I have a Graylog 3.1.3 system. In adding an elasticsearch node to the elasticsearch cluster, I accidentally started elasticsearch with a later version of elasticsearch than is in the existing cluster. One of the 5 shards of the ‘gl-events’ index was migrated to that node. I realised my error and reinstalled the correct, earlier version of elasticsearch on the new node. Now the elasticsearch cluster is red because it is missing one of the shards of the ‘gl-events’ index.
I’ve restarted the Graylog master node in an attempt to fix the situation, but it persists.
How to fix it? Can I delete the index, and assume it will be automatically recreated? Can I add replica shards to the index to avoid this issue happening in future?