# Delete documents in index alias

**URL:** <https://discuss.elastic.co/t/delete-documents-in-index-alias/84941>\
**Category:** Elasticsearch\
**Created:** [May 8, 2017, 2:01pm UTC](https://discuss.elastic.co/t/delete-documents-in-index-alias/84941 "2017-05-08T14:01:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mvleandro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mvleandro/32/14268_2.png) [@mvleandro](https://discuss.elastic.co/u/mvleandro)\
**Post date:** [May 8, 2017, 2:01pm UTC](https://discuss.elastic.co/t/delete-documents-in-index-alias/84941/1 "2017-05-08T14:01:48Z")

</div>

Hello everyone!

Supose that i create one index per month but i create one alias for this index per day filtering by a timestamp field referencing the current day.

Can i performe a DELETE operation on the index alias to delete just the documents belongs that day/index alias?

It works?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 8, 2017, 4:09pm UTC](https://discuss.elastic.co/t/delete-documents-in-index-alias/84941/2 "2017-05-08T16:09:16Z")

</div>

Short answer, no. If an alias is pointing at an index, a delete operation will hit the entire index.

You have two options, as I see it:

1. Use the delete\_by\_query plugin
2. Actually use daily indices with the rollover API or some such and delete the rolled-over indices with [Curator](https://www.elastic.co/guide/en/elasticsearch/client/curator/5.0/index.html), or some other script.

---

<div class="post-metadata">

**Author:** ![mvleandro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mvleandro/32/14268_2.png) [@mvleandro](https://discuss.elastic.co/u/mvleandro)\
**Post date:** [May 8, 2017, 5:30pm UTC](https://discuss.elastic.co/t/delete-documents-in-index-alias/84941/3 "2017-05-08T17:30:51Z")

</div>

Thank you for your answer @theuntergeek!

Actually i am currently using daily indexes but because i am creating a index per application per day (i am indexing application logs) my number of shards is too high and it are costing too memory of my cluster.

I am wondering how to reduce the number of shards without change my busines rules and i think i could use index aliases with filter, but not.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 8, 2017, 5:42pm UTC](https://discuss.elastic.co/t/delete-documents-in-index-alias/84941/4 "2017-05-08T17:42:34Z")

</div>

That's an easier answer (or two):

1. Create an [alias pointing to a rollover-friendly index](https://www.elastic.co/guide/en/elasticsearch/reference/5.4/indices-rollover-index.html).
2. Use [Curator to rollover your indices](https://www.elastic.co/guide/en/elasticsearch/client/curator/5.0/rollover.html) when they hit a certain document count.

This will enable you to reduce shard count by allowing indices to build in size, but only until they are a set number of documents.

Option 2 (which can conceivably be combined with option 1):

Use [Curator's reindex action](https://www.elastic.co/guide/en/elasticsearch/client/curator/5.0/reindex.html) to periodically reindex multiple older _daily_ indices to a single weekly (or monthly) index with a smaller shard count.

Option 3 (which is coming to Curator in a future release):

Use the [Shrink API](https://www.elastic.co/guide/en/elasticsearch/reference/5.4/indices-shrink-index.html) to reduce shards.

---

<div class="post-metadata">

**Author:** ![mvleandro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mvleandro/32/14268_2.png) [@mvleandro](https://discuss.elastic.co/u/mvleandro)\
**Post date:** [May 9, 2017, 12:12am UTC](https://discuss.elastic.co/t/delete-documents-in-index-alias/84941/5 "2017-05-09T00:12:02Z")

</div>

Thank you!

I'll try these options.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2017, 12:20am UTC](https://discuss.elastic.co/t/delete-documents-in-index-alias/84941/6 "2017-06-06T00:20:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
