# Delete data by beat.name

**URL:** <https://discuss.elastic.co/t/delete-data-by-beat-name/151860>\
**Category:** Elasticsearch\
**Created:** [October 10, 2018, 1:59pm UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860 "2018-10-10T13:59:28Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![faulander](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faulander/32/36344_2.png) [@faulander](https://discuss.elastic.co/u/faulander)\
**Post date:** [October 10, 2018, 1:59pm UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/1 "2018-10-10T13:59:28Z")

</div>

Hi Guys,  
Can you point me in the right direction when i want to delete data from a given hostname or beatname?

i tried:

```
POST metricbeat-6.4.0-2018.10.10/_delete_by_query
{
  "query": { 
    "match": {
      "term" : { "beat.name" : "Test"
      }
    }
  }
}

```

but it doesn't work. So simple question: How do i delete data by beat.name?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 10, 2018, 2:11pm UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/2 "2018-10-10T14:11:44Z")

</div>

What gives the following?

```auto
GET metricbeat-6.4.0-2018.10.10/_search
{
  "query": { 
    "match": {
      "term" : { "beat.name" : "Test"
      }
    }
  }
}

```

May be try with `"beat.name" : "test"` BTW. I guess it depends on the mapping for that field as you are using a Term query.

---

<div class="post-metadata">

**Author:** ![faulander](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faulander/32/36344_2.png) [@faulander](https://discuss.elastic.co/u/faulander)\
**Post date:** [October 10, 2018, 2:16pm UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/3 "2018-10-10T14:16:30Z")

</div>

> [@dadoonet](#):
>
> GET metricbeat-6.4.0-2018.10.10/\_search { "query": { "match": { "term" : { "beat.name" : "Test" } } } }

Thank you David, GET doesn't find the data either.

What would be the preferred way to delete data shipped by MetricBeat? The Shippers all have unique names and (of course) hostnames.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 10, 2018, 2:20pm UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/4 "2018-10-10T14:20:05Z")

</div>

Depends on your mapping and your actual data. I guess `Test` was an example.

---

<div class="post-metadata">

**Author:** ![faulander](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faulander/32/36344_2.png) [@faulander](https://discuss.elastic.co/u/faulander)\
**Post date:** [October 10, 2018, 2:23pm UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/5 "2018-10-10T14:23:02Z")

</div>

yes, here is the exact data i am talking about:

![2018-10-10%2016_22_21-Window](https://us1.discourse-cdn.com/elastic/original/3X/1/0/10d6555600eab5e2fceab15b292edbd8c2ff5643.png)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 10, 2018, 2:24pm UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/6 "2018-10-10T14:24:40Z")

</div>

It does not tell me anything about the mapping.  
But here is a guess then. Try this:

```auto
GET metricbeat-6.4.0-2018.10.10/_search
{
  "query": { 
    "match": { "beat.name" : "Test" }
  }
}

```

---

<div class="post-metadata">

**Author:** ![faulander](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faulander/32/36344_2.png) [@faulander](https://discuss.elastic.co/u/faulander)\
**Post date:** [October 10, 2018, 2:55pm UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/7 "2018-10-10T14:55:31Z")

</div>

> [@dadoonet](#):
>
> GET metricbeat-6.4.0-2018.10.10/\_search { "query": { "match": { "beat.name" : "Test" } } }

That works. Deleting still doesn't work though:  
POST metricbeat-6.4.0-2018.10.10/\_delete\_by\_query  
{  
"query": {  
"match": { "beat.name" : "Test - Daimler - SAML" }  
}  
}

Output:  
{  
"took": 1,  
"timed\_out": false,  
"total": 0,  
"deleted": 0,  
"batches": 0,  
"version\_conflicts": 0,  
"noops": 0,  
"retries": {  
"bulk": 0,  
"search": 0  
},  
"throttled\_millis": 0,  
"requests\_per\_second": -1,  
"throttled\_until\_millis": 0,  
"failures":   
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 10, 2018, 3:07pm UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/8 "2018-10-10T15:07:38Z")

</div>

In one case you searched for Test but then you deleted something else?

---

<div class="post-metadata">

**Author:** ![faulander](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faulander/32/36344_2.png) [@faulander](https://discuss.elastic.co/u/faulander)\
**Post date:** [October 10, 2018, 3:32pm UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/9 "2018-10-10T15:32:51Z")

</div>

Test was just an Example. Of course i tried the GET also with the „correct“ term - the same i tried with the Delete Statement 😉

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 10, 2018, 3:57pm UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/10 "2018-10-10T15:57:56Z")

</div>

If search gives back results, delete by query should work as well.

If not, please share the full commands you're passing to the system and both results.  
And the mapping for your index.

---

<div class="post-metadata">

**Author:** ![faulander](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faulander/32/36344_2.png) [@faulander](https://discuss.elastic.co/u/faulander)\
**Post date:** [October 11, 2018, 8:30am UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/11 "2018-10-11T08:30:50Z")

</div>

**Search:**  
GET metricbeat-6.4.0-2018.10.10/\_search  
{  
"query": {  
"match": { "beat.name" : "Test - Daimler - SAML" }  
}  
}  
**Response:**  
{  
"took": 1,  
"timed\_out": false,  
"\_shards": {  
"total": 1,  
"successful": 1,  
"skipped": 0,  
"failed": 0  
},  
"hits": {  
"total": 0,  
"max\_score": null,  
"hits": []  
}  
}  
**Delete:**  
POST metricbeat-6.4.0-2018.10.10/\_delete\_by\_query  
{  
"query": {  
"match": { "beat.name" : "Test - Daimler - SAML" }  
}  
}  
**Response:**  
{  
"took": 0,  
"timed\_out": false,  
"total": 0,  
"deleted": 0,  
"batches": 0,  
"version\_conflicts": 0,  
"noops": 0,  
"retries": {  
"bulk": 0,  
"search": 0  
},  
"throttled\_millis": 0,  
"requests\_per\_second": -1,  
"throttled\_until\_millis": 0,  
"failures": []  
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 11, 2018, 9:42am UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/12 "2018-10-11T09:42:20Z")

</div>

so the search gave back 0 result.  
Why would delete by query give another result?

---

<div class="post-metadata">

**Author:** ![faulander](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faulander/32/36344_2.png) [@faulander](https://discuss.elastic.co/u/faulander)\
**Post date:** [October 11, 2018, 12:03pm UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/13 "2018-10-11T12:03:49Z")

</div>

David, i am an idiot. Sorry, topic can be closed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2018, 12:03pm UTC](https://discuss.elastic.co/t/delete-data-by-beat-name/151860/14 "2018-11-08T12:03:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
