# Graylog Empty - Elastic Search Problem Deflector is pointing to \[graylog\_729\], not the newest one: \[graylog\_730\]. Re-pointing

**URL:** <https://community.graylog.org/t/graylog-empty-elastic-search-problem-deflector-is-pointing-to-graylog-729-not-the-newest-one-graylog-730-re-pointing/21992>\
**Category:** Graylog Central (peer support)\
**Created:** [December 8, 2021, 1:39pm UTC](https://community.graylog.org/t/graylog-empty-elastic-search-problem-deflector-is-pointing-to-graylog-729-not-the-newest-one-graylog-730-re-pointing/21992 "2021-12-08T13:39:18Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [December 8, 2021, 10:50pm UTC](https://community.graylog.org/t/graylog-empty-elastic-search-problem-deflector-is-pointing-to-graylog-729-not-the-newest-one-graylog-730-re-pointing/21992/2 "2021-12-08T22:50:47Z")

</div>

Hello,

> [@RalfThomas](#):
>
> message Deflector is pointing to [graylog\_729], not the newest one

This post may help.

> [@Index rotation failure](https://community.graylog.org/t/index-rotation-failure/11887):
>
> Hello. I’m running Graylog 3.1.0 on a test system, and last Friday, apparently, it’s run into problems trying to rotate its indices. It is still showing the problem, here’s a sample from the current log (server.log): 2019-09-09T08:22:22.890+02:00 WARN [IndexRotationThread] Deflector is pointing to [firewall-1\_10], not the newest one: [firewall-1\_11]. Re-pointing. 2019-09-09T08:22:22.902+02:00 ERROR [IndexRotationThread] Couldn’t point deflector to a new index org.graylog2.indexer.Elasticsear…

EDIT: I also found this for you.

> <https://github.com/Graylog2/graylog2-server/issues/5843>
>
> My graylog instance got stuck with the error:
> 
> \`\`\`
> 2019-04-04 11:08:15,021 WA…RN : org.graylog2.periodical.IndexRotationThread - Deflector is pointing to \[graylog\_151\], not the newest one: \[graylog\_152\]. Re-pointing.
> 2019-04-04 11:08:15,048 ERROR: org.graylog2.periodical.IndexRotationThread - Couldn't point deflector to a new index
> org.graylog2.indexer.ElasticsearchException: Couldn't switch alias graylog\_deflector from index graylog\_151 to index graylog\_152
> 
> blocked by: \[FORBIDDEN/12/index read-only / allow delete (api)\];
> at org.graylog2.indexer.cluster.jest.JestUtils.specificException(JestUtils.java:98) ~\[graylog.jar:?\]
> at org.graylog2.indexer.cluster.jest.JestUtils.execute(JestUtils.java:57) ~\[graylog.jar:?\]
> at org.graylog2.indexer.cluster.jest.JestUtils.execute(JestUtils.java:62) ~\[graylog.jar:?\]
> at org.graylog2.indexer.indices.Indices.cycleAlias(Indices.java:655) ~\[graylog.jar:?\]
> at org.graylog2.indexer.MongoIndexSet.pointTo(MongoIndexSet.java:357) ~\[graylog.jar:?\]
> at org.graylog2.periodical.IndexRotationThread.checkAndRepair(IndexRotationThread.java:166) ~\[graylog.jar:?\]
> at org.graylog2.periodical.IndexRotationThread.lambda$doRun$0(IndexRotationThread.java:76) ~\[graylog.jar:?\]
> at java.lang.Iterable.forEach(Iterable.java:75) \[?:1.8.0\_212\]
> at org.graylog2.periodical.IndexRotationThread.doRun(IndexRotationThread.java:73) \[graylog.jar:?\]
> at org.graylog2.plugin.periodical.Periodical.run(Periodical.java:77) \[graylog.jar:?\]
> at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:511) \[?:1.8.0\_212\]
> at java.util.concurrent.FutureTask.runAndReset(FutureTask.java:308) \[?:1.8.0\_212\]
> at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.access$301(ScheduledThreadPoolExecutor.java:180) \[?:1.8.0\_212\]
> at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.run(ScheduledThreadPoolExecutor.java:294) \[?:1.8.0\_212\]
> at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) \[?:1.8.0\_212\]
> at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) \[?:1.8.0\_212\]
> at java.lang.Thread.run(Thread.java:748) \[?:1.8.0\_212\]
> \`\`\`
> 
> \## Expected Behavior
> Working graylog
> 
> \## Current Behavior
> It got stuck and not indexing new messages
> 
> \## Possible Solution
> Fix it!
> 
> \## Steps to Reproduce (for bugs)
> 1. Launch graylog 3.0.1
> 2. Wait
> 
> \## Your Environment
> 
> \* Graylog Version: 3.0.1 \`https://hub.docker.com/r/graylog2/graylog/tags\`
> \* Elasticsearch Version: \`docker.elastic.co/elasticsearch/elasticsearch-oss:6.6.2\`
> \* MongoDB Version: \`mongo:3.6\`
> \* Operating System: Ubuntu 18.04

And as @jan stated in this post I quote.

> Your Elasticsearch made the index read-only - the reason for that can be found in the elasticsearch log. But I guess because of missing available space …

---

_[View the full topic](https://community.graylog.org/t/graylog-empty-elastic-search-problem-deflector-is-pointing-to-graylog-729-not-the-newest-one-graylog-730-re-pointing/21992)._
