# Graylog Retention Strategy Not Being Followed

**URL:** <https://community.graylog.org/t/graylog-retention-strategy-not-being-followed/6507>\
**Category:** Graylog Central (peer support)\
**Created:** [August 20, 2018, 9:57am UTC](https://community.graylog.org/t/graylog-retention-strategy-not-being-followed/6507 "2018-08-20T09:57:08Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![GTownson](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gtownson/32/793_2.png) [@GTownson](https://community.graylog.org/u/GTownson)\
**Post date:** [August 20, 2018, 9:57am UTC](https://community.graylog.org/t/graylog-retention-strategy-not-being-followed/6507/1 "2018-08-20T09:57:08Z")

</div>

Hi All,

I have set a Graylog instance to only hold 60 indices and delete all others. I had previously closed some older indices and then noticed that Graylog was not following the retention strategy and now has 69 indices, I then opened the old indices thinking that closing them may have caused this, but Graylog still hasn’t deleted them.  
I have also tried cyling the active write index and recalculating index ranges, but this helped.  
I encountered this issue once before, however I found Elasticsearch to be Red in status and resolving that issue resolved the retention strategy problem. In this case Elasticsearch is healthy.

System Specs

OS: Ubuntu 16.04 LTS  
Graylog: 2.4.4  
Elasticsearch: 5.6.9  
MongoDB: 2.6.10

Here you can see my config and also the amount of incides in the system.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/2/2388e48781b0ddcedde8430c224829697b0486c9.png)

Regards,

G

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [August 20, 2018, 3:41pm UTC](https://community.graylog.org/t/graylog-retention-strategy-not-being-followed/6507/2 "2018-08-20T15:41:45Z")

</div>

did you see any entries in the logfiles about the retention check?

Graylog should give you some ideas why it can’t run the retention checks.

---

<div class="post-metadata">

**Author:** ![GTownson](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gtownson/32/793_2.png) [@GTownson](https://community.graylog.org/u/GTownson)\
**Post date:** [August 21, 2018, 7:38am UTC](https://community.graylog.org/t/graylog-retention-strategy-not-being-followed/6507/3 "2018-08-21T07:38:49Z")

</div>

Hi Jan,

I looked in the logs and can’t find anything regarding retention strategies.  
I have looked into another working system and found logs such as these:

```
2018-08-21T01:03:58.379+01:00 INFO [AbstractIndexCountBasedRetentionStrategy] Number of indices (4) higher than limit (3). Running retention for 1 indices.
2018-08-21T01:03:59.296+01:00 INFO [AbstractIndexCountBasedRetentionStrategy] Running retention strategy [org.graylog2.indexer.retention.strategies.DeletionRetentionStrategy] for index <graylog_381>

```

Both systems are configured the same, however the one that is not working is set to 60 indices instead of 4.

Cheers,

G

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [August 21, 2018, 8:50am UTC](https://community.graylog.org/t/graylog-retention-strategy-not-being-followed/6507/4 "2018-08-21T08:50:55Z")

</div>

you need to find the difference to solve the issue.

---

<div class="post-metadata">

**Author:** ![GTownson](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gtownson/32/793_2.png) [@GTownson](https://community.graylog.org/u/GTownson)\
**Post date:** [August 21, 2018, 9:40am UTC](https://community.graylog.org/t/graylog-retention-strategy-not-being-followed/6507/5 "2018-08-21T09:40:06Z")

</div>

The one that works is on 2.4.5 and the one that isn’t working is on 2.4.4, is this a known issue of 2.4.4?

We will aim to update as soon as we can but due to being in production it will have to be scheduled in.

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [August 21, 2018, 10:04am UTC](https://community.graylog.org/t/graylog-retention-strategy-not-being-followed/6507/6 "2018-08-21T10:04:12Z")

</div>

not that I know - so it should be something else.

---

<div class="post-metadata">

**Author:** ![GTownson](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gtownson/32/793_2.png) [@GTownson](https://community.graylog.org/u/GTownson)\
**Post date:** [August 22, 2018, 12:18pm UTC](https://community.graylog.org/t/graylog-retention-strategy-not-being-followed/6507/7 "2018-08-22T12:18:55Z")

</div>

I did close and reopen about ten of the indices on the system that is not working properly. That’s all I can think of, it shouldn’t have caused this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 5, 2018, 12:18pm UTC](https://community.graylog.org/t/graylog-retention-strategy-not-being-followed/6507/8 "2018-09-05T12:18:59Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
