# Delete by time range with ES 1.1

**URL:** <https://discuss.elastic.co/t/delete-by-time-range-with-es-1-1/18663>\
**Category:** Elasticsearch\
**Created:** [July 14, 2014, 9:41pm UTC](https://discuss.elastic.co/t/delete-by-time-range-with-es-1-1/18663 "2014-07-14T21:41:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bastien\_Chong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastien_chong/32/1393_2.png) [@Bastien\_Chong](https://discuss.elastic.co/u/Bastien_Chong)\
**Post date:** [July 14, 2014, 9:41pm UTC](https://discuss.elastic.co/t/delete-by-time-range-with-es-1-1/18663/1 "2014-07-14T21:41:21Z")

</div>

I'm trying to delete document from an index based on the timestamp.  
I'm using ES v1.1, so I have to use the query wrapper.

This return the wanted result :

curl -\*XGET \*'[http://localhost:9200/test/\_](http://localhost:9200/test/_)_search_?pretty=1' -d  
'{"query":{"range":{"@timestamp":{"from":"2014-07-10T00:00:00","to":"2014-07-13T21:00:00"}}}}'

but this doesn't always work, command is hanging :

curl -_XDELETE_ '[http://localhost:9200/test/\_](http://localhost:9200/test/_)_query_?pretty=1' -d  
'{"query":{"range":{"@timestamp":{"from":"2014-07-10T00:00:00","to":"2014-07-13T21:00:00"}}}}'

The cluster's health is good, I worked a few hours ago, and now it's not. I  
tried to restart elasticsearch without luck.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/be990246-efb3-4ed2-bec6-101fb03bb9ce%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/be990246-efb3-4ed2-bec6-101fb03bb9ce%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Bastien\_Chong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastien_chong/32/1393_2.png) [@Bastien\_Chong](https://discuss.elastic.co/u/Bastien_Chong)\
**Post date:** [July 14, 2014, 9:48pm UTC](https://discuss.elastic.co/t/delete-by-time-range-with-es-1-1/18663/2 "2014-07-14T21:48:26Z")

</div>

Not sure what's happening, I restarted both elasticsearch instance for my 2  
nodes-cluster, and now it's working. But I'm sure the cluster was in good  
state, I could PUT and GET.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/97485ca1-98ba-45bf-bc8c-d956a01e2241%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/97485ca1-98ba-45bf-bc8c-d956a01e2241%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Patrick\_Proniewski](https://avatars.discourse-cdn.com/v4/letter/p/96bed5/32.png) [@Patrick\_Proniewski](https://discuss.elastic.co/u/Patrick_Proniewski)\
**Post date:** [July 15, 2014, 5:12am UTC](https://discuss.elastic.co/t/delete-by-time-range-with-es-1-1/18663/3 "2014-07-15T05:12:11Z")

</div>

Maybe you just discovered by yourself what Aaron described in a previous message (Message-Id: [1405173409302.ce95d5ef@Nodemailer](mailto:1405173409302.ce95d5ef@Nodemailer) on logstash mailing list):

> [deleting a type of documents from an index] is a horrible idea in the same way that running DELETE FROM TABLE WHERE TYPE='cisco' AND DATE\<... in a SQL database is a bad idea. You get thousands, if not millions of individual deletes to manage, and they are horrible in terms of disk I/O performance to the system and the cluster. Worse still, in elasticsearch, the deletes aren't immediate. They are only flagged for deletion. The actual delete takes place during the next segment merge, which is up to 30 minutes later. It could render you with horrible I/O during the seek as well as the subsequent delete.

On 14 juil. 2014, at 23:48, Bastien Chong wrote:

> Not sure what's happening, I restarted both elasticsearch instance for my 2 nodes-cluster, and now it's working. But I'm sure the cluster was in good state, I could PUT and GET.
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/97485ca1-98ba-45bf-bc8c-d956a01e2241%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/97485ca1-98ba-45bf-bc8c-d956a01e2241%40googlegroups.com).  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/D78CC74D-6B54-412A-AFF0-2E54E593362C%40patpro.net](https://groups.google.com/d/msgid/elasticsearch/D78CC74D-6B54-412A-AFF0-2E54E593362C%40patpro.net).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:15am UTC](https://discuss.elastic.co/t/delete-by-time-range-with-es-1-1/18663/4 "2017-07-06T01:15:47Z")

</div>


