# Delete by query not working

**URL:** <https://discuss.elastic.co/t/delete-by-query-not-working/11943>\
**Category:** Elasticsearch\
**Created:** [May 13, 2013, 9:16pm UTC](https://discuss.elastic.co/t/delete-by-query-not-working/11943 "2013-05-13T21:16:24Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Loic\_Bertron](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/loic_bertron/32/1794_2.png) [@Loic\_Bertron](https://discuss.elastic.co/u/Loic_Bertron)\
**Post date:** [May 13, 2013, 9:16pm UTC](https://discuss.elastic.co/t/delete-by-query-not-working/11943/1 "2013-05-13T21:16:24Z")

</div>

Hey guys,

I'm trying to delete some tweets i've been indexing automatically after 1h  
but even TTL or delete by query is not working.  
When i set TTL, nothing happen.  
Same result if i try this command :

curl -XDELETE localhost:9200/twitter/\_query -d '{  
"query" : {  
"filtered": {  
"query": {"match\_all": {}},  
"filter": {"range": {  
"created\_at": {  
"lt": "now-1h"  
}  
}}  
}  
}  
}'

What am i doing wrong ?

Loïc

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 13, 2013, 10:12pm UTC](https://discuss.elastic.co/t/delete-by-query-not-working/11943/2 "2013-05-13T22:12:28Z")

</div>

Hey Loic!

Could you share a full curl recreation of your problem?  
I would like to reproduce it.

Thanks

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr | @scrutmydocs

Le 13 mai 2013 à 23:16, Loïc Bertron [loic.bertron@gmail.com](mailto:loic.bertron@gmail.com) a écrit :

> Hey guys,
> 
> I'm trying to delete some tweets i've been indexing automatically after 1h but even TTL or delete by query is not working.  
> When i set TTL, nothing happen.  
> Same result if i try this command :
> 
> curl -XDELETE localhost:9200/twitter/\_query -d '{  
> "query" : {  
> "filtered": {  
> "query": {"match\_all": {}},  
> "filter": {"range": {  
> "created\_at": {  
> "lt": "now-1h"  
> }  
> }}  
> }  
> }  
> }'
> 
> What am i doing wrong ?
> 
> Loïc
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Loic\_Bertron](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/loic_bertron/32/1794_2.png) [@Loic\_Bertron](https://discuss.elastic.co/u/Loic_Bertron)\
**Post date:** [May 14, 2013, 8:14pm UTC](https://discuss.elastic.co/t/delete-by-query-not-working/11943/3 "2013-05-14T20:14:53Z")

</div>

Hey David,

Thanks for your reply.  
Here is attached an example tweet that i'm inserting with this command :

curl -XPUT '[http://localhost:9200/twitter/tweet/1?ttl=1h](http://localhost:9200/twitter/tweet/1?ttl=1h)' -d @tweet.json

When i'm running the following command

curl -XGET '[http://localhost:9200/twitter/tweet/\_search](http://localhost:9200/twitter/tweet/_search)' -d @query.json

I get more than 10000 results

If i try to delete by query with this one :

curl -XDELETE '[http://localhost:9200/twitter/tweet/\_query](http://localhost:9200/twitter/tweet/_query)' -d @query.json

Does it helps reproduce the error ?

Le 2013-05-13 à 18:13, David Pilato [david@pilato.fr](mailto:david@pilato.fr) a écrit :

> Hey Loic!
> 
> Could you share a full curl recreation of your problem?  
> I would like to reproduce it.
> 
> Thanks
> 
> --  
> David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
> @dadoonet | @elasticsearchfr | @scrutmydocs
> 
> Le 13 mai 2013 à 23:16, Loïc Bertron [loic.bertron@gmail.com](mailto:loic.bertron@gmail.com) a écrit :
> 
> > Hey guys,
> > 
> > I'm trying to delete some tweets i've been indexing automatically after 1h but even TTL or delete by query is not working.  
> > When i set TTL, nothing happen.  
> > Same result if i try this command :
> > 
> > curl -XDELETE localhost:9200/twitter/\_query -d '{  
> > "query" : {  
> > "filtered": {  
> > "query": {"match\_all": {}},  
> > "filter": {"range": {  
> > "created\_at": {  
> > "lt": "now-1h"  
> > }  
> > }}  
> > }  
> > }  
> > }'
> > 
> > What am i doing wrong ?
> > 
> > Loïc
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 15, 2013, 6:35am UTC](https://discuss.elastic.co/t/delete-by-query-not-working/11943/4 "2013-05-15T06:35:23Z")

</div>

Hey Loic,

the delete by query does not need a 'query' field in the JSON, as the whole  
request body is the query itself, where as a search can consist of more  
root level fields like 'query', 'filter' or 'facets'... So you need to send  
a little bit different data to your delete by query request.

Hope this helps.

--Alex

On Tue, May 14, 2013 at 10:14 PM, Loïc Bertron [loic.bertron@gmail.com](mailto:loic.bertron@gmail.com)wrote:

> Hey David,
> 
> Thanks for your reply.  
> Here is attached an example tweet that i'm inserting with this command :
> 
> curl -XPUT '[http://localhost:9200/twitter/tweet/1?ttl=1h](http://localhost:9200/twitter/tweet/1?ttl=1h)' -d @tweet.json
> 
> When i'm running the following command
> 
> curl -XGET '[http://localhost:9200/twitter/tweet/\_search](http://localhost:9200/twitter/tweet/_search)' -d @query.json
> 
> I get more than 10000 results
> 
> If i try to delete by query with this one :
> 
> curl -XDELETE '[http://localhost:9200/twitter/tweet/\_query](http://localhost:9200/twitter/tweet/_query)' -d @query.json
> 
> Does it helps reproduce the error ?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> Le 2013-05-13 à 18:13, David Pilato [david@pilato.fr](mailto:david@pilato.fr) a écrit :
> 
> Hey Loic!
> 
> Could you share a full curl recreation of your problem?  
> I would like to reproduce it.
> 
> Thanks
> 
> --  
> _David Pilato_ | _Technical Advocate_ | \*[Elasticsearch.com](http://Elasticsearch.com)[http://elasticsearch.com/](http://elasticsearch.com/)  
> \*  
> @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr[https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)  
> | @scrutmydocs [https://twitter.com/scrutmydocs](https://twitter.com/scrutmydocs)
> 
> Le 13 mai 2013 à 23:16, Loïc Bertron [loic.bertron@gmail.com](mailto:loic.bertron@gmail.com) a écrit :
> 
> Hey guys,
> 
> I'm trying to delete some tweets i've been indexing automatically after 1h  
> but even TTL or delete by query is not working.  
> When i set TTL, nothing happen.  
> Same result if i try this command :
> 
> curl -XDELETE localhost:9200/twitter/\_query -d '{  
> "query" : {  
> "filtered": {  
> "query": {"match\_all": {}},  
> "filter": {"range": {  
> "created\_at": {  
> "lt": "now-1h"  
> }  
> }}  
> }  
> }  
> }'
> 
> What am i doing wrong ?
> 
> Loïc
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Loic\_Bertron](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/loic_bertron/32/1794_2.png) [@Loic\_Bertron](https://discuss.elastic.co/u/Loic_Bertron)\
**Post date:** [May 15, 2013, 5:59pm UTC](https://discuss.elastic.co/t/delete-by-query-not-working/11943/5 "2013-05-15T17:59:58Z")

</div>

Hey Alexander,

I tried this already, but no success.  
Actually every time i'm running my delete query, i got this answer :  
{"ok":true,"\_indices":{"twitter":{"\_shards":{"total":3,"successful":0,"failed":3}}}}

with this error in the logs :

[2013-05-15 09:37:05,386][DEBUG][action.deletebyquery] [Damon Dran]  
[twitter][0], node[nce4haLhTQeLaX76zJNPBg], [P], s[STARTED]: Failed to  
execute [delete\_by\_query {[twitter][tweet], query [  
"term" : { "user" : "kimchy" }  
]}]  
org.elasticsearch.index.query.QueryParsingException: [twitter] [\_na] query  
malformed, must start with start\_object  
at  
org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:170)  
at  
org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:268)  
at  
org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:216)  
at  
org.elasticsearch.index.shard.service.InternalIndexShard.prepareDeleteByQuery(InternalIndexShard.java:370)  
at  
org.elasticsearch.action.deletebyquery.TransportShardDeleteByQueryAction.shardOperationOnPrimary(TransportShardDeleteByQueryAction.java:95)  
at  
org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction.performOnPrimary(TransportShardReplicationOperationAction.java:532)  
at  
org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$1.run(TransportShardReplicationOperationAction.java:430)  
at  
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)  
at  
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)  
at java.lang.Thread.run(Thread.java:722)

I'm using in that case the query from the doc : "term" : { "user" :  
"kimchy" }

I'm also getting a lot of errors of this type : [2013-05-15  
09:36:41,056][WARN][transport.netty] [Damon Dran] Message not  
fully read (response) for [977] handler  
org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$2@29a00473,  
error [true], resetting

I have an Elasticsearch cluster with 2 nodes on 2 different locations  
linked by a dedicated 100M link. I have only one index of 3 shards with 1  
replica for each shard.

Do you have an idea ?

Le mercredi 15 mai 2013 02:35:23 UTC-4, Alexander Reelsen a écrit :

> Hey Loic,
> 
> the delete by query does not need a 'query' field in the JSON, as the  
> whole request body is the query itself, where as a search can consist of  
> more root level fields like 'query', 'filter' or 'facets'... So you need to  
> send a little bit different data to your delete by query request.
> 
> Hope this helps.
> 
> --Alex
> 
> On Tue, May 14, 2013 at 10:14 PM, Loïc Bertron \<[loic.b...@gmail.com](mailto:loic.b...@gmail.com)\<javascript:\>
> 
> > wrote:
> 
> > Hey David,
> > 
> > Thanks for your reply.  
> > Here is attached an example tweet that i'm inserting with this command :
> > 
> > curl -XPUT '[http://localhost:9200/twitter/tweet/1?ttl=1h](http://localhost:9200/twitter/tweet/1?ttl=1h)' -d @tweet.json
> > 
> > When i'm running the following command
> > 
> > curl -XGET '[http://localhost:9200/twitter/tweet/\_search](http://localhost:9200/twitter/tweet/_search)' -d @query.json
> > 
> > I get more than 10000 results
> > 
> > If i try to delete by query with this one :
> > 
> > curl -XDELETE '[http://localhost:9200/twitter/tweet/\_query](http://localhost:9200/twitter/tweet/_query)' -d @query.json
> > 
> > Does it helps reproduce the error ?
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > Le 2013-05-13 à 18:13, David Pilato \<[da...@pilato.fr](mailto:da...@pilato.fr) \<javascript:\>\> a  
> > écrit :
> > 
> > Hey Loic!
> > 
> > Could you share a full curl recreation of your problem?  
> > I would like to reproduce it.
> > 
> > Thanks
> > 
> > --  
> > _David Pilato_ | _Technical Advocate_ | \*[Elasticsearch.com](http://Elasticsearch.com)[http://elasticsearch.com/](http://elasticsearch.com/)  
> > \*  
> > @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr[https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)  
> > | @scrutmydocs [https://twitter.com/scrutmydocs](https://twitter.com/scrutmydocs)
> > 
> > Le 13 mai 2013 à 23:16, Loïc Bertron \<[loic.b...@gmail.com](mailto:loic.b...@gmail.com) \<javascript:\>\>  
> > a écrit :
> > 
> > Hey guys,
> > 
> > I'm trying to delete some tweets i've been indexing automatically after  
> > 1h but even TTL or delete by query is not working.  
> > When i set TTL, nothing happen.  
> > Same result if i try this command :
> > 
> > curl -XDELETE localhost:9200/twitter/\_query -d '{  
> > "query" : {  
> > "filtered": {  
> > "query": {"match\_all": {}},  
> > "filter": {"range": {  
> > "created\_at": {  
> > "lt": "now-1h"  
> > }  
> > }}  
> > }  
> > }  
> > }'
> > 
> > What am i doing wrong ?
> > 
> > Loïc
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 15, 2013, 7:57pm UTC](https://discuss.elastic.co/t/delete-by-query-not-working/11943/6 "2013-05-15T19:57:14Z")

</div>

Hey Loic.

I made this GIST to illustrate how to build your query: [Delete By Query usage · GitHub](https://gist.github.com/dadoonet/5586855)

Hope this helps

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr | @scrutmydocs

Le 15 mai 2013 à 19:59, Loïc Bertron [loic.bertron@gmail.com](mailto:loic.bertron@gmail.com) a écrit :

> Hey Alexander,
> 
> I tried this already, but no success.  
> Actually every time i'm running my delete query, i got this answer :  
> {"ok":true,"\_indices":{"twitter":{"\_shards":{"total":3,"successful":0,"failed":3}}}}
> 
> with this error in the logs :
> 
> [2013-05-15 09:37:05,386][DEBUG][action.deletebyquery] [Damon Dran] [twitter][0], node[nce4haLhTQeLaX76zJNPBg], [P], s[STARTED]: Failed to execute [delete\_by\_query {[twitter][tweet], query [  
> "term" : { "user" : "kimchy" }  
> ]}]  
> org.elasticsearch.index.query.QueryParsingException: [twitter] [\_na] query malformed, must start with start\_object  
> at org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:170)  
> at org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:268)  
> at org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:216)  
> at org.elasticsearch.index.shard.service.InternalIndexShard.prepareDeleteByQuery(InternalIndexShard.java:370)  
> at org.elasticsearch.action.deletebyquery.TransportShardDeleteByQueryAction.shardOperationOnPrimary(TransportShardDeleteByQueryAction.java:95)  
> at org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction.performOnPrimary(TransportShardReplicationOperationAction.java:532)  
> at org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$1.run(TransportShardReplicationOperationAction.java:430)  
> at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)  
> at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)  
> at java.lang.Thread.run(Thread.java:722)
> 
> I'm using in that case the query from the doc : "term" : { "user" : "kimchy" }
> 
> I'm also getting a lot of errors of this type : [2013-05-15 09:36:41,056][WARN][transport.netty] [Damon Dran] Message not fully read (response) for [977] handler org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$2@29a00473, error [true], resetting
> 
> I have an Elasticsearch cluster with 2 nodes on 2 different locations linked by a dedicated 100M link. I have only one index of 3 shards with 1 replica for each shard.
> 
> Do you have an idea ?
> 
> Le mercredi 15 mai 2013 02:35:23 UTC-4, Alexander Reelsen a écrit :  
> Hey Loic,
> 
> the delete by query does not need a 'query' field in the JSON, as the whole request body is the query itself, where as a search can consist of more root level fields like 'query', 'filter' or 'facets'... So you need to send a little bit different data to your delete by query request.
> 
> Hope this helps.
> 
> --Alex
> 
> On Tue, May 14, 2013 at 10:14 PM, Loïc Bertron [loic.b...@gmail.com](mailto:loic.b...@gmail.com) wrote:  
> Hey David,
> 
> Thanks for your reply.  
> Here is attached an example tweet that i'm inserting with this command :
> 
> curl -XPUT '[http://localhost:9200/twitter/tweet/1?ttl=1h](http://localhost:9200/twitter/tweet/1?ttl=1h)' -d @tweet.json
> 
> When i'm running the following command
> 
> curl -XGET '[http://localhost:9200/twitter/tweet/\_search](http://localhost:9200/twitter/tweet/_search)' -d @query.json
> 
> I get more than 10000 results
> 
> If i try to delete by query with this one :
> 
> curl -XDELETE '[http://localhost:9200/twitter/tweet/\_query](http://localhost:9200/twitter/tweet/_query)' -d @query.json
> 
> Does it helps reproduce the error ?
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> Le 2013-05-13 à 18:13, David Pilato [da...@pilato.fr](mailto:da...@pilato.fr) a écrit :
> 
> > Hey Loic!
> > 
> > Could you share a full curl recreation of your problem?  
> > I would like to reproduce it.
> > 
> > Thanks
> > 
> > --  
> > David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
> > @dadoonet | @elasticsearchfr | @scrutmydocs
> > 
> > Le 13 mai 2013 à 23:16, Loïc Bertron [loic.b...@gmail.com](mailto:loic.b...@gmail.com) a écrit :
> > 
> > > Hey guys,
> > > 
> > > I'm trying to delete some tweets i've been indexing automatically after 1h but even TTL or delete by query is not working.  
> > > When i set TTL, nothing happen.  
> > > Same result if i try this command :
> > > 
> > > curl -XDELETE localhost:9200/twitter/\_query -d '{  
> > > "query" : {  
> > > "filtered": {  
> > > "query": {"match\_all": {}},  
> > > "filter": {"range": {  
> > > "created\_at": {  
> > > "lt": "now-1h"  
> > > }  
> > > }}  
> > > }  
> > > }  
> > > }'
> > > 
> > > What am i doing wrong ?
> > > 
> > > Loïc
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Loic\_Bertron](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/loic_bertron/32/1794_2.png) [@Loic\_Bertron](https://discuss.elastic.co/u/Loic_Bertron)\
**Post date:** [May 15, 2013, 8:19pm UTC](https://discuss.elastic.co/t/delete-by-query-not-working/11943/7 "2013-05-15T20:19:17Z")

</div>

Thanks David,

When i'm running your gist, it's working fine.  
But when i re-run this on the tweets i'm indexing, i got some errors.

[2013-05-15 16:12:44,144][WARN][transport.netty] [Damon Dran]  
Message not fully read (response) for [127080] handler  
org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$2@4a9b1a42,  
error [true], resetting

May 15 16:12:55 [WARNING] RemoteTransportException[Failed to deserialize  
exception response from stream]; nested:  
TransportSerializationException[Failed to deserialize exception response  
from stream]; nested: StreamCorruptedException[unexpected end of block  
data];

I can delete now using the query but I think the issue will appears again  
in the future.

Do you know anything about theses errors ?

Le mercredi 15 mai 2013 15:58:50 UTC-4, David Pilato a écrit :

> Hey Loic.
> 
> I made this GIST to illustrate how to build your query:  
> [Delete By Query usage · GitHub](https://gist.github.com/dadoonet/5586855)
> 
> Hope this helps
> 
> --  
> _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr[https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)  
> | @scrutmydocs [https://twitter.com/scrutmydocs](https://twitter.com/scrutmydocs)
> 
> Le 15 mai 2013 à 19:59, Loïc Bertron \<[loic.b...@gmail.com](mailto:loic.b...@gmail.com) \<javascript:\>\>  
> a écrit :
> 
> Hey Alexander,
> 
> I tried this already, but no success.  
> Actually every time i'm running my delete query, i got this answer :
> 
> {"ok":true,"\_indices":{"twitter":{"\_shards":{"total":3,"successful":0,"failed":3}}}}
> 
> with this error in the logs :
> 
> [2013-05-15 09:37:05,386][DEBUG][action.deletebyquery] [Damon Dran]  
> [twitter][0], node[nce4haLhTQeLaX76zJNPBg], [P], s[STARTED]: Failed to  
> execute [delete\_by\_query {[twitter][tweet], query [  
> "term" : { "user" : "kimchy" }  
> ]}]  
> org.elasticsearch.index.query.QueryParsingException: [twitter] [\_na] query  
> malformed, must start with start\_object  
> at  
> org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:170)  
> at  
> org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:268)  
> at  
> org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:216)  
> at  
> org.elasticsearch.index.shard.service.InternalIndexShard.prepareDeleteByQuery(InternalIndexShard.java:370)  
> at  
> org.elasticsearch.action.deletebyquery.TransportShardDeleteByQueryAction.shardOperationOnPrimary(TransportShardDeleteByQueryAction.java:95)  
> at  
> org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction.performOnPrimary(TransportShardReplicationOperationAction.java:532)  
> at  
> org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$1.run(TransportShardReplicationOperationAction.java:430)  
> at  
> java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)  
> at  
> java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)  
> at java.lang.Thread.run(Thread.java:722)
> 
> I'm using in that case the query from the doc : "term" : { "user" :  
> "kimchy" }
> 
> I'm also getting a lot of errors of this type : [2013-05-15  
> 09:36:41,056][WARN][transport.netty] [Damon Dran] Message not  
> fully read (response) for [977] handler  
> org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$2@29a00473,  
> error [true], resetting
> 
> I have an Elasticsearch cluster with 2 nodes on 2 different locations  
> linked by a dedicated 100M link. I have only one index of 3 shards with 1  
> replica for each shard.
> 
> Do you have an idea ?
> 
> Le mercredi 15 mai 2013 02:35:23 UTC-4, Alexander Reelsen a écrit :
> 
> > Hey Loic,
> > 
> > the delete by query does not need a 'query' field in the JSON, as the  
> > whole request body is the query itself, where as a search can consist of  
> > more root level fields like 'query', 'filter' or 'facets'... So you need to  
> > send a little bit different data to your delete by query request.
> > 
> > Hope this helps.
> > 
> > --Alex
> > 
> > On Tue, May 14, 2013 at 10:14 PM, Loïc Bertron [loic.b...@gmail.com](mailto:loic.b...@gmail.com)wrote:
> > 
> > > Hey David,
> > > 
> > > Thanks for your reply.  
> > > Here is attached an example tweet that i'm inserting with this command :
> > > 
> > > curl -XPUT '[http://localhost:9200/twitter/tweet/1?ttl=1h](http://localhost:9200/twitter/tweet/1?ttl=1h)' -d @tweet.json
> > > 
> > > When i'm running the following command
> > > 
> > > curl -XGET '[http://localhost:9200/twitter/tweet/\_search](http://localhost:9200/twitter/tweet/_search)' -d @query.json
> > > 
> > > I get more than 10000 results
> > > 
> > > If i try to delete by query with this one :
> > > 
> > > curl -XDELETE '[http://localhost:9200/twitter/tweet/\_query](http://localhost:9200/twitter/tweet/_query)' -d  
> > > @query.json
> > > 
> > > Does it helps reproduce the error ?
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > > 
> > > Le 2013-05-13 à 18:13, David Pilato [da...@pilato.fr](mailto:da...@pilato.fr) a écrit :
> > > 
> > > Hey Loic!
> > > 
> > > Could you share a full curl recreation of your problem?  
> > > I would like to reproduce it.
> > > 
> > > Thanks
> > > 
> > > --  
> > > _David Pilato_ | _Technical Advocate_ | \*[Elasticsearch.com](http://Elasticsearch.com)[http://elasticsearch.com/](http://elasticsearch.com/)  
> > > \*  
> > > @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr[https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)  
> > > | @scrutmydocs [https://twitter.com/scrutmydocs](https://twitter.com/scrutmydocs)
> > > 
> > > Le 13 mai 2013 à 23:16, Loïc Bertron [loic.b...@gmail.com](mailto:loic.b...@gmail.com) a écrit :
> > > 
> > > Hey guys,
> > > 
> > > I'm trying to delete some tweets i've been indexing automatically after  
> > > 1h but even TTL or delete by query is not working.  
> > > When i set TTL, nothing happen.  
> > > Same result if i try this command :
> > > 
> > > curl -XDELETE localhost:9200/twitter/\_query -d '{  
> > > "query" : {  
> > > "filtered": {  
> > > "query": {"match\_all": {}},  
> > > "filter": {"range": {  
> > > "created\_at": {  
> > > "lt": "now-1h"  
> > > }  
> > > }}  
> > > }  
> > > }  
> > > }'
> > > 
> > > What am i doing wrong ?
> > > 
> > > Loïc
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 15, 2013, 8:40pm UTC](https://discuss.elastic.co/t/delete-by-query-not-working/11943/8 "2013-05-15T20:40:05Z")

</div>

Sounds like you are mixing versions or something like that???  
What is your architecture here?

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 15 mai 2013 à 22:19, Loïc Bertron [loic.bertron@gmail.com](mailto:loic.bertron@gmail.com) a écrit :

Thanks David,

When i'm running your gist, it's working fine.  
But when i re-run this on the tweets i'm indexing, i got some errors.

[2013-05-15 16:12:44,144][WARN][transport.netty] [Damon Dran] Message not fully read (response) for [127080] handler org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$2@4a9b1a42, error [true], resetting

May 15 16:12:55 [WARNING] RemoteTransportException[Failed to deserialize exception response from stream]; nested: TransportSerializationException[Failed to deserialize exception response from stream]; nested: StreamCorruptedException[unexpected end of block data];

I can delete now using the query but I think the issue will appears again in the future.

Do you know anything about theses errors ?

Le mercredi 15 mai 2013 15:58:50 UTC-4, David Pilato a écrit :

> Hey Loic.
> 
> I made this GIST to illustrate how to build your query: [Delete By Query usage · GitHub](https://gist.github.com/dadoonet/5586855)
> 
> Hope this helps
> 
> --  
> David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
> @dadoonet | @elasticsearchfr | @scrutmydocs
> 
> Le 15 mai 2013 à 19:59, Loïc Bertron [loic.b...@gmail.com](mailto:loic.b...@gmail.com) a écrit :
> 
> > Hey Alexander,
> > 
> > I tried this already, but no success.  
> > Actually every time i'm running my delete query, i got this answer :  
> > {"ok":true,"\_indices":{"twitter":{"\_shards":{"total":3,"successful":0,"failed":3}}}}
> > 
> > with this error in the logs :
> > 
> > [2013-05-15 09:37:05,386][DEBUG][action.deletebyquery] [Damon Dran] [twitter][0], node[nce4haLhTQeLaX76zJNPBg], [P], s[STARTED]: Failed to execute [delete\_by\_query {[twitter][tweet], query [  
> > "term" : { "user" : "kimchy" }  
> > ]}]  
> > org.elasticsearch.index.query.QueryParsingException: [twitter] [\_na] query malformed, must start with start\_object  
> > at org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:170)  
> > at org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:268)  
> > at org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:216)  
> > at org.elasticsearch.index.shard.service.InternalIndexShard.prepareDeleteByQuery(InternalIndexShard.java:370)  
> > at org.elasticsearch.action.deletebyquery.TransportShardDeleteByQueryAction.shardOperationOnPrimary(TransportShardDeleteByQueryAction.java:95)  
> > at org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction.performOnPrimary(TransportShardReplicationOperationAction.java:532)  
> > at org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$1.run(TransportShardReplicationOperationAction.java:430)  
> > at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)  
> > at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)  
> > at java.lang.Thread.run(Thread.java:722)
> > 
> > I'm using in that case the query from the doc : "term" : { "user" : "kimchy" }
> > 
> > I'm also getting a lot of errors of this type : [2013-05-15 09:36:41,056][WARN][transport.netty] [Damon Dran] Message not fully read (response) for [977] handler org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$2@29a00473, error [true], resetting
> > 
> > I have an Elasticsearch cluster with 2 nodes on 2 different locations linked by a dedicated 100M link. I have only one index of 3 shards with 1 replica for each shard.
> > 
> > Do you have an idea ?
> > 
> > Le mercredi 15 mai 2013 02:35:23 UTC-4, Alexander Reelsen a écrit :
> > 
> > > Hey Loic,
> > > 
> > > the delete by query does not need a 'query' field in the JSON, as the whole request body is the query itself, where as a search can consist of more root level fields like 'query', 'filter' or 'facets'... So you need to send a little bit different data to your delete by query request.
> > > 
> > > Hope this helps.
> > > 
> > > --Alex
> > > 
> > > On Tue, May 14, 2013 at 10:14 PM, Loïc Bertron [loic.b...@gmail.com](mailto:loic.b...@gmail.com) wrote:
> > > 
> > > > Hey David,
> > > > 
> > > > Thanks for your reply.  
> > > > Here is attached an example tweet that i'm inserting with this command :
> > > > 
> > > > curl -XPUT '[http://localhost:9200/twitter/tweet/1?ttl=1h](http://localhost:9200/twitter/tweet/1?ttl=1h)' -d @tweet.json
> > > > 
> > > > When i'm running the following command
> > > > 
> > > > curl -XGET '[http://localhost:9200/twitter/tweet/\_search](http://localhost:9200/twitter/tweet/_search)' -d @query.json
> > > > 
> > > > I get more than 10000 results
> > > > 
> > > > If i try to delete by query with this one :
> > > > 
> > > > curl -XDELETE '[http://localhost:9200/twitter/tweet/\_query](http://localhost:9200/twitter/tweet/_query)' -d @query.json
> > > > 
> > > > Does it helps reproduce the error ?
> > > > 
> > > > --  
> > > > You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> > > > To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > > > 
> > > > Le 2013-05-13 à 18:13, David Pilato [da...@pilato.fr](mailto:da...@pilato.fr) a écrit :
> > > > 
> > > > > Hey Loic!
> > > > > 
> > > > > Could you share a full curl recreation of your problem?  
> > > > > I would like to reproduce it.
> > > > > 
> > > > > Thanks
> > > > > 
> > > > > --  
> > > > > David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
> > > > > @dadoonet | @elasticsearchfr | @scrutmydocs
> > > > > 
> > > > > Le 13 mai 2013 à 23:16, Loïc Bertron [loic.b...@gmail.com](mailto:loic.b...@gmail.com) a écrit :
> > > > > 
> > > > > > Hey guys,
> > > > > > 
> > > > > > I'm trying to delete some tweets i've been indexing automatically after 1h but even TTL or delete by query is not working.  
> > > > > > When i set TTL, nothing happen.  
> > > > > > Same result if i try this command :
> > > > > > 
> > > > > > curl -XDELETE localhost:9200/twitter/\_query -d '{  
> > > > > > "query" : {  
> > > > > > "filtered": {  
> > > > > > "query": {"match\_all": {}},  
> > > > > > "filter": {"range": {  
> > > > > > "created\_at": {  
> > > > > > "lt": "now-1h"  
> > > > > > }  
> > > > > > }}  
> > > > > > }  
> > > > > > }  
> > > > > > }'
> > > > > > 
> > > > > > What am i doing wrong ?
> > > > > > 
> > > > > > Loïc
> > > > > > 
> > > > > > --  
> > > > > > You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> > > > > > To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > > > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 16, 2013, 6:54am UTC](https://discuss.elastic.co/t/delete-by-query-not-working/11943/9 "2013-05-16T06:54:22Z")

</div>

Hey

minor difference in the docs, note the wrapping curly braces around the  
"term" field. This also the reason why the exception message was, that  
there is a missing START\_OBJECT, which basically translates to a { in JSON  
in order to build an object.

curl -XDELETE '[http://localhost:9200/twitter/tweet/\_query](http://localhost:9200/twitter/tweet/_query)' -d '{  
"term" : { "user" : "kimchy" }  
}  
'

Not sure where your other exceptions are coming from. Do you maybe use  
different JVMs on your nodes? If so, try using the exact same JVM versions  
on all nodes.

--Alex

On Wed, May 15, 2013 at 7:59 PM, Loïc Bertron [loic.bertron@gmail.com](mailto:loic.bertron@gmail.com)wrote:

> Hey Alexander,
> 
> I tried this already, but no success.  
> Actually every time i'm running my delete query, i got this answer :
> 
> {"ok":true,"\_indices":{"twitter":{"\_shards":{"total":3,"successful":0,"failed":3}}}}
> 
> with this error in the logs :
> 
> [2013-05-15 09:37:05,386][DEBUG][action.deletebyquery] [Damon Dran]  
> [twitter][0], node[nce4haLhTQeLaX76zJNPBg], [P], s[STARTED]: Failed to  
> execute [delete\_by\_query {[twitter][tweet], query [  
> "term" : { "user" : "kimchy" }  
> ]}]  
> org.elasticsearch.index.query.QueryParsingException: [twitter] [\_na] query  
> malformed, must start with start\_object  
> at  
> org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:170)  
> at  
> org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:268)  
> at  
> org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:216)  
> at  
> org.elasticsearch.index.shard.service.InternalIndexShard.prepareDeleteByQuery(InternalIndexShard.java:370)  
> at  
> org.elasticsearch.action.deletebyquery.TransportShardDeleteByQueryAction.shardOperationOnPrimary(TransportShardDeleteByQueryAction.java:95)  
> at  
> org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction.performOnPrimary(TransportShardReplicationOperationAction.java:532)  
> at  
> org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$1.run(TransportShardReplicationOperationAction.java:430)  
> at  
> java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)  
> at  
> java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)  
> at java.lang.Thread.run(Thread.java:722)
> 
> I'm using in that case the query from the doc : "term" : { "user" :  
> "kimchy" }
> 
> I'm also getting a lot of errors of this type : [2013-05-15  
> 09:36:41,056][WARN][transport.netty] [Damon Dran] Message not  
> fully read (response) for [977] handler  
> org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$2@29a00473,  
> error [true], resetting
> 
> I have an Elasticsearch cluster with 2 nodes on 2 different locations  
> linked by a dedicated 100M link. I have only one index of 3 shards with 1  
> replica for each shard.
> 
> Do you have an idea ?
> 
> Le mercredi 15 mai 2013 02:35:23 UTC-4, Alexander Reelsen a écrit :
> 
> > Hey Loic,
> > 
> > the delete by query does not need a 'query' field in the JSON, as the  
> > whole request body is the query itself, where as a search can consist of  
> > more root level fields like 'query', 'filter' or 'facets'... So you need to  
> > send a little bit different data to your delete by query request.
> > 
> > Hope this helps.
> > 
> > --Alex
> > 
> > On Tue, May 14, 2013 at 10:14 PM, Loïc Bertron [loic.b...@gmail.com](mailto:loic.b...@gmail.com)wrote:
> > 
> > > Hey David,
> > > 
> > > Thanks for your reply.  
> > > Here is attached an example tweet that i'm inserting with this command :
> > > 
> > > curl -XPUT '[http://localhost:9200/\*\*twitter/tweet/1?ttl=1h'\<http://localhost:9200/twitter/tweet/1?ttl=1h'](http://localhost:9200/**twitter/tweet/1?ttl=1h'%3Chttp://localhost:9200/twitter/tweet/1?ttl=1h')\>-d @tweet.json
> > > 
> > > When i'm running the following command
> > > 
> > > curl -XGET '[http://localhost:9200/\*\*twitter/tweet/\_search'\<http://localhost:9200/twitter/tweet/\_search'](http://localhost:9200/**twitter/tweet/_search'%3Chttp://localhost:9200/twitter/tweet/_search')\>-d @query.json
> > > 
> > > I get more than 10000 results
> > > 
> > > If i try to delete by query with this one :
> > > 
> > > curl -XDELETE '[http://localhost:9200/\*\*twitter/tweet/\_query'\<http://localhost:9200/twitter/tweet/\_query'](http://localhost:9200/**twitter/tweet/_query'%3Chttp://localhost:9200/twitter/tweet/_query')\>-d @query.json
> > > 
> > > Does it helps reproduce the error ?
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to elasticsearc...@\*\*[googlegroups.com](http://googlegroups.com).
> > > 
> > > For more options, visit [https://groups.google.com/\*\*groups/opt\_out](https://groups.google.com/**groups/opt_out)[https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out)  
> > > .
> > > 
> > > Le 2013-05-13 à 18:13, David Pilato [da...@pilato.fr](mailto:da...@pilato.fr) a écrit :
> > > 
> > > Hey Loic!
> > > 
> > > Could you share a full curl recreation of your problem?  
> > > I would like to reproduce it.
> > > 
> > > Thanks
> > > 
> > > --  
> > > _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)[http://elasticsearch.com/](http://elasticsearch.com/)  
> > > \*  
> > > @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr[https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)  
> > > |_\* @scrutmydocs [https://twitter.com/scrutmydocs](https://twitter.com/scrutmydocs)
> > > 
> > > Le 13 mai 2013 à 23:16, Loïc Bertron [loic.b...@gmail.com](mailto:loic.b...@gmail.com) a écrit :
> > > 
> > > Hey guys,
> > > 
> > > I'm trying to delete some tweets i've been indexing automatically after  
> > > 1h but even TTL or delete by query is not working.  
> > > When i set TTL, nothing happen.  
> > > Same result if i try this command :
> > > 
> > > curl -XDELETE localhost:9200/twitter/\_query -d '{  
> > > "query" : {  
> > > "filtered": {  
> > > "query": {"match\_all": {}},  
> > > "filter": {"range": {  
> > > "created\_at": {  
> > > "lt": "now-1h"  
> > > }  
> > > }}  
> > > }  
> > > }  
> > > }'
> > > 
> > > What am i doing wrong ?
> > > 
> > > Loïc
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to elasticsearc...@\*\*[googlegroups.com](http://googlegroups.com).
> > > 
> > > For more options, visit [https://groups.google.com/\*\*groups/opt\_out](https://groups.google.com/**groups/opt_out)[https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out)  
> > > .
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:36am UTC](https://discuss.elastic.co/t/delete-by-query-not-working/11943/10 "2017-07-06T02:36:23Z")

</div>


