# Change TTL value

**URL:** <https://discuss.elastic.co/t/change-ttl-value/6337>\
**Category:** Elasticsearch\
**Created:** [January 10, 2012, 6:30pm UTC](https://discuss.elastic.co/t/change-ttl-value/6337 "2012-01-10T18:30:58Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![vannya](https://avatars.discourse-cdn.com/v4/letter/v/e495f1/32.png) [@vannya](https://discuss.elastic.co/u/vannya)\
**Post date:** [January 10, 2012, 6:30pm UTC](https://discuss.elastic.co/t/change-ttl-value/6337/1 "2012-01-10T18:30:58Z")

</div>

Hi all,

I'm analyzing how can I use ttl in my system to implement document  
aging.  
I've already configured indices.ttl.interval and indices.ttl.bulk\_size  
properties, and created the specific mapping for my index in:

config/mappings/my\_index/my\_type.json, having:

{  
"my\_type":{  
"\_ttl":{  
"enabled":true,  
"default":"7d"  
}  
}  
}

I have now some questions:  
1 - where can I see the possible time values? Can I use s for seconds  
and m for minutes? d actually stands for days!  
2 - this ttl will be coupled to each document, or if I change it, all  
documents will reflect the change? And is there any other way to  
change it besides the mapping update?  
3 - why is my bulk\_size property not working (is not being correctly  
used to delete documents - is set to 100, but clears all my  
documents)?  
4 - to set the interval of tll process, can I use an regular  
expression (like cron) or I'm limited to use time values?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Benjamin\_Deveze](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_deveze/32/1577_2.png) [@Benjamin\_Deveze](https://discuss.elastic.co/u/Benjamin_Deveze)\
**Post date:** [January 10, 2012, 10:25pm UTC](https://discuss.elastic.co/t/change-ttl-value/6337/2 "2012-01-10T22:25:29Z")

</div>

Hey,

1. I am not sure if it is documented. You can use w for week, d for day, H  
for hours, m for minutes, s for secs, ms for msecs, etc. Maybe have a look  
here for more information:  
[https://github.com/elasticsearch/elasticsearch/blob/master/src/main/java/org/elasticsearch/common/unit/TimeValue.java](https://github.com/elasticsearch/elasticsearch/blob/master/src/main/java/org/elasticsearch/common/unit/TimeValue.java)

2. the TTL defined in mapping will be applied to all indexed docs of type  
"my\_type" if you don't specify explicitly a TTL for each doc you index.

3. it is normal that all your expired docs are purged no matter what is  
your bulk\_size value. The bulk\_size value just allow to configure how much  
docs are expired at once by the purge process.

4. no

---

<div class="post-metadata">

**Author:** ![vannya](https://avatars.discourse-cdn.com/v4/letter/v/e495f1/32.png) [@vannya](https://discuss.elastic.co/u/vannya)\
**Post date:** [January 11, 2012, 10:21am UTC](https://discuss.elastic.co/t/change-ttl-value/6337/3 "2012-01-11T10:21:22Z")

</div>

Hi Benjamin, thanks for your reply!

I deduce from your answer to 2), that a document once indexed wil a  
ttl value, even if tll value is changed (by updating mapping), no  
changes will be made to documents already indexed (unless we reindex  
all documents), correct?

And, in 3), if I have 1000 documents, and have a bulk\_size of 100 (and  
for instance, ttl is running every minute and ttl value is set to 5m),  
shouldn't I see deleted only 100 documents at a time? The problem is  
that, is the situation above, all documents are deleted!

Thanks!

On Jan 10, 10:25 pm, Benjamin Devèze [benjamin.dev...@gmail.com](mailto:benjamin.dev...@gmail.com)  
wrote:

> Hey,
> 
> 1. I am not sure if it is documented. You can use w for week, d for day, H  
> for hours, m for minutes, s for secs, ms for msecs, etc. Maybe have a look  
> here for more information:[https://github.com/elasticsearch/elasticsearch/blob/master/src/main/j](https://github.com/elasticsearch/elasticsearch/blob/master/src/main/j)...
> 
> 2. the TTL defined in mapping will be applied to all indexed docs of type  
> "my\_type" if you don't specify explicitly a TTL for each doc you index.
> 
> 3. it is normal that all your expired docs are purged no matter what is  
> your bulk\_size value. The bulk\_size value just allow to configure how much  
> docs are expired at once by the purge process.
> 
> 4. no

---

<div class="post-metadata">

**Author:** ![Benjamin\_Deveze](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_deveze/32/1577_2.png) [@Benjamin\_Deveze](https://discuss.elastic.co/u/Benjamin_Deveze)\
**Post date:** [January 11, 2012, 10:54am UTC](https://discuss.elastic.co/t/change-ttl-value/6337/4 "2012-01-11T10:54:11Z")

</div>

- changing the default TTL value in the mapping won't affect the TTL of  
already indexed docs. If you want to update the TTL of an already indexed  
document you can use the update API that has been recently added and doing  
in your script something like this: ctx.\_ttl = "2d" (this is only available  
in master branch for now and will be in next released version)

- Nope. As it is currently implemented the purger is called, it collects  
the 1000 expired documents, then executes 10 bulk requests of 100 delete  
requests. So all expired documents are deleted.

---

<div class="post-metadata">

**Author:** ![vannya](https://avatars.discourse-cdn.com/v4/letter/v/e495f1/32.png) [@vannya](https://discuss.elastic.co/u/vannya)\
**Post date:** [January 11, 2012, 11:29am UTC](https://discuss.elastic.co/t/change-ttl-value/6337/5 "2012-01-11T11:29:15Z")

</div>

Ok, got it!

Thanks for your help!

On Jan 11, 10:54 am, Benjamin Devèze [benjamin.dev...@gmail.com](mailto:benjamin.dev...@gmail.com)  
wrote:

> - changing the default TTL value in the mapping won't affect the TTL of  
> already indexed docs. If you want to update the TTL of an already indexed  
> document you can use the update API that has been recently added and doing  
> in your script something like this: ctx.\_ttl = "2d" (this is only available  
> in master branch for now and will be in next released version)
> 
> - Nope. As it is currently implemented the purger is called, it collects  
> the 1000 expired documents, then executes 10 bulk requests of 100 delete  
> requests. So all expired documents are deleted.

---

<div class="post-metadata">

**Author:** ![Steve\_2](https://avatars.discourse-cdn.com/v4/letter/s/c77e96/32.png) [@Steve\_2](https://discuss.elastic.co/u/Steve_2)\
**Post date:** [January 12, 2012, 8:18pm UTC](https://discuss.elastic.co/t/change-ttl-value/6337/6 "2012-01-12T20:18:56Z")

</div>

Sorry to jump in on this - Benjamin, you say "changing the default TTL  
in the mapping", and I've been trying to do exactly that without much  
success on 0.18.6. Whatever I first use as the mapping seems to stick.  
There's been some discussion of what can be updated for mappings but I  
couldn't find any solid information. Is it possible to update the  
default ttl?

For example:

$ curl -XPUT '[http://localhost:9200/myindex/mytype/\_mapping](http://localhost:9200/myindex/mytype/_mapping)' -d  
'{"mytype": {"\_timestamp": {"enabled": false}, "\_ttl":  
{"enabled":false, "default": "10d"}}}  
{"ok":true,"acknowledged":true}  
$ curl [http://localhost:9200/myindex/mytype/\_mapping](http://localhost:9200/myindex/mytype/_mapping)  
{"mytype":{"\_timestamp":{"enabled":true},"\_ttl":  
{"enabled":true,"default":86400000},"properties":{}}}  
$ curl -XPUT '[http://localhost:9200/myindex/mytype/\_mapping](http://localhost:9200/myindex/mytype/_mapping)' -d  
'{"mytype": {"\_timestamp": {"enabled": false}, "\_ttl":  
{"enabled":false}}}'  
{"ok":true,"acknowledged":true}  
$ curl [http://localhost:9200/myindex/mytype/\_mapping](http://localhost:9200/myindex/mytype/_mapping)  
{"mytype":{"\_timestamp":{"enabled":true},"\_ttl":  
{"enabled":true,"default":86400000},"properties":{}}}

The server debug log contains:  
[2012-01-12 20:10:39,612][DEBUG][cluster.service] [White  
Rabbit] processing [put-mapping [sweeper]]: execute  
[2012-01-12 20:10:39,627][DEBUG][cluster.service] [White  
Rabbit] processing [put-mapping [sweeper]]: no change in cluster\_state

Thanks!

On Jan 11, 5:29 am, vannya [vann...@gmail.com](mailto:vann...@gmail.com) wrote:

> > - changing the default TTL value in themappingwon't affect the TTL of  
> > already indexed docs. If you want toupdatethe TTL of an already indexed  
> > document you can use theupdateAPI that has been recently added and doing  
> > in your script something like this: ctx.\_ttl = "2d" (this is only available  
> > in master branch for now and will be in next released version)
> 
> > - Nope. As it is currently implemented the purger is called, it collects  
> > the 1000 expired documents, then executes 10 bulk requests of 100 delete  
> > requests. So all expired documents are deleted.

---

<div class="post-metadata">

**Author:** ![Benjamin\_Deveze](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_deveze/32/1577_2.png) [@Benjamin\_Deveze](https://discuss.elastic.co/u/Benjamin_Deveze)\
**Post date:** [January 12, 2012, 10:33pm UTC](https://discuss.elastic.co/t/change-ttl-value/6337/7 "2012-01-12T22:33:49Z")

</div>

Hey Steve,

it seems it has to deal with the merge process in the mapping. Just open an  
issue and it will be supported soon.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:42am UTC](https://discuss.elastic.co/t/change-ttl-value/6337/8 "2017-07-06T03:42:54Z")

</div>


