# Archiving and deletion per tenant

**URL:** <https://discuss.elastic.co/t/archiving-and-deletion-per-tenant/63988>\
**Category:** Elasticsearch\
**Created:** [October 26, 2016, 10:19am UTC](https://discuss.elastic.co/t/archiving-and-deletion-per-tenant/63988 "2016-10-26T10:19:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![framework](https://avatars.discourse-cdn.com/v4/letter/f/a88e4f/32.png) [@framework](https://discuss.elastic.co/u/framework)\
**Post date:** [October 26, 2016, 10:19am UTC](https://discuss.elastic.co/t/archiving-and-deletion-per-tenant/63988/1 "2016-10-26T10:19:13Z")

</div>

Hi Elasticsearch Team,

We have three different machines namely machine A, machine B and machine C.  
These three machine are sending syslog data to our logger, which uses elastisearch for storage

In our logger there are three inputs for three machines. (machine A, B and C)

All logs are coming properly and we can view them in UI and they are stored in elasticsearch (one instance only).  
Currently we have around 47,285,976 messages in 2,285 ms, searched in 3 indices.

Now my queries are as follows:

Can i archive the data coming from three separate inputs(machines) into elasticsearch for secure storage and re-import back when necessary?

Can i delete logs from elasticsearch based on the inputs(machines from which syslog is pushed to logger) or based on time and date?

Thanks in advance.

framework

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 26, 2016, 10:28am UTC](https://discuss.elastic.co/t/archiving-and-deletion-per-tenant/63988/2 "2016-10-26T10:28:11Z")

</div>

> [@framework](#):
>
> Can i archive the data coming from three separate inputs(machines) into elasticsearch for secure storage and re-import back when necessary?

Elasticsearch doesn't do encryption at rest, but you can use OS level tools to provide that.

> [@framework](#):
>
> Can i delete logs from elasticsearch based on the inputs(machines from which syslog is pushed to logger) or based on time and date?

You can, but it's not recommended as it is expensive. You are better off splitting the data into a per-customer, per time index.

---

<div class="post-metadata">

**Author:** ![framework](https://avatars.discourse-cdn.com/v4/letter/f/a88e4f/32.png) [@framework](https://discuss.elastic.co/u/framework)\
**Post date:** [October 26, 2016, 12:41pm UTC](https://discuss.elastic.co/t/archiving-and-deletion-per-tenant/63988/3 "2016-10-26T12:41:47Z")

</div>

Thanks for your quick reply.  
You said you can but expensive, could you point me to some documentation or explain me how to do this.

You also said you can segregate based on per customer, per time index.  
Can you guide me how to do it.

Thanks  
framework

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 26, 2016, 10:08pm UTC](https://discuss.elastic.co/t/archiving-and-deletion-per-tenant/63988/4 "2016-10-26T22:08:57Z")

</div>

Have a look at [https://www.elastic.co/guide/en/elasticsearch/reference/5.0/docs-delete-by-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/5.0/docs-delete-by-query.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:09pm UTC](https://discuss.elastic.co/t/archiving-and-deletion-per-tenant/63988/5 "2017-07-05T22:09:20Z")

</div>


