# Curator 5.6.0 deletes indices newer than unit\_count

**URL:** <https://discuss.elastic.co/t/curator-5-6-0-deletes-indices-newer-than-unit-count/187393>\
**Category:** Elasticsearch\
**Created:** [June 25, 2019, 5:00pm UTC](https://discuss.elastic.co/t/curator-5-6-0-deletes-indices-newer-than-unit-count/187393 "2019-06-25T17:00:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ayush\_Mathur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayush_mathur/32/77134_2.png) [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Post date:** [June 25, 2019, 5:00pm UTC](https://discuss.elastic.co/t/curator-5-6-0-deletes-indices-newer-than-unit-count/187393/1 "2019-06-25T17:00:09Z")

</div>

Elastic Stack version: 6.2.3  
Curator Version : 5.6.0

We have configured curator to delete the indices which are older than 14 days where indices are rolled on daily basis.  
The configuration looks like:

```
    action: delete_indices
    description: "Delete \"security\" indices older than 14 days,(ignore_empty_list) and exit cleanly."
    filters: 
      - 
        exclude: ~
        filtertype: pattern
        kind: prefix
        value: security
      - 
        direction: older
        exclude: ~
        filtertype: age
        source: name
        timestring: "%Y.%m.%d"
        unit: days
        unit_count: 14
    options: 
      continue_if_exception: false
      disable_action: false
      ignore_empty_list: true
      timeout_override: ~

```

However, it has been noticed several times that curator is also deleting the newer indices.  
For 24th June midnight run, the output was:

```
2019-06-25 00:04:46,739 INFO Trying Action ID: 15, "delete_indices": Delete "security" indices older than 14 days,(ignore_empty_list) and exit cleanly.
--
  | 2019-06-25 00:04:58,935 INFO Deleting selected indices: [u'security-logging.ec2.2019.06.10', u'security-logging.ec2.2019.06.11', u'security-logging.ec2.2019.06.09', u'security-logging.ec2.2019.06.08', u'security-logging.ec2.2018.06.22', u'security-logging.ec2.2018.06.23', u'security-logging.ec2.2018.06.21', u'security-logging.ec2.2018.06.24', u'security-logging.ec2.2018.06.25']
  | 2019-06-25 00:04:58,935 INFO ---deleting index security-logging.ec2.2019.06.10
  | 2019-06-25 00:04:58,936 INFO ---deleting index security-logging.ec2.2019.06.11
  | 2019-06-25 00:04:58,936 INFO ---deleting index security-logging.ec2.2019.06.09
  | 2019-06-25 00:04:58,936 INFO ---deleting index security-logging.ec2.2019.06.08
  | 2019-06-25 00:04:58,936 INFO ---deleting index security-logging.ec2.2018.06.22
  | 2019-06-25 00:04:58,936 INFO ---deleting index security-logging.ec2.2018.06.23
  | 2019-06-25 00:04:58,936 INFO ---deleting index security-logging.ec2.2018.06.21
  | 2019-06-25 00:04:58,936 INFO ---deleting index security-logging.ec2.2018.06.24
  | 2019-06-25 00:04:58,936 INFO ---deleting index security-logging.ec2.2018.06.25
  | 2019-06-25 00:05:01,089 INFO Action ID: 15, "delete_indices" completed.
  | 2019-06-25 00:05:01,089 INFO Job completed.
```

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 25, 2019, 6:10pm UTC](https://discuss.elastic.co/t/curator-5-6-0-deletes-indices-newer-than-unit-count/187393/2 "2019-06-25T18:10:11Z")

</div>

Please run with `--dry-run` and with `loglevel: DEBUG` set. With these, it won't delete anything, but it will show you how Curator made decisions (in this case, the math comparisons that lead to which indices are selected).

Please paste the relevant output here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2019, 8:10pm UTC](https://discuss.elastic.co/t/curator-5-6-0-deletes-indices-newer-than-unit-count/187393/3 "2019-07-23T20:10:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
