# Delete host specific index data

**URL:** <https://discuss.elastic.co/t/delete-host-specific-index-data/15375>\
**Category:** Elasticsearch\
**Created:** [January 23, 2014, 8:14am UTC](https://discuss.elastic.co/t/delete-host-specific-index-data/15375 "2014-01-23T08:14:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Prasad\_Lele](https://avatars.discourse-cdn.com/v4/letter/p/c67d28/32.png) [@Prasad\_Lele](https://discuss.elastic.co/u/Prasad_Lele)\
**Post date:** [January 23, 2014, 8:14am UTC](https://discuss.elastic.co/t/delete-host-specific-index-data/15375/1 "2014-01-23T08:14:54Z")

</div>

Hi,

We have setup elasticsearch + logstash. The log stash collects data from  
various firewalls/Linux servers etc. I do not need firewall's info logs  
older than 7 days, but still need logs above that (critical, warning etc).  
Is there any way that I can delete specific in logs from the index or say  
logs of specific host(firewall/Server) from the indexes

Regards  
Prasad Lele

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4e9f82b7-7abc-4d0e-a859-c0fe95097e1b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4e9f82b7-7abc-4d0e-a859-c0fe95097e1b%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Johan\_Rask](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johan_rask/32/1132_2.png) [@Johan\_Rask](https://discuss.elastic.co/u/Johan_Rask)\
**Post date:** [January 23, 2014, 2:26pm UTC](https://discuss.elastic.co/t/delete-host-specific-index-data/15375/2 "2014-01-23T14:26:12Z")

</div>

Take a look att this page for more info.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Basically it says that you should manage your logs so you can delete  
complete indices and deleting  
lots of documents from an index is not recommendend.

If you still want to try =\>

: You can delete by query.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

However, read the warning saying not to delete large bulks"

: Set time-to-live

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Regards /johan

Den torsdagen den 23:e januari 2014 kl. 09:14:54 UTC+1 skrev Prasad Lele:

> Hi,
> 
> We have setup elasticsearch + logstash. The log stash collects data from  
> various firewalls/Linux servers etc. I do not need firewall's info logs  
> older than 7 days, but still need logs above that (critical, warning etc).  
> Is there any way that I can delete specific in logs from the index or say  
> logs of specific host(firewall/Server) from the indexes
> 
> Regards  
> Prasad Lele

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/8c778364-7ddc-41cf-b3cb-d277c74fb15c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/8c778364-7ddc-41cf-b3cb-d277c74fb15c%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:55am UTC](https://discuss.elastic.co/t/delete-host-specific-index-data/15375/3 "2017-07-06T01:55:09Z")

</div>


