# Data Retention Policy for Storing and Deleting

**URL:** <https://discuss.elastic.co/t/data-retention-policy-for-storing-and-deleting/44104>\
**Category:** Elasticsearch\
**Created:** [March 11, 2016, 2:58am UTC](https://discuss.elastic.co/t/data-retention-policy-for-storing-and-deleting/44104 "2016-03-11T02:58:19Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [March 11, 2016, 2:58am UTC](https://discuss.elastic.co/t/data-retention-policy-for-storing-and-deleting/44104/1 "2016-03-11T02:58:19Z")

</div>

How does ES know or FileBeat know -

1. How much data to be loaded to store ? i.e. Data within this month only or Data within last 3 months will be loaded only. By loaded I meant stored for searching when a text is searched in Kiabana
2. How is the data retention policy set for ES? i.e. a month of data to be stored and rest to be deleted.

Which line of code explains the above ?

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [March 11, 2016, 4:16am UTC](https://discuss.elastic.co/t/data-retention-policy-for-storing-and-deleting/44104/2 "2016-03-11T04:16:45Z")

</div>

Data retention policy isnt a thing elasticsearch has natively. You can use  
tools like curator to manage creating daily or weekly indices.

---

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [March 11, 2016, 6:48am UTC](https://discuss.elastic.co/t/data-retention-policy-for-storing-and-deleting/44104/3 "2016-03-11T06:48:04Z")

</div>

By default how much data is loaded into ES via FB ? Is there any time frame setting to configure this ?

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [March 11, 2016, 1:03pm UTC](https://discuss.elastic.co/t/data-retention-policy-for-storing-and-deleting/44104/4 "2016-03-11T13:03:35Z")

</div>

> [@Sameer\_Panicker](#):
>
> By default how much data is loaded into ES via FB ?

Elasticsearch will keep all the data you through at it. It won't delete things unless you tell it to. A tool like curator will tell it to do just that.

---

<div class="post-metadata">

**Author:** ![thn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thn/32/8061_2.png) [@thn](https://discuss.elastic.co/u/thn)\
**Post date:** [March 11, 2016, 1:30pm UTC](https://discuss.elastic.co/t/data-retention-policy-for-storing-and-deleting/44104/5 "2016-03-11T13:30:45Z")

</div>

In addition to what @nik9000 said... each index consists of N shards and M replicas. Each shard is equivalent to one Lucene index and each Lucene index can hold roughly 2B documents. From here, you can do your own calculation in terms of how many shards one index should have when you want to have 1) one big index 2) one index per month and so on.

---

<div class="post-metadata">

**Author:** ![raghvendra](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@raghvendra](https://discuss.elastic.co/u/raghvendra)\
**Post date:** [June 20, 2017, 8:20am UTC](https://discuss.elastic.co/t/data-retention-policy-for-storing-and-deleting/44104/6 "2017-06-20T08:20:16Z")

</div>

@nik9000 Hey  
I want to calculate Retention rate of Apache access log data for one month. Can you help me how to get it done. I have been told to use curator , but I don't know how to do .  
Can you suggest any better approach or any document / link related to curator, which can be helpful in my case ?

Any advice would be appreciated .

---

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [June 21, 2017, 5:32am UTC](https://discuss.elastic.co/t/data-retention-policy-for-storing-and-deleting/44104/7 "2017-06-21T05:32:41Z")

</div>

If you are looking to purge records using rest api calls is the easiest option. I faced some issues while configuring curator and its been a long while hence don't remember the issue.

Now, i can suggest to use the rest api calls to purge all the data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 4:16am UTC](https://discuss.elastic.co/t/data-retention-policy-for-storing-and-deleting/44104/8 "2022-11-04T04:16:15Z")

</div>


