# Automate Deletion of Docs from an Index that are older than 10 days

**URL:** <https://discuss.elastic.co/t/automate-deletion-of-docs-from-an-index-that-are-older-than-10-days/293826>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [January 9, 2022, 1:44pm UTC](https://discuss.elastic.co/t/automate-deletion-of-docs-from-an-index-that-are-older-than-10-days/293826 "2022-01-09T13:44:41Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Divyank\_Mahalle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divyank_mahalle/32/91240_2.png) [@Divyank\_Mahalle](https://discuss.elastic.co/u/Divyank_Mahalle)\
**Post date:** [January 21, 2022, 11:16am UTC](https://discuss.elastic.co/t/automate-deletion-of-docs-from-an-index-that-are-older-than-10-days/293826/3 "2022-01-21T11:16:31Z")

</div>

Thanks @Christian_Dahlqvist ,  
My index was not time series index, post reindexing it I convert it into time series index and rollover is happening as per ilm policy and able to achieve the goal.

```auto
POST /_reindex
{
  "source": {
    "index": "weather"
  },
  "dest": {
    "index": "weather-000001"
  }
}

DELETE weather

Appying Alias on timeseries index, Queries can run on alias which will be the weather.
POST /_aliases
{
  "actions": [
    {
      "add": {
        "index": "weather-000001",
        "alias": "weather",
        "is_write_index": true
      }
    }
  ]
}

```

Logstash output-

```auto
output {
  stdout {
    codec => rubydebug
    }
   elasticsearch {
           ilm_rollover_alias => "weather"
           ilm_pattern => "000001"
           ilm_policy => "weather"
     	   hosts => ["localhost:9200"]

```

**One Query-**

If we query (using an index pattern) for the last 3 days of data in an index that has rollover set to daily, does the query run only on the latest 3 indices or does it run on all?  
I guess we need to specify the indices names in the query to limit to search to only the last 3 indices. Doesn't it happen automatically? Or does it happen automatically in the data stream but not in the index alias/ pattern?  
If we have 10 days of data with daily rollover.

Sample query-

```auto
GET weather-*/_search
{
 "query": {
   "range": {
     "@timestamp": {
       "gte": "now-3d"
      }
    }
  }
}

```

Ref link-  
[  
  ![](https://us1.discourse-cdn.com/elastic/optimized/3X/5/d/5ded4d26a9eb0b035f2650d43025d92144c19f9c_2_32x32.ico)Index lifecycle error - illegal\_argument\_exception: index.lifecycle.rollover\_alias](https://discuss.elastic.co/t/index-lifecycle-error-illegal-argument-exception-index-lifecycle-rollover-alias/207900/8)

[![](https://us1.discourse-cdn.com/elastic/original/3X/9/2/92fb7ff93b9877fd59341d159284e1a247bb277b.png)Manage existing indices | Elasticsearch Guide [7.15] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/ilm-with-existing-indices.html#ilm-existing-indices-apply)  
[![](https://us1.discourse-cdn.com/elastic/original/3X/d/f/df9825935fc1b209109e6aad25db8f47d93c762e.png)Data rollover in Elasticsearch](https://medium.com/nerd-for-tech/data-rollover-in-elasticsearch-b809bb9f150a)

---

_[View the full topic](https://discuss.elastic.co/t/automate-deletion-of-docs-from-an-index-that-are-older-than-10-days/293826)._
