# Curator action, delete\_indices problem

**URL:** <https://discuss.elastic.co/t/curator-action-delete-indices-problem/54858>\
**Category:** Elasticsearch\
**Created:** [July 6, 2016, 5:51pm UTC](https://discuss.elastic.co/t/curator-action-delete-indices-problem/54858 "2016-07-06T17:51:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pedro\_Lopes](https://avatars.discourse-cdn.com/v4/letter/p/e0b2c6/32.png) [@Pedro\_Lopes](https://discuss.elastic.co/u/Pedro_Lopes)\
**Post date:** [July 6, 2016, 5:51pm UTC](https://discuss.elastic.co/t/curator-action-delete-indices-problem/54858/1 "2016-07-06T17:51:49Z")

</div>

Hello guys,

I have ELK reading a folder with CSV's, everything is working like a charm. I installed curator to delete indices older than 7 days, but I'm in a testing environment so I used minutes instead of days. I've started Logstash at 18:05 GMT to start inserting in Elastic, then at 18:30 GMT I did a echo to a CSV to have at least one row with a controlable timegap.

My config file is has follow, runned at 18:31 GMT:

actions:  
1:  
action: delete\_indices  
description: \>-  
Delete indices older than 45 days (based on index name), for logstash-  
prefixed indices. Ignore the error if the filter does not result in an  
actionable list of indices (ignore\_empty\_list) and exit cleanly.  
options:  
ignore\_empty\_list: True  
timeout\_override:  
continue\_if\_exception: False  
disable\_action: False  
filters:  
- filtertype: pattern  
kind: prefix  
value: logstash\_  
exclude:  
- filtertype: age  
source: creation\_date  
direction: older  
unit: minutes  
unit\_count: 20  
exclude:

But curator delete all index not the ones older than 20 minutes, so should ignore the entry at 18:30. Curator output:

2016-07-06 18:31:55,828 INFO Action #1: delete\_indices  
2016-07-06 18:31:55,829 INFO Starting new HTTP connection (1): 127.0.0.1  
2016-07-06 18:31:55,834 INFO GET [http://127.0.0.1:9200/](http://127.0.0.1:9200/) [status:200 request:0.005s]  
2016-07-06 18:31:55,836 INFO GET [http://127.0.0.1:9200/\_all/\_settings?expand\_wildcards=open%2Cclosed](http://127.0.0.1:9200/_all/_settings?expand_wildcards=open%2Cclosed) [status:200 request:0.001s]  
2016-07-06 18:31:55,838 INFO GET [http://127.0.0.1:9200/\_cluster/state/metadata/.kibana,logstash\_2016-07-06](http://127.0.0.1:9200/_cluster/state/metadata/.kibana,logstash_2016-07-06) [status:200 request:0.001s]  
2016-07-06 18:31:55,842 INFO GET [http://127.0.0.1:9200/.kibana,logstash\_2016-07-06/\_stats/store,docs](http://127.0.0.1:9200/.kibana,logstash_2016-07-06/_stats/store,docs) [status:200 request:0.004s]  
2016-07-06 18:31:55,842 INFO Index .kibana is not actionable, removing from list.  
2016-07-06 18:31:55,843 INFO Index logstash\_2016-07-06 is actionable and remains in the list.  
2016-07-06 18:31:55,843 INFO Index logstash\_2016-07-06 is actionable and remains in the list.  
2016-07-06 18:31:55,843 INFO Remains in actionable list: Index "logstash\_2016-07-06" age (1467824921), direction: "older", point of reference, (1467825115)  
2016-07-06 18:31:55,843 INFO Deleting selected indices  
2016-07-06 18:31:55,844 INFO ---deleting index logstash\_2016-07-06  
2016-07-06 18:31:55,880 INFO DELETE [http://127.0.0.1:9200/logstash\_2016-07-06?master\_timeout=30s](http://127.0.0.1:9200/logstash_2016-07-06?master_timeout=30s) [status:200 request:0.036s]  
2016-07-06 18:31:55,881 INFO GET [http://127.0.0.1:9200/\_all/\_settings?expand\_wildcards=open%2Cclosed](http://127.0.0.1:9200/_all/_settings?expand_wildcards=open%2Cclosed) [status:200 request:0.001s]

Can anyone help me? What I'm doing wrong?

Thanks in advanced 🙂

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [July 6, 2016, 6:21pm UTC](https://discuss.elastic.co/t/curator-action-delete-indices-problem/54858/2 "2016-07-06T18:21:05Z")

</div>

I only see one matching index, `logstash_2016-07-06`. Your description seems inaccurate:

> Delete indices older than 45 days (based on index name), for logstash-  
> prefixed indices. Ignore the error if the filter does not result in an  
> actionable list of indices (ignore\_empty\_list) and exit cleanly.

What I see is that you're filtering based on prefix (`logstash_`, and that's clearly working), and by age. The age your configuration suggests is a `creation_date` older than 20 minutes ago. The creation date of the `logstash_2016-07-06` is more than 20 minutes ago, so it remains in the actionable list.

I don't see anything wrong here. It's doing exactly what you told it to do. If this is not what you want Curator to do, please advise and I will see if I can help you reconfigure.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [July 6, 2016, 6:28pm UTC](https://discuss.elastic.co/t/curator-action-delete-indices-problem/54858/3 "2016-07-06T18:28:38Z")

</div>

For further consideration:

```auto
2016-07-06 18:31:55,843 INFO Remains in actionable list: Index "logstash_2016-07-06" age (1467824921), direction: "older", point of reference, (1467825115)

```

The `creation_date` is `1467824921`, which is **Wed, 06 Jul 2016 17:08:41 GMT**  
The point of reference is `1467825115`, which is **Wed, 06 Jul 2016 17:11:55 GMT** , which is 20 minutes before 17:31:55 GMT. You're apparently ahead of GMT by 1 hour, so your log entry reads `2016-07-06 18:31:55,843`

The raw comparison states that the index was created at 17:08:41, which is older than your designated reference point of 17:11:55, so the index is slated for deletion.

---

<div class="post-metadata">

**Author:** ![Pedro\_Lopes](https://avatars.discourse-cdn.com/v4/letter/p/e0b2c6/32.png) [@Pedro\_Lopes](https://discuss.elastic.co/u/Pedro_Lopes)\
**Post date:** [July 7, 2016, 9:41am UTC](https://discuss.elastic.co/t/curator-action-delete-indices-problem/54858/4 "2016-07-07T09:41:18Z")

</div>

Hello Aaron,

That would be a great point, and actually you were correct. To avoid a smaller timespace, I did other test.

Yesterday I left the data from Elastic, added new data about 5 minutes ago. And reconfigured action file to:  
`unit: hours unit_count: 12`

So it should delete indices older than 12 hours, weirdly deleted all.

---

<div class="post-metadata">

**Author:** ![Pedro\_Lopes](https://avatars.discourse-cdn.com/v4/letter/p/e0b2c6/32.png) [@Pedro\_Lopes](https://discuss.elastic.co/u/Pedro_Lopes)\
**Post date:** [July 7, 2016, 10:41am UTC](https://discuss.elastic.co/t/curator-action-delete-indices-problem/54858/5 "2016-07-07T10:41:19Z")

</div>

Hello again Aaron,

I did it with minutes search, had 20K records each 10k block with difference of 15 min. Runned action file with unit in minutes older than 15min and it worked :). Was your tip of the timestamp 🙂

Thanks for your support.

Best regards,  
Pedro Lopes

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:37pm UTC](https://discuss.elastic.co/t/curator-action-delete-indices-problem/54858/6 "2017-07-05T22:37:24Z")

</div>


