# Curator and ELK 5.4

**URL:** <https://discuss.elastic.co/t/curator-and-elk-5-4/85687>\
**Category:** Elasticsearch\
**Created:** [May 14, 2017, 5:38pm UTC](https://discuss.elastic.co/t/curator-and-elk-5-4/85687 "2017-05-14T17:38:00Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![hispeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hispeed/32/16232_2.png) [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Post date:** [May 14, 2017, 5:38pm UTC](https://discuss.elastic.co/t/curator-and-elk-5-4/85687/1 "2017-05-14T17:38:00Z")

</div>

Hi,

I have installed curator via RPM package on CentOS 7. I run Elasticsearch 5.4. I want to run curator on it to delete old indices.

I have 2 files created. I hope they are correct:

ctaction.yml

> * * *
> 
> actions:  
> 1:  
> action: delete\_indices  
> options:  
> ignore\_empty\_list: True  
> disable\_action: False  
> filters:
> 
> - filtertype: pattern  
> kind: prefix  
> value: logstash-
> - filtertype: age  
> source: name  
> direction: older  
> timestring: '%Y.%m.%d'  
> unit: days  
> unit\_count: 3

ctcurator.yml

> * * *
> 
> client:  
> hosts:
> 
> - 127.0.0.1  
> port: 9200  
> url\_prefix:  
> use\_ssl: False  
> certificate:  
> client\_cert:  
> client\_key:  
> ssl\_no\_validate: False  
> http\_auth:  
> timeout: 30  
> master\_only: False

> logging:  
> loglevel: INFO  
> logfile: /var/log/curator.log  
> logformat: default  
> blacklist: ['elasticsearch', 'urllib3']

I use the following command for test:

> /usr/bin/curator --config /etc/curator/ctcurator.yml /etc/curator/ctaction.yml --dry-run

Error:

> Configuration: filters: Location: Action ID "1", action "delete\_indices", "filte rs": Bad Value: "None", 0. Check configuration file.

Can someone help me?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 14, 2017, 6:44pm UTC](https://discuss.elastic.co/t/curator-and-elk-5-4/85687/2 "2017-05-14T18:44:33Z")

</div>

I can't tell whether the files are properly indented, or have spaces between lines, or any other number of things which could cause invalid YAML syntax.

Please paste the files _exactly_ as they are in your configuration, between triple back-ticks, like this:

````
```
PASTE FILE HERE
```

````

The error seems to indicate that a problem with the filter block. Without exact pasting between those triple back-ticks, I won't be able to further troubleshoot.

---

<div class="post-metadata">

**Author:** ![hispeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hispeed/32/16232_2.png) [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Post date:** [May 14, 2017, 6:50pm UTC](https://discuss.elastic.co/t/curator-and-elk-5-4/85687/3 "2017-05-14T18:50:10Z")

</div>

Hi,

Ok here we go:  
This is: ctaction.yml

```
---
#Hier werden die Tage eingestellt für den Curator.
actions:
  1:
   action: delete_indices
   options:
    ignore_empty_list: True
    disable_action: False
  filters:
  - filtertype: pattern
    kind: prefix
    value: logstash-
  - filtertype: age
    source: name
    direction: older
    timestring: '%Y.%m.%d'
    unit: days
    unit_count: 3

```

This is: ctcurator.yml

```
---
#Curator Konfiguration hiermit werden die Idices von Elasticsearch gelöscht.
client:
 hosts:
 - 127.0.0.1
 port: 9200
 url_prefix:
 use_ssl: False
 certificate:
 client_cert:
 client_key:
 ssl_no_validate: False
 http_auth:
 timeout: 30
 master_only: False

logging:
 loglevel: INFO
 logfile: /var/log/curator.log
 logformat: default
 blacklist: ['elasticsearch', 'urllib3']
```

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 14, 2017, 7:09pm UTC](https://discuss.elastic.co/t/curator-and-elk-5-4/85687/4 "2017-05-14T19:09:07Z")

</div>

I see it now. The `filters` block needs to be indented exactly as far as the `options` and also `action` (singular, not `actions` at the root level.

---

<div class="post-metadata">

**Author:** ![hispeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hispeed/32/16232_2.png) [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Post date:** [May 14, 2017, 7:13pm UTC](https://discuss.elastic.co/t/curator-and-elk-5-4/85687/5 "2017-05-14T19:13:33Z")

</div>

I have corrected that. Now i get the following error:

```
 /usr/bin/curator --config /etc/curator/ctcurator.yml /etc/curator/ctaction.yml --dry-run
Configuration: Actions File: Location: root: Bad Value: "{1: {'action': 'delete_indices', 'options': {'ignore_empty_list': True, 'disable_action': False}, 'filters': [{'filtertype': 'pattern', 'kind': 'prefix', 'value': 'logstash-'}, {'filtertype': 'age', 'source': 'name', 'direction': 'older', 'timestring': '%Y.%m.%d', 'unit': 'days', 'unit_count': 3}]}}", extra keys not allowed @ data['action']. Check configuration file.

```

The action files looks now like that.

```
---
#Hier werden die Tage eingestellt für den Curator.
action:
  1:
   action: delete_indices
   options:
    ignore_empty_list: True
    disable_action: False
   filters:
   - filtertype: pattern
     kind: prefix
     value: logstash-
   - filtertype: age
     source: name
     direction: older
     timestring: '%Y.%m.%d'
     unit: days
     unit_count: 3
```

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 14, 2017, 7:18pm UTC](https://discuss.elastic.co/t/curator-and-elk-5-4/85687/6 "2017-05-14T19:18:57Z")

</div>

The root level should still be `actions`. Just change that top line.

---

<div class="post-metadata">

**Author:** ![hispeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hispeed/32/16232_2.png) [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Post date:** [May 14, 2017, 7:24pm UTC](https://discuss.elastic.co/t/curator-and-elk-5-4/85687/7 "2017-05-14T19:24:07Z")

</div>

Thanks it is working :). Awesome!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2017, 7:26pm UTC](https://discuss.elastic.co/t/curator-and-elk-5-4/85687/8 "2017-06-11T19:26:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
