# Automatically deleting logs

**URL:** <https://discuss.elastic.co/t/automatically-deleting-logs/16065>\
**Category:** Elasticsearch\
**Created:** [February 28, 2014, 6:35am UTC](https://discuss.elastic.co/t/automatically-deleting-logs/16065 "2014-02-28T06:35:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![san](https://avatars.discourse-cdn.com/v4/letter/s/ba9def/32.png) [@san](https://discuss.elastic.co/u/san)\
**Post date:** [February 28, 2014, 6:35am UTC](https://discuss.elastic.co/t/automatically-deleting-logs/16065/1 "2014-02-28T06:35:30Z")

</div>

When the storage of Elasticsearch is full, i want to get the oldest logs  
automatically deleted to accommodate new logs.

Could someone help me in achieving this?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0f335836-3395-4071-9b79-33d3505d6e5a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0f335836-3395-4071-9b79-33d3505d6e5a%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 28, 2014, 7:25am UTC](https://discuss.elastic.co/t/automatically-deleting-logs/16065/2 "2014-02-28T07:25:01Z")

</div>

I think you are looking for this: [https://github.com/elasticsearch/elasticsearch/issues/2114](https://github.com/elasticsearch/elasticsearch/issues/2114)

By now, you have to manage it yourself.

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 28 févr. 2014 à 07:35, san [sandks14@gmail.com](mailto:sandks14@gmail.com) a écrit :

When the storage of Elasticsearch is full, i want to get the oldest logs automatically deleted to accommodate new logs.

Could someone help me in achieving this?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0f335836-3395-4071-9b79-33d3505d6e5a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0f335836-3395-4071-9b79-33d3505d6e5a%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/E3BC7678-D805-475E-9C1E-E6865F551C30%40pilato.fr](https://groups.google.com/d/msgid/elasticsearch/E3BC7678-D805-475E-9C1E-E6865F551C30%40pilato.fr).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![san](https://avatars.discourse-cdn.com/v4/letter/s/ba9def/32.png) [@san](https://discuss.elastic.co/u/san)\
**Post date:** [February 28, 2014, 8:01am UTC](https://discuss.elastic.co/t/automatically-deleting-logs/16065/3 "2014-02-28T08:01:42Z")

</div>

Hi David,

Thanks for you response.

My requirement is to get the old logs deleted due to non-availability of  
STORAGE SPACE to accommodate new logs.  
This is regardless of ttl is expired or not.

On Friday, February 28, 2014 12:55:01 PM UTC+5:30, David Pilato wrote:

> I think you are looking for this:  
> [Allow setting ttl at index level · Issue #2114 · elastic/elasticsearch · GitHub](https://github.com/elasticsearch/elasticsearch/issues/2114)
> 
> By now, you have to manage it yourself.
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 28 févr. 2014 à 07:35, san \<[sand...@gmail.com](mailto:sand...@gmail.com) \<javascript:\>\> a écrit :
> 
> When the storage of Elasticsearch is full, i want to get the oldest logs  
> automatically deleted to accommodate new logs.
> 
> Could someone help me in achieving this?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/0f335836-3395-4071-9b79-33d3505d6e5a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0f335836-3395-4071-9b79-33d3505d6e5a%40googlegroups.com)  
> .  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/dce0efc5-9bd8-4656-baf6-e317aca28e28%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/dce0efc5-9bd8-4656-baf6-e317aca28e28%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 28, 2014, 8:07am UTC](https://discuss.elastic.co/t/automatically-deleting-logs/16065/4 "2014-02-28T08:07:09Z")

</div>

It does not exist.  
I really think that you should run a cron job and decide what to do in that case.

But why not removing logs after a given period?

BTW when I say delete logs I mean remove daily index. Deleting logs entry will cost you more space due to how Lucene works behind the scene.

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 28 févr. 2014 à 09:01, san [sandks14@gmail.com](mailto:sandks14@gmail.com) a écrit :

Hi David,

Thanks for you response.

My requirement is to get the old logs deleted due to non-availability of STORAGE SPACE to accommodate new logs.  
This is regardless of ttl is expired or not.

> On Friday, February 28, 2014 12:55:01 PM UTC+5:30, David Pilato wrote:  
> I think you are looking for this: [Allow setting ttl at index level · Issue #2114 · elastic/elasticsearch · GitHub](https://github.com/elasticsearch/elasticsearch/issues/2114)
> 
> By now, you have to manage it yourself.
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 28 févr. 2014 à 07:35, san [sand...@gmail.com](mailto:sand...@gmail.com) a écrit :
> 
> When the storage of Elasticsearch is full, i want to get the oldest logs automatically deleted to accommodate new logs.
> 
> Could someone help me in achieving this?
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0f335836-3395-4071-9b79-33d3505d6e5a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0f335836-3395-4071-9b79-33d3505d6e5a%40googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/dce0efc5-9bd8-4656-baf6-e317aca28e28%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/dce0efc5-9bd8-4656-baf6-e317aca28e28%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/2D09CA87-E272-4E08-ACB6-CB8DBED65233%40pilato.fr](https://groups.google.com/d/msgid/elasticsearch/2D09CA87-E272-4E08-ACB6-CB8DBED65233%40pilato.fr).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 28, 2014, 8:43am UTC](https://discuss.elastic.co/t/automatically-deleting-logs/16065/5 "2014-02-28T08:43:44Z")

</div>

Take a look at [GitHub - elastic/curator: Curator: Tending your Elasticsearch indices](https://github.com/elasticsearch/curator)

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 28 February 2014 19:07, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> It does not exist.  
> I really think that you should run a cron job and decide what to do in  
> that case.
> 
> But why not removing logs after a given period?
> 
> BTW when I say delete logs I mean remove daily index. Deleting logs entry  
> will cost you more space due to how Lucene works behind the scene.
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 28 févr. 2014 à 09:01, san [sandks14@gmail.com](mailto:sandks14@gmail.com) a écrit :
> 
> Hi David,
> 
> Thanks for you response.
> 
> My requirement is to get the old logs deleted due to non-availability of  
> STORAGE SPACE to accommodate new logs.  
> This is regardless of ttl is expired or not.
> 
> On Friday, February 28, 2014 12:55:01 PM UTC+5:30, David Pilato wrote:
> 
> > I think you are looking for this: [https://github.com/](https://github.com/)  
> > elasticsearch/elasticsearch/issues/2114
> > 
> > By now, you have to manage it yourself.
> > 
> > --  
> > David 😉  
> > Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> > 
> > Le 28 févr. 2014 à 07:35, san [sand...@gmail.com](mailto:sand...@gmail.com) a écrit :
> > 
> > When the storage of Elasticsearch is full, i want to get the oldest logs  
> > automatically deleted to accommodate new logs.
> > 
> > Could someone help me in achieving this?
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > msgid/elasticsearch/0f335836-3395-4071-9b79-33d3505d6e5a%  
> > [40googlegroups.com](http://40googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/dce0efc5-9bd8-4656-baf6-e317aca28e28%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/dce0efc5-9bd8-4656-baf6-e317aca28e28%40googlegroups.com)  
> .  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/2D09CA87-E272-4E08-ACB6-CB8DBED65233%40pilato.fr](https://groups.google.com/d/msgid/elasticsearch/2D09CA87-E272-4E08-ACB6-CB8DBED65233%40pilato.fr)  
> .
> 
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624aqxU-A1B8DB\_\_GwmdM7hgMFY7iQgwQj37p\_0GdgZjhuw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624aqxU-A1B8DB__GwmdM7hgMFY7iQgwQj37p_0GdgZjhuw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46am UTC](https://discuss.elastic.co/t/automatically-deleting-logs/16065/6 "2017-07-06T01:46:39Z")

</div>


