# Automatically delete old indices

**URL:** <https://discuss.elastic.co/t/automatically-delete-old-indices/190276>\
**Category:** Beats\
**Tags:** ilm-index-lifecycle-management, filebeat\
**Created:** [July 12, 2019, 3:46pm UTC](https://discuss.elastic.co/t/automatically-delete-old-indices/190276 "2019-07-12T15:46:15Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![ngg971](https://avatars.discourse-cdn.com/v4/letter/n/b782af/32.png) [@ngg971](https://discuss.elastic.co/u/ngg971)\
**Post date:** [July 12, 2019, 3:46pm UTC](https://discuss.elastic.co/t/automatically-delete-old-indices/190276/1 "2019-07-12T15:46:16Z")

</div>

Hi,

I know this has been asked a lot, but I wanted to check if there were any updates since most threads on this date back to 2017. I have integrated Filebeat into my Kubernetes cluster and it is ingesting around 3GB a day of logs and them in storing in an index a day. Eg: filebeat-2019.06.21

I want to set up a daily job to delete indeces older than a certain period, to keep our storage usage under control. Is ILM or Curator the best tool to do this? And is there a GUI or will this have to be done via CLI?

Thanks!  
Nathanael

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [July 12, 2019, 6:08pm UTC](https://discuss.elastic.co/t/automatically-delete-old-indices/190276/2 "2019-07-12T18:08:17Z")

</div>

If ILM meets your needs, it is preferred, as there are no other moving pieces you would need to manage. With Curator, you'd need to install Curator itself, maintain configuration files and updates, and run with a scheduler.

---

<div class="post-metadata">

**Author:** ![ngg971](https://avatars.discourse-cdn.com/v4/letter/n/b782af/32.png) [@ngg971](https://discuss.elastic.co/u/ngg971)\
**Post date:** [July 14, 2019, 11:45pm UTC](https://discuss.elastic.co/t/automatically-delete-old-indices/190276/3 "2019-07-14T23:45:04Z")

</div>

Thanks.

I tried setting up a policy, but got the following error (below). Does this mean that ILM is not currently set up on my Elastic instance?

```auto
PUT /_ilm/policy/my_policy
{
  "policy": {
    "phases": {
      "warm": {
        "min_age": "1d",
        "actions": {
          "shrink" : {
            "number_of_shards": 1
          }
        }
      },
      "cold": {
        "min_age": "3d",
        "actions": {
          "allocate": {
            "number_of_replicas": 1
          }
        }
      },
      "delete": {
        "min_age": "15d",
        "actions": {
          "delete": {}
        }
      }
    }
  }
}

```

Response:

```auto
    "type": "invalid_index_name_exception",
    "reason": "Invalid index name [_ilm], must not start with '_', '-', or '+'",

```

Also, just to confirm, once I am able to create the policy, I should use the following API call to apply it?

```auto
    PUT _template/<filebeat-index-pattern> 

```

Many thanks,  
Nathanael

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [July 15, 2019, 12:57am UTC](https://discuss.elastic.co/t/automatically-delete-old-indices/190276/4 "2019-07-15T00:57:53Z")

</div>

These pastes are a lot harder to read when they are not contained within triple back ticks, like this:

````
```
PASTE HERE
```

````

It makes it pre-formatted text, monospaced, and preserves your indenting. I will be able to read what you've created much better if you can make that change (edit your previous post), please.

---

<div class="post-metadata">

**Author:** ![ngg971](https://avatars.discourse-cdn.com/v4/letter/n/b782af/32.png) [@ngg971](https://discuss.elastic.co/u/ngg971)\
**Post date:** [July 15, 2019, 8:59am UTC](https://discuss.elastic.co/t/automatically-delete-old-indices/190276/5 "2019-07-15T08:59:05Z")

</div>

Apologies, I couldn't figure out how to format it properly. I've edited it above.

---

<div class="post-metadata">

**Author:** ![dakrone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dakrone/32/23351_2.png) [@dakrone](https://discuss.elastic.co/u/dakrone)\
**Post date:** [July 15, 2019, 1:45pm UTC](https://discuss.elastic.co/t/automatically-delete-old-indices/190276/6 "2019-07-15T13:45:01Z")

</div>

> [@ngg971](#):
>
> "type": "invalid\_index\_name\_exception", "reason": "Invalid index name [_ilm], must not start with '_', '-', or '+'",

It appears that you have ILM disabled, x-pack is not installed, or you have an older version of ES/X-pack from before ILM was released. Can you give us some more details about your environment?

---

<div class="post-metadata">

**Author:** ![ngg971](https://avatars.discourse-cdn.com/v4/letter/n/b782af/32.png) [@ngg971](https://discuss.elastic.co/u/ngg971)\
**Post date:** [July 15, 2019, 7:12pm UTC](https://discuss.elastic.co/t/automatically-delete-old-indices/190276/7 "2019-07-15T19:12:31Z")

</div>

I do believe I have x-pack installed as I have set up alerts in Watcher. My elastic version is **6.5.4**.

Would ILM come enabled by default? I cannot find a setting to enable/disable it anywhere in the Kibana or Elastic Cloud UI.

Thanks.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 15, 2019, 7:19pm UTC](https://discuss.elastic.co/t/automatically-delete-old-indices/190276/8 "2019-07-15T19:19:25Z")

</div>

I believe ILM was introduced in version 6.6, so I would recommend upgrading to version 6.8.

---

<div class="post-metadata">

**Author:** ![ngg971](https://avatars.discourse-cdn.com/v4/letter/n/b782af/32.png) [@ngg971](https://discuss.elastic.co/u/ngg971)\
**Post date:** [July 16, 2019, 10:33am UTC](https://discuss.elastic.co/t/automatically-delete-old-indices/190276/9 "2019-07-16T10:33:56Z")

</div>

Ok thanks, will give that a go.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2019, 10:38am UTC](https://discuss.elastic.co/t/automatically-delete-old-indices/190276/10 "2019-08-13T10:38:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
