# Deflector exists as an index and is not an alias. Again

**URL:** <https://community.graylog.org/t/deflector-exists-as-an-index-and-is-not-an-alias-again/5814>\
**Category:** Graylog Central (peer support)\
**Created:** [June 29, 2018, 5:47am UTC](https://community.graylog.org/t/deflector-exists-as-an-index-and-is-not-an-alias-again/5814 "2018-06-29T05:47:20Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sarnold270](https://avatars.discourse-cdn.com/v4/letter/s/3bc359/32.png) [@sarnold270](https://community.graylog.org/u/sarnold270)\
**Post date:** [June 29, 2018, 5:47am UTC](https://community.graylog.org/t/deflector-exists-as-an-index-and-is-not-an-alias-again/5814/1 "2018-06-29T05:47:20Z")

</div>

Hey everyone, we receive following error in Graylog: “Error in Deflector exists as an index and is not an alias. (triggered an hour ago)  
The deflector is meant to be an alias but exists as an index. Multiple failures of infrastructure can lead to this. Your messages are still indexed but searches and all maintenance tasks will fail or produce incorrect results”.

Also, under System/Overview in log this is replicating “There is no index target to point to. Creating one now”.

We are running Elasticsearch 1.7.3, Mongodb 3.4.15, and Graylog-Server 2.3.2 on Ubuntu Server 16.04. All is running on same server.

We already tried to stop graylog service, running curl -X DELETE ‘[http://127.0.0.1:9200/graylog\_deflector](http://127.0.0.1:9200/graylog_deflector)’ and restarting service but no avail.

Also this from Local Inputs - Syslog UDP Traffic (yes, we modified rsyslog.conf for binding address and changed port 5140):  
allow\_override\_date: true  
bind\_address: 127.0.0.1  
expand\_structured\_data: false  
force\_rdns: false  
override\_source:   
port: 5140  
recv\_buffer\_size: 262144  
store\_full\_message: false

This is our first Graylog server so I am new at this. Any help will be greatly appreciated. Hope to get over this hurdle soon. It’s getting really late here.

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 29, 2018, 7:13am UTC](https://community.graylog.org/t/deflector-exists-as-an-index-and-is-not-an-alias-again/5814/2 "2018-06-29T07:13:13Z")

</div>

> We are running Elasticsearch 1.7.3, Mongodb 3.4.15, and Graylog-Server 2.3.2 on Ubuntu Server 16.04. All is running on same server.

I’m pretty sure that one of the above Versions does not match - Elasticsearch or Graylog - as those both are not compatible. If they work you are in unsupported stage that was never tested!

You can find the answer in our FAQ

[http://docs.graylog.org/en/2.4/pages/faq.html#how-do-i-fix-the-deflector-exists-as-an-index-and-is-not-an-alias-error-message](http://docs.graylog.org/en/2.4/pages/faq.html#how-do-i-fix-the-deflector-exists-as-an-index-and-is-not-an-alias-error-message)

---

<div class="post-metadata">

**Author:** ![sarnold270](https://avatars.discourse-cdn.com/v4/letter/s/3bc359/32.png) [@sarnold270](https://community.graylog.org/u/sarnold270)\
**Post date:** [June 29, 2018, 7:00pm UTC](https://community.graylog.org/t/deflector-exists-as-an-index-and-is-not-an-alias-again/5814/3 "2018-06-29T19:00:12Z")

</div>

Jan, what version does Elasticsearch, Mongodb ad Graylog-Server need to be on to function properly?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [June 29, 2018, 8:52pm UTC](https://community.graylog.org/t/deflector-exists-as-an-index-and-is-not-an-alias-again/5814/4 "2018-06-29T20:52:55Z")

</div>

[http://docs.graylog.org/en/2.4/pages/installation.html#system-requirements](http://docs.graylog.org/en/2.4/pages/installation.html#system-requirements)

---

<div class="post-metadata">

**Author:** ![sarnold270](https://avatars.discourse-cdn.com/v4/letter/s/3bc359/32.png) [@sarnold270](https://community.graylog.org/u/sarnold270)\
**Post date:** [July 2, 2018, 7:16am UTC](https://community.graylog.org/t/deflector-exists-as-an-index-and-is-not-an-alias-again/5814/5 "2018-07-02T07:16:32Z")

</div>

OK. We updated Elasticsearch to 2.3.5, Mongodb is 3.4.15 and Graylog-Server is 2.4.5 but still receiving the same message:  
Deflector exists as an index and is not an alias. (triggered 11 minutes ago)  
The deflector is meant to be an alias but exists as an index. Multiple failures of infrastructure can lead to this. Your messages are still indexed but searches and all maintenance tasks will fail or produce incorrect results. It is strongly recommend that you act as soon as possible.  
When we go to “Show Received Messages” under Local Input it says “Loading”.

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [July 2, 2018, 7:28am UTC](https://community.graylog.org/t/deflector-exists-as-an-index-and-is-not-an-alias-again/5814/6 "2018-07-02T07:28:41Z")

</div>

You might want to read the FAQ entry linked in @jan’s reply:

> [@Deflector exists as an index and is not an alias. Again](https://community.graylog.org/t/deflector-exists-as-an-index-and-is-not-an-alias-again/5814/2):
>
> We are running Elasticsearch 1.7.3, Mongodb 3.4.15, and Graylog-Server 2.3.2 on Ubuntu Server 16.04. All is running on same server. I’m pretty sure that one of the above Versions does not match - Elasticsearch or Graylog - as those both are not compatible. If they work you are in unsupported stage that was never tested! You can find the answer in our FAQ [http://docs.graylog.org/en/2.4/pages/faq.html#how-do-i-fix-the-deflector-exists-as-an-index-and-is-not-an-alias-error-message](http://docs.graylog.org/en/2.4/pages/faq.html#how-do-i-fix-the-deflector-exists-as-an-index-and-is-not-an-alias-error-message)

---

<div class="post-metadata">

**Author:** ![sarnold270](https://avatars.discourse-cdn.com/v4/letter/s/3bc359/32.png) [@sarnold270](https://community.graylog.org/u/sarnold270)\
**Post date:** [July 10, 2018, 5:10pm UTC](https://community.graylog.org/t/deflector-exists-as-an-index-and-is-not-an-alias-again/5814/7 "2018-07-10T17:10:54Z")

</div>

Jochen, that resolved our issue. It is now logging!!! Thank you and everyone for your time and assistance in getting graylog up and running. Plus, you have lots of great docs to research for issues. We have another client in need of SIEM Logging server. We will go with Graylog.

Thanks Again,  
SA

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [July 24, 2018, 5:10pm UTC](https://community.graylog.org/t/deflector-exists-as-an-index-and-is-not-an-alias-again/5814/8 "2018-07-24T17:10:55Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
