# Creating Cron job for Close and Delete indices from elasticsearch

**URL:** <https://discuss.elastic.co/t/creating-cron-job-for-close-and-delete-indices-from-elasticsearch/86614>\
**Category:** Elasticsearch\
**Created:** [May 22, 2017, 7:28am UTC](https://discuss.elastic.co/t/creating-cron-job-for-close-and-delete-indices-from-elasticsearch/86614 "2017-05-22T07:28:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![warunac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warunac/32/73645_2.png) [@warunac](https://discuss.elastic.co/u/warunac)\
**Post date:** [May 22, 2017, 7:28am UTC](https://discuss.elastic.co/t/creating-cron-job-for-close-and-delete-indices-from-elasticsearch/86614/1 "2017-05-22T07:28:52Z")

</div>

I would like to share my Cron job for Close and Delete indices from elasticsearch 5.4

First installed elasticsearch-curator

then created /etc/elasticsearch-curator folder for config files  
Created below files on that folder

1. curator.yml (config file)
2. action\_close.yml (close action file)
3. action\_delete.yml (delete action file)
4. curator\_cron.sh (shell script for cron job)

## **curator.yml**

client:  
hosts:  
- 127.0.0.1  
port: 9200  
url\_prefix:  
use\_ssl: False  
certificate:  
client\_cert:  
client\_key:  
ssl\_no\_validate: False  
http\_auth:  
timeout: 30  
master\_only: False

logging:  
loglevel: INFO  
logfile:  
logformat: default  
blacklist: ['elasticsearch', 'urllib3']

## **action\_close.yml**

actions:  
1:  
action: close  
description: \>-  
Close indices older than 20 days (based on index name), for logstash-  
prefixed indices.  
options:  
delete\_aliases: False  
disable\_action: False  
filters:  
- filtertype: pattern  
kind: prefix  
value: logstash-  
- filtertype: age  
source: name  
direction: older  
timestring: '%Y.%m.%d'  
unit: days  
unit\_count: 20

## **action\_delete.yml**

actions:  
1:  
action: delete\_indices  
description: \>-  
Delete indices older than 50 days (based on index name), for logstash-  
prefixed indices. Ignore the error if the filter does not result in an  
actionable list of indices (ignore\_empty\_list) and exit cleanly.  
options:  
ignore\_empty\_list: True  
disable\_action: False  
filters:  
- filtertype: pattern  
kind: prefix  
value: logstash-  
- filtertype: age  
source: name  
direction: older  
timestring: '%Y.%m.%d'  
unit: days  
unit\_count: 50

## **curator\_cron.sh**

**#!/bin/bash**  
**#elasticsearch curator run daly**  
**#Cron job**  
**#30 2 \* \* \* /etc/elasticsearch-curator/curator\_cron.sh \>\>/var/log/curator.log 2\>&1**  
**#Close indices older than 20 days (based on index name), for logstash-**  
HOST=$(hostname)  
start\_time=$(date)  
echo "$hostname Starting curator indices Close job: $start\_time"  
/usr/bin/curator --config /etc/elasticsearch-curator/curator.yml /etc/elasticsearch-curator/action\_close.yml \>\>/var/log/curator.log 2\>&1  
stop\_time=$(date)  
echo "$hostname Stopping curator indices Close job: $stop\_time"

**#Delete indices older than 50 days (based on index name), for logstash- prefixed indices**  
start\_time=$(date)  
echo "$hostname Starting curator indices Delete job: $start\_time"  
/usr/bin/curator --config /etc/elasticsearch-curator/curator.yml /etc/elasticsearch-curator/action\_delete.yml \>\>/var/log/curator.log 2\>&1  
stop\_time=$(date)  
echo "$hostname Stopping curator indices Delete job: $stop\_time"

**added ## curator\_cron.sh for crontab runing every dat 2:30 am**  
crontab -e  
30 2 \* \* \* /etc/elasticsearch-curator/curator\_cron.sh \>\>/var/log/curator.log 2\>&1

**note :-**  
no need curator\_cron.sh file we can add  
curator derectly crontab like below if you want

> [@Elastic curator in cron job?](https://discuss.elastic.co/t/elastic-curator-in-cron-job/80139):
>
> Hi, i have curator in linux environment which is in live so i can't experiment with that . i need one clarification regarding the command i have curator files in /home/hero/.curator . If i run the below cron job command whether it will run in dry-run mode correctly or it will delete the indices in the live environment. \* \* \* \* \* /home/hero/.curator/curator --dry-run --config curator.yml delete .yml \>\> /home/hero/.curator/log.txt And also i want to know whether the command is correct or not, …

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 19, 2017, 7:28am UTC](https://discuss.elastic.co/t/creating-cron-job-for-close-and-delete-indices-from-elasticsearch/86614/2 "2017-06-19T07:28:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
