# About the curator setting about curator.yml and action\_file

**URL:** <https://discuss.elastic.co/t/about-the-curator-setting-about-curator-yml-and-action-file/103811>\
**Category:** Elasticsearch\
**Created:** [October 13, 2017, 2:46am UTC](https://discuss.elastic.co/t/about-the-curator-setting-about-curator-yml-and-action-file/103811 "2017-10-13T02:46:28Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [October 13, 2017, 2:46am UTC](https://discuss.elastic.co/t/about-the-curator-setting-about-curator-yml-and-action-file/103811/1 "2017-10-13T02:46:28Z")

</div>

about the curator  
can give me a example how setting the "curator.yml" and the "action\_file"  
thanks so much.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [October 13, 2017, 4:09am UTC](https://discuss.elastic.co/t/about-the-curator-setting-about-curator-yml-and-action-file/103811/2 "2017-10-13T04:09:05Z")

</div>

How about the ones in the documentation?

- [Config file](https://www.elastic.co/guide/en/elasticsearch/client/curator/5.2/configfile.html)
- [Action file Examples](https://www.elastic.co/guide/en/elasticsearch/client/curator/5.2/examples.html)

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [October 13, 2017, 5:06am UTC](https://discuss.elastic.co/t/about-the-curator-setting-about-curator-yml-and-action-file/103811/3 "2017-10-13T05:06:15Z")

</div>

ok @theuntergeek  
the filter about "timestring" ,  
if the indices like  
logstash-20170918-ip-122 ;  
logstash-20170919-ip-122;  
logstash-20170920-ip-122;

how setting the filter about it ?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [October 13, 2017, 5:31am UTC](https://discuss.elastic.co/t/about-the-curator-setting-about-curator-yml-and-action-file/103811/4 "2017-10-13T05:31:18Z")

</div>

That timestring appears to be `%Y%m%d`

Do you have to use the timestring? Is the index `creation_date` inaccurate?

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [October 13, 2017, 5:38am UTC](https://discuss.elastic.co/t/about-the-curator-setting-about-curator-yml-and-action-file/103811/5 "2017-10-13T05:38:26Z")

</div>

the tools is difference about use curl shell tasks delete the indices?  
like  
#!/bin/sh  
yesterday=`date --date='31 days ago' +%Y%m%d`  
curl -XDELETE [http://xx.xx.xx.xxx:9200/](http://xx.xx.xx.xxx:9200/)_-$yesterday_?pretty

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [October 13, 2017, 5:42am UTC](https://discuss.elastic.co/t/about-the-curator-setting-about-curator-yml-and-action-file/103811/6 "2017-10-13T05:42:59Z")

</div>

yes the logstash index as index =\> "system-log-61-%{+YYYY.MM.dd}-ip-61"  
how about set the timestring .  
@theuntergeek

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [October 13, 2017, 7:46am UTC](https://discuss.elastic.co/t/about-the-curator-setting-about-curator-yml-and-action-file/103811/7 "2017-10-13T07:46:08Z")

</div>

i slove it  
use  
`kind: regex`  
`value: '^logs-.*ip-61'`  
`source: creation_date`

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [October 13, 2017, 1:14pm UTC](https://discuss.elastic.co/t/about-the-curator-setting-about-curator-yml-and-action-file/103811/8 "2017-10-13T13:14:43Z")

</div>

Hmmm. You previously stated:

> [@zqc0512](#):
>
> if the indices like  
> logstash-20170918-ip-122 ;  
> logstash-20170919-ip-122;  
> logstash-20170920-ip-122;

But your index pattern you're sharing (`system-log-61-%{+YYYY.MM.dd}-ip-61`) indicates the pattern is actually `%Y.%m.%d`, with periods in between.

This is another great reason to go with `creation_date`, which it seems you've discovered works well for you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 10, 2017, 1:14pm UTC](https://discuss.elastic.co/t/about-the-curator-setting-about-curator-yml-and-action-file/103811/9 "2017-11-10T13:14:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
