# Curator and the close command

**URL:** <https://discuss.elastic.co/t/curator-and-the-close-command/34168>\
**Category:** Elasticsearch\
**Created:** [November 9, 2015, 3:57pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168 "2015-11-09T15:57:53Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![tyosick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tyosick/32/5814_2.png) [@tyosick](https://discuss.elastic.co/u/tyosick)\
**Post date:** [November 9, 2015, 3:57pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168/1 "2015-11-09T15:57:53Z")

</div>

How do I use curator's "close" command feature with age of indices? The documentation page only shows this:

$ curator close --help  
Usage: curator close [OPTIONS] COMMAND [ARGS]...

Close indices

Options:  
--help Show this message and exit.

Commands:  
indices Index selection.

I need to close indices based on either space or age, but the documentation does not show how it's done. Please help. Thank you!

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 9, 2015, 4:12pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168/2 "2015-11-09T16:12:59Z")

</div>

The "[Getting Started](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/getting-started.html)" section helps you to navigate the nested command structure, particularly [The Command-Line Interface](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/command-line.html) and [Examples](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/examples.html)

---

<div class="post-metadata">

**Author:** ![tyosick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tyosick/32/5814_2.png) [@tyosick](https://discuss.elastic.co/u/tyosick)\
**Post date:** [November 9, 2015, 4:26pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168/3 "2015-11-09T16:26:24Z")

</div>

I've looked on that page already and it does not state how to close indices days/minutes/hours old. It shows this:

curator --host 10.0.0.2 close indices --exclude do-not-touch --exclude logstash-2015.03

---

<div class="post-metadata">

**Author:** ![tyosick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tyosick/32/5814_2.png) [@tyosick](https://discuss.elastic.co/u/tyosick)\
**Post date:** [November 9, 2015, 4:32pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168/4 "2015-11-09T16:32:57Z")

</div>

So I tried the following command, and I think I'm getting closer:

curator close indices --older-than 1 --time-unit hours

2015-11-09 16:30:12,125 ERROR Parameters --older-than and --newer-than  
require the --timestring parameter

Can you clarify what it's asking for as far as the --timestring parameter?  
My logstash index format is "logstash-2015.11.09"

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 9, 2015, 4:33pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168/5 "2015-11-09T16:33:29Z")

</div>

Ah, I see. You're looking for specifics, and the documentation does not do this.

The examples and docs are non-specific because every command that uses the [`indices`](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/indices-subcommand.html) [sub-command](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/subcommand.html) uses the same [Index Selection](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index-selection.html) parameters, including the [`close`](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/close.html) command:

> **! Important**  
> This command requires the [indices](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/indices-subcommand.html) [subcommand](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/subcommand.html) for [index selection](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index-selection.html).

The links in the documentation are to help explain the usage of the nested command/subcommand structure. The same "indices" arguments that work in one example will work for all.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 9, 2015, 4:35pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168/6 "2015-11-09T16:35:41Z")

</div>

> [@tyosick](#):
>
> Can you clarify what it's asking for as far as the --timestring parameter?

See the [timestring](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/timestring.html) documentation. It has links to the [python strftime formatting](https://docs.python.org/2/library/datetime.html#strftime-and-strptime-behavior) examples that will help you.

> [@tyosick](#):
>
> My logstash index format is "logstash-2015.11.09"

That would result in a timestring of `%Y.%m.%d`

---

<div class="post-metadata">

**Author:** ![tyosick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tyosick/32/5814_2.png) [@tyosick](https://discuss.elastic.co/u/tyosick)\
**Post date:** [November 9, 2015, 5:27pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168/7 "2015-11-09T17:27:32Z")

</div>

So how would that command look? Could you check mine below and tell me what is wrong?

curator close indices --older-than 1 %Y.%m.%d --time-unit hours  
2015-11-09 17:21:51,806 ERROR Parameters --older-than and --newer-than require the --timestring parameter

---

<div class="post-metadata">

**Author:** ![tyosick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tyosick/32/5814_2.png) [@tyosick](https://discuss.elastic.co/u/tyosick)\
**Post date:** [November 9, 2015, 5:46pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168/8 "2015-11-09T17:46:17Z")

</div>

Now i'm getting a different error:

curator close indices --older-than 1 --time-unit hours 1 --timestring %Y.%m.%d  
Usage: curator close indices [OPTIONS]

Error: Got unexpected extra argument (1)

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 9, 2015, 6:03pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168/9 "2015-11-09T18:03:31Z")

</div>

For one, you're using `hours` but your timestring is daily. You can't use hours unless `%H` appears in your timestring.

The unexpected argument comes between `hours` and `--timestring`. You don't need that `1` there. That's what's causing the error.

---

<div class="post-metadata">

**Author:** ![tyosick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tyosick/32/5814_2.png) [@tyosick](https://discuss.elastic.co/u/tyosick)\
**Post date:** [November 9, 2015, 6:17pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168/10 "2015-11-09T18:17:55Z")

</div>

Got it. Thanks Aaron. My final command worked:

curator close indices --older-than 1 --time-unit days --timestring %Y.%m.%d

2015-11-09 18:04:55,857 INFO Job starting: close indices  
2015-11-09 18:04:55,915 WARNING No indices matched provided args: {'regex': None, 'index': (), 'suffix': None, 'newer\_than': None, 'closed\_only': False, 'prefix': None, 'time\_unit': 'days', 'timestring': u'%Y.%m.%d', 'exclude': (), 'older\_than': 1, 'all\_indices': False}  
No indices matched provided args: {'regex': None, 'index': (), 'suffix': None, 'newer\_than': None, 'closed\_only': False, 'prefix': None, 'time\_unit': 'days', 'timestring': u'%Y.%m.%d', 'exclude': (), 'older\_than': 1, 'all\_indices': False}

---

<div class="post-metadata">

**Author:** ![tyosick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tyosick/32/5814_2.png) [@tyosick](https://discuss.elastic.co/u/tyosick)\
**Post date:** [November 10, 2015, 1:14pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168/11 "2015-11-10T13:14:01Z")

</div>

Hi Aaron-

One last question...

When indices are closed, what exactly happens to them? Does it move to a different directory? How are they distinguishable apart from open indices?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 10, 2015, 2:27pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168/12 "2015-11-10T14:27:19Z")

</div>

Indices do not move. They are only marked as closed and unavailable for search.

There are only 2 things Elasticsearch can do with closed indices: open them, and delete them. Even deletes are a brief "open" followed by an immediate delete.

Elasticsearch cannot calculate the size of closed indices. Elasticsearch does not keep tabs on how much disk-space closed indices consume. If you close indices, you will need to rely on operating-system-level disk usage monitoring.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:39pm UTC](https://discuss.elastic.co/t/curator-and-the-close-command/34168/13 "2017-07-05T23:39:27Z")

</div>


