# Reconfiguring Indices in production

**URL:** <https://community.graylog.org/t/reconfiguring-indices-in-production/24839>\
**Category:** Graylog Central (peer support)\
**Created:** [July 18, 2022, 11:51pm UTC](https://community.graylog.org/t/reconfiguring-indices-in-production/24839 "2022-07-18T23:51:38Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raynu](https://avatars.discourse-cdn.com/v4/letter/r/a9adbd/32.png) [@Raynu](https://community.graylog.org/u/Raynu)\
**Post date:** [July 18, 2022, 11:51pm UTC](https://community.graylog.org/t/reconfiguring-indices-in-production/24839/1 "2022-07-18T23:51:38Z")

</div>

How to close active write index and reconfigure with new retention strategy.

Also, Can I get some reference documents on how to open close indices and make them available in Elastic search?

Graylog Version - Graylog v4.2.9+f0d8298  
Configured on docker container

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [July 18, 2022, 11:58pm UTC](https://community.graylog.org/t/reconfiguring-indices-in-production/24839/2 "2022-07-18T23:58:16Z")

</div>

Hello @Raynu

> [@Raynu](#):
>
> How to close active write index

Below each index set are these

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/6/6ef433ff0456bd309365848af9cb73cfe8f1d7ae.png)

> [@Raynu](#):
>
> reconfigure with new retention strategy.

Navigate to System/Indices, Click on "Edit " Button. Adjust the retention strategy. You may want to manually rotate the index.

- [Index model](https://docs.graylog.org/docs/index-model)

> [@Raynu](#):
>
> Can I get some reference documents on how to open close indices and make them available in Elastic search

Perhaps here

- [Open index API | Elasticsearch Guide [7.10] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.10/indices-open-close.html)

---

<div class="post-metadata">

**Author:** ![Raynu](https://avatars.discourse-cdn.com/v4/letter/r/a9adbd/32.png) [@Raynu](https://community.graylog.org/u/Raynu)\
**Post date:** [July 19, 2022, 1:44am UTC](https://community.graylog.org/t/reconfiguring-indices-in-production/24839/3 "2022-07-19T01:44:06Z")

</div>

Thanks @gsmith

Just tested on Dev box.  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/a/a56ff9a8a042ed9598040e2ccce4b388d6cb6ab4.png)

Once the index is rotated and closed. you get an option to reopen that index.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/6/62d9dff9a4d229a34211dfc290f7c0faa0daeb64.png)

Never thought it will be that easy.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [July 19, 2022, 1:53am UTC](https://community.graylog.org/t/reconfiguring-indices-in-production/24839/4 "2022-07-19T01:53:05Z")

</div>

👍 Just an FYI, Graylog controls Elasticsearch/OpenSearch.

---

<div class="post-metadata">

**Author:** ![Raynu](https://avatars.discourse-cdn.com/v4/letter/r/a9adbd/32.png) [@Raynu](https://community.graylog.org/u/Raynu)\
**Post date:** [July 19, 2022, 1:56am UTC](https://community.graylog.org/t/reconfiguring-indices-in-production/24839/5 "2022-07-19T01:56:12Z")

</div>

What does that mean? Sorry I am not an expert in this area.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [July 19, 2022, 2:01am UTC](https://community.graylog.org/t/reconfiguring-indices-in-production/24839/6 "2022-07-19T02:01:41Z")

</div>

Oh,  
Meaning to can make adjustments with indices through Graylog Web UI. ELK stack you normally have to do curl commands to modify you indices.

---

<div class="post-metadata">

**Author:** ![Raynu](https://avatars.discourse-cdn.com/v4/letter/r/a9adbd/32.png) [@Raynu](https://community.graylog.org/u/Raynu)\
**Post date:** [July 19, 2022, 2:08am UTC](https://community.graylog.org/t/reconfiguring-indices-in-production/24839/7 "2022-07-19T02:08:53Z")

</div>

> [@gsmith](#):
>
> h,  
> Meaning to can make adjustments with indices through Graylog Web UI. ELK stack you normally have to do curl commands to modify you indices.

Aah right, I find those commands tricky when I search on google because we have docker container and the configuration is slightly different. I am still struggling to find out how I can see actual indexes and data via command line. I my Indices directory in Elasticsearch there are no actual names of the indices as I see on UI.

Every day there is a new learning,

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [July 19, 2022, 2:25am UTC](https://community.graylog.org/t/reconfiguring-indices-in-production/24839/8 "2022-07-19T02:25:21Z")

</div>

For Docker, depending on how you setup you Docker-compose.

I use the Docker container IP address, to find that IP Address, I use this command.

```auto
root # docker ps

```

then

```auto
root # docker inspect 5c3b42ba17d6 <--- Elasticsearch_container_id

```

Then use that ip address like so

```auto
curl -XGET http://172.17.0.3:9200/_cat/indices

```

Results

```auto
root@ansible:/usr/local/bin# curl -X GET http://172.17.0.3:9200/_cluster/health?pretty
{
  "cluster_name" : "docker-cluster",
  "status" : "green",
  "timed_out" : false,
  "number_of_nodes" : 1,
  "number_of_data_nodes" : 1,
  "active_primary_shards" : 114,
  "active_shards" : 114,
  "relocating_shards" : 0,
  "initializing_shards" : 0,
  "unassigned_shards" : 0,
  "delayed_unassigned_shards" : 0,
  "number_of_pending_tasks" : 0,
  "number_of_in_flight_fetch" : 0,
  "task_max_waiting_in_queue_millis" : 0,
  "active_shards_percent_as_number" : 100.0
}
root@ansible:/usr/local/bin#

```

OR

```auto
root@ansible:/usr/local/bin# curl -X GET http://172.17.0.3:9200/_cat/indices?pretty
green open gl-failures_70 0-SMsbiWT6m6Q2grl9TIHQ 2 0 0 0 416b 416b
green open gl-failures_75 j5Y5f5erQ0iGX-h7dicIBg 2 0 0 0 416b 416b
green open gl-failures_73 wh6246BFQ4yux-chCC9Ymw 2 0 0 0 416b 416b
green open gl-failures_74 VhB-jShSTXC8dv4p7LMvGw 2 0 0 0 416b 416b
green open gl-failures_71 5EKaiLQXRLyvmy6O76Wz4Q 2 0 0 0 416b 416b
green open gl-failures_72 WxKsOTrKSWKGGoBtvWrGTw 2 0 0 0 416b 416b
green open graylog_36 CK1_UbhzReOX0dghZlV_7A 2 0 185797 0 41.3mb 41.3mb
green open graylog_35 cllJF1T3SwqW98yMqVk9WQ 2 0 48446 0 10.8mb 10.8mb
green open graylog_38 -JGlAUEwS9-A1aoOb0sh7w 2 0 68243 0 15mb 15mb
green open graylog_37 Rn18l_FnSn6FfceXrbOyOA 2 0 31678 0 7.4mb 7.4mb
green open graylog_39 KkZ9VZCCRbumKVCqppGznQ 2 0 25717 0 6.2mb 6.2mb
green open gl-failures_48 UghG8pQvRx6H-dw-Wm4rcg 2 0 0 0 416b 416b
green open gl-failures_49 q34y6mSxQECOvgnIorHWGA 2 0 0 0 416b 416b
green open gl-failures_46 BhgAbE2zSJqijClizpkiwA 2 0 0 0 416b 416b
green open gl-failures_47 BbA1C3OdRTWv23bTaI4kuQ 2 0 0 0 416b 416b
green open graylog_41 ozcGKVcXQee3GjNbWMgwiA 2 0 26166 0 6.2mb 6.2mb
green open graylog_40 mmypHdvLTQOk0M2HvJ5rqA 2 0 25717 0 6.1mb 6.1mb
green open graylog_43 KdJ_a7XQRcajre-Cc2We7w 2 0 26110 0 6.2mb 6.2mb
green open graylog_42 tABeMuBiQJCjgF2Txdq3EA 2 0 26550 0 6.4mb 6.4mb
green open graylog_45 AhwS4kmsSHSREgxONiWNKg 2 0 36629 0 8.6mb 8.6mb
green open graylog_44 APRfXxe7R5uPv-6_QvTHWw 2 0 26820 0 6.4mb 6.4mb
green open graylog_47 0Pid3PlaRlqhoPqbE9y7WQ 2 0 25629 0 6.1mb 6.1mb
green open graylog_46 Rua1xuHHSMyOQCKnpO6h3Q 2 0 25852 0 6.2mb 6.2mb
green open graylog_49 lec3ySJRS2-uYprQ4F1s8Q 2 0 4183 0 2.3mb 2.3mb
green open graylog_48 6fJCSHQxSSeIIs-6Ec5PZA 2 0 25607 0 6.1mb 6.1mb
green open gl-failures_55 icjSVuhaQUeeP5ElnR6Ttg 2 0 0 0 416b 416b
green open gl-failures_56 er1KZddsTmyhbbnNJkJ8nA 2 0 0 0 416b 416b
green open gl-failures_53 qKOL72pOSo6zTK_6dy-G7Q 2 0 0 0 416b 416b
green open gl-failures_54 ferZIwrhStGayYCUH7_R6w 2 0 0 0 416b 416b
green open gl-failures_51 KPEIeAVgQAiKu0MTo2HX4w 2 0 0 0 416b 416b
green open gl-failures_52 ju4Dh6apRJiFny-xfwX1Uw 2 0 0 0 416b 416b
green open gl-failures_50 A7mJlKcZSdCc7hZ7YJ0WEA 2 0 0 0 416b 416b
green open gl-failures_59 C6U_6QttRU6iHoYiDun5jw 2 0 0 0 416b 416b
green open gl-failures_57 eauYJr__RvKRHMeR18ok7Q 2 0 0 0 416b 416b
green open gl-failures_58 rB193zrQRACereNRZaV6JQ 2 0 0 0 416b 416b
green open gl-system-events_2 Gcj8pHI9SFOJ6gg5HBhZOg 4 0 0 0 832b 832b
green open gl-system-events_0 0VJyfJH-TiuB6HRVtekKIQ 4 0 0 0 832b 832b
green open gl-system-events_1 4SnH4ipSQqKUEhrbzkm4Sg 4 0 0 0 832b 832b
green open gl-failures_66 MBGd-MV2T7WCzmWy_J6MGA 2 0 0 0 416b 416b
green open gl-events_1 6_fhAYxfRw6Q7bgXGEnQww 4 0 7142329 0 1.1gb 1.1gb
green open gl-events_0 5I8vbJacT22BLtDtTyhlNA 4 0 869062 0 150.7mb 150.7mb
green open gl-failures_67 ryEXm_zfTMKg5XgQTmbt6A 2 0 0 0 416b 416b
green open gl-failures_64 NLPR-X2BSOOcjzVD4japjw 2 0 0 0 416b 416b

```

---

<div class="post-metadata">

**Author:** ![Raynu](https://avatars.discourse-cdn.com/v4/letter/r/a9adbd/32.png) [@Raynu](https://community.graylog.org/u/Raynu)\
**Post date:** [July 19, 2022, 3:14am UTC](https://community.graylog.org/t/reconfiguring-indices-in-production/24839/9 "2022-07-19T03:14:52Z")

</div>

> [@gsmith](#):
>
> ```auto
> /health?pretty
> {
> 
> ```

Wow, that’s great. You made my day. Thanks heaps for simple explanation and examples…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 2, 2022, 3:15am UTC](https://community.graylog.org/t/reconfiguring-indices-in-production/24839/10 "2022-08-02T03:15:34Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
