# Curator --snapshot option matching all snapshots

**URL:** <https://discuss.elastic.co/t/curator-snapshot-option-matching-all-snapshots/64010>\
**Category:** Elasticsearch\
**Created:** [October 26, 2016, 1:56pm UTC](https://discuss.elastic.co/t/curator-snapshot-option-matching-all-snapshots/64010 "2016-10-26T13:56:55Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![David\_McClain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_mcclain/32/8613_2.png) [@David\_McClain](https://discuss.elastic.co/u/David_McClain)\
**Post date:** [October 26, 2016, 1:56pm UTC](https://discuss.elastic.co/t/curator-snapshot-option-matching-all-snapshots/64010/1 "2016-10-26T13:56:56Z")

</div>

I am trying to use the curator tool to automate deleting older snapshots.

Up until now, I've been using the Elasticsearch API to create the snapshots instead of Curator.

Curator version: 3.5.1

The following:

```auto
curator --host `hostname -f` --port 9201 show snapshots --repository logstash_backup

```

produces a large list of snapshots, just over 200.

Sample:  
ls\_2016.04.11  
ls\_2016.04.12  
ls\_2016.04.13  
ls\_2016.04.14  
ls\_2016.04.15  
ls\_2016.04.16  
ls\_2016.04.17

**Problem 1:**  
Matching by 'older-than' produces no results - I tried as low as 1 day as you can see in the example:

```auto
(13:45:37) PROD ->curator --host `hostname -f`show snapshots --repository logstash_backup --older-than 100 --time-unit days
2016-10-26 13:45:41,737 INFO Job starting: show snapshots
2016-10-26 13:45:41,885 WARNING No snapshots matched provided args.
No snapshots matched provided args.

(13:45:41) PROD ->curator --host `hostname -f` show snapshots --repository logstash_backup --older-than 1 --time-unit days
2016-10-26 13:45:46,101 INFO Job starting: show snapshots
2016-10-26 13:45:46,252 WARNING No snapshots matched provided args.
No snapshots matched provided args.

```

**Problem 2:**  
Deleting by specific snapshot name using --snapshot ends up deleting **all** snapshots instead of just the one specified.  
Example below using the 'show' option.

```auto
(13:45:46) PROD ->curator --host `hostname -f` --port 9201 show snapshots --repository logstash_backup --snapshot ls_2016.10.19
2016-10-26 13:46:10,868 INFO Job starting: show snapshots
2016-10-26 13:46:11,120 INFO Adding ls_2016.10.19 from command-line argument
2016-10-26 13:46:11,120 INFO Matching snapshots:
ls_2016.04.11
ls_2016.04.12
ls_2016.04.13
ls_2016.04.14
...

```

This goes on to list all my snapshots. I thought maybe it was seeing the '.' and matching all, so I tried escaping it, but it had no effect.

I did see that this was an issue in earlier Curator versions based on another discussion: [Curator is deleting all snapshots](https://discuss.elastic.co/t/curator-is-deleting-all-snapshots/36833)  
However, the only resolution there was to use older-than and I couldn't find any issues on the github project to match.

Any thoughts?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 1, 2016, 1:02pm UTC](https://discuss.elastic.co/t/curator-snapshot-option-matching-all-snapshots/64010/2 "2016-11-01T13:02:32Z")

</div>

Only Curator 4 filters by the actual snapshot creation time. With Curator 3, you need to use a `--timestring` to match the date in the snapshot name. See [https://www.elastic.co/guide/en/elasticsearch/client/curator/3.5/snapshot-selection.html](https://www.elastic.co/guide/en/elasticsearch/client/curator/3.5/snapshot-selection.html)

In your case, it seems that `--timestring '%Y.%m.%d'` will work.

---

<div class="post-metadata">

**Author:** ![Ashish\_Goel](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@Ashish\_Goel](https://discuss.elastic.co/u/Ashish_Goel)\
**Post date:** [November 8, 2016, 6:40am UTC](https://discuss.elastic.co/t/curator-snapshot-option-matching-all-snapshots/64010/3 "2016-11-08T06:40:56Z")

</div>

When mentioning "Problem 1", I see that you have not mentioned the port. Curator must be failing with connection process, leading to no snapshots found.  
In "Problem 2", you used --snapshot flag which I believe is buggy in the old curator versions as mentioned in the discussion you referenced.

I am using --older-than flag in my setup with curator 3.2.3. Works fine.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 8, 2016, 1:30pm UTC](https://discuss.elastic.co/t/curator-snapshot-option-matching-all-snapshots/64010/4 "2016-11-08T13:30:29Z")

</div>

> [@Ashish\_Goel](#):
>
> I see that you have not mentioned the port. Curator must be failing with connection process, leading to no snapshots found.

But `--port` is not required. If not specified, it defaults to `9200`.

> [@Ashish\_Goel](#):
>
> In "Problem 2", you used --snapshot flag which I believe is buggy in the old curator versions as mentioned in the discussion you referenced.

Not buggy, _per se._ It's designed to allow you to **re-add** a given snapshot that may have been excluded by your filters. In this case, it's merely re-adding it to the list of all snapshots, so it looks like it's not working correctly. To get the desired behavior with example 2, set a `--prefix` that will not match any snapshots, and then use `--snapshot` to add the one index you're trying to use.

---

<div class="post-metadata">

**Author:** ![Ashish\_Goel](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@Ashish\_Goel](https://discuss.elastic.co/u/Ashish_Goel)\
**Post date:** [November 8, 2016, 1:40pm UTC](https://discuss.elastic.co/t/curator-snapshot-option-matching-all-snapshots/64010/5 "2016-11-08T13:40:49Z")

</div>

I think David has set the port to 9201.  
The very first command he posted which gives a long list of snapshots was using 9201 as the port.  
That is why I mentioned the --port thing.

For the second problem, thanks for the info, I was not aware of the --prefix flag.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:06pm UTC](https://discuss.elastic.co/t/curator-snapshot-option-matching-all-snapshots/64010/6 "2017-07-05T22:06:07Z")

</div>


