest [[.monitoring-es-6-2018.12.20][0]] containing [index {[.monitoring-es-6-2018.12.20][doc][MrzYymcBNIueI7r1YAIm], source[{"cluster\_uuid":"lqoa3HJhRPyUAQUkLgFeqw","timestamp":"2018-12-20T09:00:37.283Z","interval\_ms":10000,"type":"node\_stats","source\_node":{"uuid":"LdsS8QO7SUauL7vUOYljMw","host":"xxxxxxx","transport\_address":"xxxxxxxx","ip":"xxxxxx","name":"elklog02","timestamp":"2018-12-20T09:00:37.283Z"},"node\_stats":{"node\_id":"LdsS8QO7SUauL7vUOYljMw","node\_master":false,"mlockall":false,"indices":{"docs":{"count":0},"store":{"size\_in\_bytes":0},"indexing":{"index\_total":0,"index\_time\_in\_millis":0,"throttle\_time\_in\_millis":0},"search":{"query\_total":0,"query\_time\_in\_millis":0},"query\_cache":{"memory\_size\_in\_bytes":0,"hit\_count":0,"miss\_count":0,"evictions":0},"fielddata":{"memory\_size\_in\_bytes":0,"evictions":0},"segments":{"count":0,"memory\_in\_bytes":0,"terms\_memory\_in\_bytes":0,"stored\_fields\_memory\_in\_bytes":0,"term\_vectors\_memory\_in\_bytes":0,"norms\_memory\_in\_bytes":0,"points\_memory\_in\_bytes":0,"doc\_values\_memory\_in\_bytes":0,"index\_writer\_memory\_in\_bytes":0,"version\_map\_memory\_in\_bytes":0,"fixed\_bit\_set\_memory\_in\_bytes":0},"request\_cache":{"memory\_size\_in\_bytes":0,"evictions":0,"hit\_count":0,"miss\_count":0}},"os":{"cpu":{"load\_average":{"1m":0.06,"5m":0.27,"15m":0.47}},"cgroup":{"cpuacct":{"control\_group":"/","usage\_nanos":329135454114692},"cpu":{"control\_group":"/","cfs\_period\_micros":100000,"cfs\_quota\_micros":-1,"stat":{"number\_of\_elapsed\_periods":0,"number\_of\_times\_throttled":0,"time\_throttled\_nanos":0}},"memory":{"control\_group":"/","limit\_in\_bytes":"9223372036854771712","usage\_in\_bytes":"7188840448"}}},"process":{"open\_file\_descriptors":353,"max\_file\_descriptors":65536,"cpu":{"percent":1}},"jvm":{"mem":{"heap\_used\_in\_bytes":883829600,"heap\_used\_percent":27,"heap\_max\_in\_bytes":3203792896},"gc":{"collectors":{"young":{"collection\_count":218,"collection\_time\_in\_millis":7084},"old":{"collection\_count":2,"collection\_time\_in\_millis":88}}}},"thread\_pool":{"generic":{"threads":53,"queue":0,"rejected":0},"get":{"threads":0,"queue":0,"rejected":0},"index":{"threads":0,"queue":0,"rejected":0},"management":{"threads":2,"queue":0,"rejected":0},"search":{"threads":0,"queue":0,"rejected":0},"watcher":{"threads":0,"queue":0,"rejected":0},"write":{"threads":0,"queue":0,"rejected":0}},"fs":{"total":{"total\_in\_bytes":50986217472,"free\_in\_bytes":45045489664,"available\_in\_bytes":45045489664},"io\_stats":{"total":{"operations":43899,"read\_operations":33705,"write\_operations":10194,"read\_kilobytes":1088276,"write\_kilobytes":147328}}}}}]}]]

Also please point me to setting the monitoring indices template as well.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 20, 2018, 9:31am UTC](https://discuss.elastic.co/t/template-for-monitoring-indices/161636/6 "2018-12-20T09:31:23Z")

</div>

> [@Hari\_Prasad](#):
>
> Master eligible nodes are 2. (I know this setting is to be an odd number)

This is indeed not ideal. If you want a highly available cluster it has to be at least 3. Is `discovery.zen.minimum_master_nodes` set correctly according to [these guidelines](https://www.elastic.co/guide/en/elasticsearch/reference/6.5/modules-node.html#split-brain)?

---

<div class="post-metadata">

**Author:** ![Hari\_Prasad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hari_prasad/32/56784_2.png) [@Hari\_Prasad](https://discuss.elastic.co/u/Hari_Prasad)\
**Post date:** [December 20, 2018, 9:41am UTC](https://discuss.elastic.co/t/template-for-monitoring-indices/161636/7 "2018-12-20T09:41:16Z")

</div>

I did it after posting the previous reply, Thank you. Am I correct to say that dangling index is generally caused by split brain?  
But why UnavailableShardsException is caused. Can you please provide explanation for this.

---

<div class="post-metadata">

**Author:** ![Hari\_Prasad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hari_prasad/32/56784_2.png) [@Hari\_Prasad](https://discuss.elastic.co/u/Hari_Prasad)\
**Post date:** [December 20, 2018, 3:28pm UTC](https://discuss.elastic.co/t/template-for-monitoring-indices/161636/8 "2018-12-20T15:28:08Z")

</div>

I have the min master node count set but I am still getting the below exception on restart

org.elasticsearch.action.UnavailableShardsException: [.monitoring-es-6-2018.12.20][0] primary shard is not active Timeout: [1m]

---

<div class="post-metadata">

**Author:** ![Hari\_Prasad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hari_prasad/32/56784_2.png) [@Hari\_Prasad](https://discuss.elastic.co/u/Hari_Prasad)\
**Post date:** [December 21, 2018, 11:49am UTC](https://discuss.elastic.co/t/template-for-monitoring-indices/161636/9 "2018-12-21T11:49:40Z")

</div>

I got the answer for shards being unavailable. This was because the cluster.routing.allocation.node\_initial\_primaries\_recoveries was as default value of 2. Hence it took time to recover the primary shard. Increasing this solved the above mentioned issue.  
I got this answer by executing the below query

```
GET /_cluster/allocation/explain
{
  "index": ".monitoring-es-6-2018.12.20",
  "shard": 0,
  "primary": true
}

```

**But I still do not have answer regarding how the template can be set for the monitoring indices.**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2019, 11:49am UTC](https://discuss.elastic.co/t/template-for-monitoring-indices/161636/10 "2019-01-18T11:49:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
