# Delete by query?

**URL:** <https://discuss.elastic.co/t/delete-by-query/289472>\
**Category:** Elasticsearch\
**Created:** [November 17, 2021, 3:38pm UTC](https://discuss.elastic.co/t/delete-by-query/289472 "2021-11-17T15:38:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saliinger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saliinger/32/77470_2.png) [@Saliinger](https://discuss.elastic.co/u/Saliinger)\
**Post date:** [November 17, 2021, 3:38pm UTC](https://discuss.elastic.co/t/delete-by-query/289472/1 "2021-11-17T15:38:29Z")

</div>

Hello. 🙂

I'm using `delete_by_query` to remove old data from all index.  
Looks like that:

```auto
POST */_delete_by_query
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "lt": "now-180d"
            }
          }
        }
      ]
    }
  }
}

```

It works perfectly, and the answer I get is:

```auto
{
  "took" : 13,
  "timed_out" : false,
  "total" : 0,
  "deleted" : 0,
  "batches" : 0,
  "version_conflicts" : 0,
  "noops" : 0,
  "retries" : {
    "bulk" : 0,
    "search" : 0
  },
  "throttled_millis" : 0,
  "requests_per_second" : -1.0,
  "throttled_until_millis" : 0,
  "failures" : []
}

```

Now, what I need is filter this data deleting all index where a field have a special name.  
For example: Delete last 180 days from all index than their fields `agent.hostname` are `box_1`.

I'm trying this:

```auto
POST */_delete_by_query
{
  "query": {
    "match":{
      "agent.hostname": "box_1"
    },
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "lt": "now-180d"
            }
          }
        }
      ]
    }
  }
}

```

I need to match the field `agent.hostname` in my `delete_by_query`

Any suggestions?

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [November 17, 2021, 3:47pm UTC](https://discuss.elastic.co/t/delete-by-query/289472/2 "2021-11-17T15:47:05Z")

</div>

```auto
POST */_delete_by_query
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "lt": "now-180d"
            }
          }
        },
        {
          "term": {
            "agent.hostname": "box_1"
          }
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Saliinger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saliinger/32/77470_2.png) [@Saliinger](https://discuss.elastic.co/u/Saliinger)\
**Post date:** [November 17, 2021, 4:27pm UTC](https://discuss.elastic.co/t/delete-by-query/289472/3 "2021-11-17T16:27:25Z")

</div>

Thank you so much! 😃

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2021, 4:27pm UTC](https://discuss.elastic.co/t/delete-by-query/289472/4 "2021-12-15T16:27:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
