# My graylog elasticsearch indices have been deleted for no reason

**URL:** <https://community.graylog.org/t/my-graylog-elasticsearch-indices-have-been-deleted-for-no-reason/24745>\
**Category:** Graylog Central (peer support)\
**Tags:** elastic\
**Created:** [July 12, 2022, 1:15pm UTC](https://community.graylog.org/t/my-graylog-elasticsearch-indices-have-been-deleted-for-no-reason/24745 "2022-07-12T13:15:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nosmoking1210](https://avatars.discourse-cdn.com/v4/letter/n/edb3f5/32.png) [@nosmoking1210](https://community.graylog.org/u/nosmoking1210)\
**Post date:** [July 12, 2022, 1:15pm UTC](https://community.graylog.org/t/my-graylog-elasticsearch-indices-have-been-deleted-for-no-reason/24745/1 "2022-07-12T13:15:21Z")

</div>

Hi guys,  
I have a cluster graylog with 3 nodes  
Node1: graylog master, elastic, mongodb  
Node2: graylog, elastic, mongodb  
Node3: graylog, elastic, mongodb  
All of them are clusterd.  
Recently, I got a problem, when my indices in elasticsearch have been delete for no reason (I mean I dont know why).  
I have check index retention and rotation policy, they are fine  
Index retention strategy: Delete  
Index rotation strategy: Document count (20M docs)  
Max number of indices: 20

I’m pretty sure that I have enough storage for that (200GB each node), and the deletion always happen when I have graylog\_0, graylog\_1, graylog\_2, graylog\_3, graylog\_4

This is what I found when all indices have been gone

```auto
server.log:2022-07-11T12:37:46.627Z INFO [IndexRangesCleanupPeriodical] Removing index range information for unavailable indices: [gl-failures_5, gl-failures_4, gl-failures_3, gl-failures_2, gl-failures_1, graylog_1, graylog_4, graylog_3, gl-failures_6, graylog_2]

```

I cant find any reason which my elasticsearch indices have been delele, Can you guys give me some clues.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [July 12, 2022, 11:30pm UTC](https://community.graylog.org/t/my-graylog-elasticsearch-indices-have-been-deleted-for-no-reason/24745/2 "2022-07-12T23:30:25Z")

</div>

Hello && welcome @nosmoking1210

Yes this is some Dark Graylog Magic.

> [@nosmoking1210](#):
>
> `INFO [IndexRangesCleanupPeriodical]`

Graylog goes through a clean check for index ranges, How do you know those indices have been deleted? Are they removed on the Web UI?

I’m assuming any configuration you made for these indices are made from the Web UI, correct?

Perhaps check Elasticsearch.

```auto
curl -XGET 'http://localhost:9200/_cluster/health?pretty=true'  

```

Check template settings

```auto
curl -X GET "localhost:9200/graylog_6?pretty"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [July 26, 2022, 11:30pm UTC](https://community.graylog.org/t/my-graylog-elasticsearch-indices-have-been-deleted-for-no-reason/24745/3 "2022-07-26T23:30:51Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
