# Curator instead of ILM to delete old indices

**URL:** <https://discuss.elastic.co/t/curator-instead-of-ilm-to-delete-old-indices/264186>\
**Category:** Kibana\
**Tags:** curator\
**Created:** [February 12, 2021, 9:45pm UTC](https://discuss.elastic.co/t/curator-instead-of-ilm-to-delete-old-indices/264186 "2021-02-12T21:45:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bruceclegg](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Post date:** [February 12, 2021, 9:45pm UTC](https://discuss.elastic.co/t/curator-instead-of-ilm-to-delete-old-indices/264186/1 "2021-02-12T21:45:53Z")

</div>

I have been unable to use ILM to manage my indices. The developers have the index names hardcoded in their code and don't want to change the index names.

I attempted to use curator and was only partially successful. It appeared to delete the old index, but it also knocked the web interface down. I had to restart kibana to get the browser interface back up AND the job deleted the index patterns. Can someone tell me where I went wrong and what I need to do to fix this?

[root@ELK curator]# cat action.yml  
actions:  
1:  
action: delete\_indices  
description: \>-  
Delete indices older than 30 days (based on creation date).  
options:  
ignore\_empty\_list: True  
timeout\_override:  
continue\_if\_exception: False  
disable\_action: False  
filters:  
- filtertype: age  
source: creation\_date  
direction: older  
timestring: '%Y.%m.%d'  
unit: days  
unit\_count: 30

[root@ELK curator]# cat config.yml  
client:  
hosts:  
- 10.X.X.X  
port: 9200  
url\_prefix:  
use\_ssl: False  
certificate:  
client\_cert: /etc/elasticsearch/config/certs/elk/elk.crt  
client\_key: /etc/elasticsearch/config/certs/elk/elk.key  
ssl\_no\_validate: False  
http\_auth: kibana:  
timeout: 30  
master\_only: False

logging:  
loglevel: INFO  
logfile: /var/log/curator/curator\_log  
logformat: default  
blacklist: ['elasticsearch', 'urllib3']

Logging from dry-run:  
2021-02-12 15:31:24,750 INFO Preparing Action ID: 1, "delete\_indices"  
2021-02-12 15:31:24,752 INFO Creating client object and testing connection  
2021-02-12 15:31:24,758 WARNING Use of "http\_auth" is deprecated. Please use "username" and "password" instead.  
2021-02-12 15:31:24,758 INFO Instantiating client object  
2021-02-12 15:31:24,760 INFO Testing client connectivity  
2021-02-12 15:31:24,788 INFO Successfully created Elasticsearch client object with provided settings  
2021-02-12 15:31:24,794 INFO Trying Action ID: 1, "delete\_indices": Delete indices older than 30 days (based on creation date).  
2021-02-12 15:31:24,982 INFO DRY-RUN MODE. No changes will be made.  
2021-02-12 15:31:24,982 INFO (CLOSED) indices may be shown that may not be acted on by action "delete\_indices".  
2021-02-12 15:31:24,982 INFO DRY-RUN: delete\_indices: .kibana6\_7 with arguments: {}  
2021-02-12 15:31:24,983 INFO DRY-RUN: delete\_indices: .kibana6\_8 with arguments: {}  
2021-02-12 15:31:24,983 INFO DRY-RUN: delete\_indices: .kibana\_task\_manager with arguments: {}  
2021-02-12 15:31:24,983 INFO DRY-RUN: delete\_indices: .reporting-2021.01.03 with arguments: {}  
2021-02-12 15:31:24,983 INFO DRY-RUN: delete\_indices: .tasks with arguments: {}  
2021-02-12 15:31:24,983 INFO DRY-RUN: delete\_indices: aapc.log-local with arguments: {}  
2021-02-12 15:31:24,984 INFO DRY-RUN: delete\_indices: banking-development- with arguments: {}  
2021-02-12 15:31:24,984 INFO Action ID: 1, "delete\_indices" completed.  
2021-02-12 15:31:24,985 INFO Job completed.

Logs from NOT dry-run:

2021-02-12 15:41:44,830 INFO Preparing Action ID: 1, "delete\_indices"  
2021-02-12 15:41:44,831 INFO Creating client object and testing connection  
2021-02-12 15:41:44,836 WARNING Use of "http\_auth" is deprecated. Please use "username" and "password" instead.  
2021-02-12 15:41:44,837 INFO Instantiating client object  
2021-02-12 15:41:44,838 INFO Testing client connectivity  
2021-02-12 15:41:44,847 INFO Successfully created Elasticsearch client object with provided settings  
2021-02-12 15:41:44,853 INFO Trying Action ID: 1, "delete\_indices": Delete indices older than 30 days (based on creation date).  
2021-02-12 15:41:44,998 INFO Deleting 7 selected indices: ['.kibana6\_8', 'aapc.log-local', '.kibana\_task\_manager', '.tasks', '.kibana6\_7', 'banking-development-', '.reporting-2021.01.03']  
2021-02-12 15:41:44,999 INFO ---deleting index .kibana6\_8  
2021-02-12 15:41:44,999 INFO ---deleting index aapc.log-local  
2021-02-12 15:41:44,999 INFO ---deleting index .kibana\_task\_manager  
2021-02-12 15:41:44,999 INFO ---deleting index .tasks  
2021-02-12 15:41:45,000 INFO ---deleting index .kibana6\_7  
2021-02-12 15:41:45,000 INFO ---deleting index banking-development-  
2021-02-12 15:41:45,000 INFO ---deleting index .reporting-2021.01.03  
2021-02-12 15:41:45,802 INFO Action ID: 1, "delete\_indices" completed.  
2021-02-12 15:41:45,803 INFO Job completed.

I was expecting the aapc.log-local and the banking-development index to be deleted - the other indexes are all less than 30 days old. I am surmising I should not have deleted the other 5 indices. How can I modify curator to skip those?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [February 12, 2021, 10:29pm UTC](https://discuss.elastic.co/t/curator-instead-of-ilm-to-delete-old-indices/264186/2 "2021-02-12T22:29:28Z")

</div>

> [@Bruceclegg](#):
>
> Can someone tell me where I went wrong and what I need to do to fix this?

Sure thing!

> [@Bruceclegg](#):
>
> ```auto
> filters:
> - filtertype: age
> source: creation_date
> direction: older
> timestring: '%Y.%m.%d'
> unit: days
> unit_count: 30
> 
> ```

This is your only filter, an `age` filter which checks the `creation_date` of every index passed into it. Since you're not also filtering for named indices, this filter will identify _every_ index older than 30 days, including system indices, like` .kibana` ones.

You should insert a `pattern` filter and do [`kind: regex`](https://www.elastic.co/guide/en/elasticsearch/client/curator/5.8/filtertype_pattern.html#_regex) to use logical OR, like the documentation suggests:

```auto
- filtertype: pattern
  kind: regex
  value: '^banking-development|^aapc.log-local'

```

If you put this above (or after, but it saves the creation date calculation if you do this part before the `age` filter) your existing filter, only the banking-development and aapc.log-local indices would have been deleted.

---

<div class="post-metadata">

**Author:** ![Bruceclegg](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Post date:** [February 17, 2021, 3:37pm UTC](https://discuss.elastic.co/t/curator-instead-of-ilm-to-delete-old-indices/264186/3 "2021-02-17T15:37:20Z")

</div>

Thank You! I have set this up and it looks good in --dry-run.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2021, 3:37pm UTC](https://discuss.elastic.co/t/curator-instead-of-ilm-to-delete-old-indices/264186/4 "2021-03-17T15:37:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
