# Delete Indices older than 30 days

**URL:** <https://discuss.elastic.co/t/delete-indices-older-than-30-days/96630>\
**Category:** Elasticsearch\
**Created:** [August 10, 2017, 2:31pm UTC](https://discuss.elastic.co/t/delete-indices-older-than-30-days/96630 "2017-08-10T14:31:03Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![waterwalker23](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/waterwalker23/32/19707_2.png) [@waterwalker23](https://discuss.elastic.co/u/waterwalker23)\
**Post date:** [August 10, 2017, 2:31pm UTC](https://discuss.elastic.co/t/delete-indices-older-than-30-days/96630/1 "2017-08-10T14:31:04Z")

</div>

All,

I'm trying to delete old indices, but I can't get it working. I have curator version 5.1 installed. I found info stating to use the following command `curator --host localhost delete indices --older-than 30 --time-unit days --timestring %Y-%m-%dt%H` but that errors with no such --host option. I tried using the host IP & the hostname as well. I know deleting indices can be set up with a cron job, but right now, I just want to be able to delete manually.

I've seen info about a YML file for curator, but for the life of me I can't find it. If I need to create it, where does it need to be located? I'm just all kinds of confused about curator... I'm familair with Linux, but don't get to use it as much as I'd like, so be nice... 🙂

---

<div class="post-metadata">

**Author:** ![shanec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanec/32/4004_2.png) [@shanec](https://discuss.elastic.co/u/shanec)\
**Post date:** [August 10, 2017, 6:44pm UTC](https://discuss.elastic.co/t/delete-indices-older-than-30-days/96630/2 "2017-08-10T18:44:27Z")

</div>

There are 2 operating modes for Curator. The one you've got is for the [singleton CLI](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/singleton-cli.html), which means you need to replace `curator` with `curator_cli`. The other operating mode is via a yml config. That generally offers a much richer set of options and workflows. For that, you use the `curator` CLI and you can find the format and you can find the format of the configuration as well as detailed actions, options and filters [here](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/configuration.html). There are also some [examples](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/examples.html) in the docs to get you started.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 11, 2017, 3:23pm UTC](https://discuss.elastic.co/t/delete-indices-older-than-30-days/96630/3 "2017-08-11T15:23:39Z")

</div>

> [@waterwalker23](#):
>
> I found info stating to use the following command `curator --host localhost delete indices --older-than 30 --time-unit days --timestring %Y-%m-%dt%H`

Unfortunately, that info is for Curator v3. Curator is currently on version 5. @shanec has given you links to the current documentation, which is for Elasticsearch v5.

In the event that you are using Elasticsearch 2.x, Curator v4 is still downloadable. The documentation for Curator v4 will be available via dropdown in the [official documentation](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html).

---

<div class="post-metadata">

**Author:** ![waterwalker23](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/waterwalker23/32/19707_2.png) [@waterwalker23](https://discuss.elastic.co/u/waterwalker23)\
**Post date:** [August 11, 2017, 4:53pm UTC](https://discuss.elastic.co/t/delete-indices-older-than-30-days/96630/4 "2017-08-11T16:53:05Z")

</div>

Thanks for your response! I'm just now getting back to this... I've tried the following `curator_cli delete_indices --filter_list --unit_count 30 --unit days --timestring %Y.%m.%d` and I get an error about --unit not being an option, yet that's what I see in the documentation. Am I not supposed to use double hyphens? Sorry... 😧

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 11, 2017, 5:24pm UTC](https://discuss.elastic.co/t/delete-indices-older-than-30-days/96630/5 "2017-08-11T17:24:53Z")

</div>

@waterwalker23 you can't quite use `curator_cli` that way. That's the older 3.x syntax. The [new syntax](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/singleton-cli.html) is a bit more complex, since it tries to allow for [complex filters](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/singleton-cli.html#_command_line_filtering).

What you're trying to do would be more like this:

```auto
curator_cli show_indices --filter_list '{"filtertype":"age","source":"name","timestring":"%Y.%m.%d","unit":"days","unit_count":30}'

```

Note that I replaced `delete_indices` with `show_indices`. That's kind of like a `--dry-run`, in that it shows you which indices would be acted on without doing anything to them. It's a great way to test your `--filter_list` and see exactly what will happen to your filtered indices.

Just be sure you don't have other indices with `%Y.%m.%d` in them that you don't want deleted, or they will be affected too, as there are no other filters.

This would look like this in a yaml file (you have to create it yourself):

```auto
---
actions:
  1:
    action: delete_indices
    description: Delete indices with %Y.%m.%d in the name where that date is older than 30 days
    options:
      ignore_empty_list: True
    filters:
      - filtertype: age
        source: name
        timestring: '%Y.%m.%d'
        unit: days
        unit_count: 30

```

If you were to save that file to say, `/path/to/action.yml`, all you'd have to do to run this would be:

```auto
curator --dry-run /path/to/action.yml

```

Again, I add `--dry-run` here so you don't accidentally delete anything before verifying.

---

<div class="post-metadata">

**Author:** ![waterwalker23](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/waterwalker23/32/19707_2.png) [@waterwalker23](https://discuss.elastic.co/u/waterwalker23)\
**Post date:** [August 11, 2017, 5:43pm UTC](https://discuss.elastic.co/t/delete-indices-older-than-30-days/96630/6 "2017-08-11T17:43:41Z")

</div>

When I run `curator_cli show_indices --filter_list '{"filtertype":"age","source":"name","timestring":"%Y.%m.%d","unit":"days","unit_count":30}'` I get the following

Unable to create client connection to Elasticsearch. Error: ConnectionError(\<urllib3.connection.HTTPConnection object at 0x7fb3037ebef0\>: Failed to establish a new connection: [Errno 111] Connection refused) caused by: NewConnectionError(\<urllib3.connection.HTTPConnection object at 0x7fb3037ebef0\>: Failed to establish a new connection: [Errno 111] Connection refused)

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 11, 2017, 5:55pm UTC](https://discuss.elastic.co/t/delete-indices-older-than-30-days/96630/7 "2017-08-11T17:55:26Z")

</div>

You probably still need to include the `--host` option, e.g.

```auto
curator_cli --host localhost show_indices --filter_list '{"filtertype":"age","source":"name","timestring":"%Y.%m.%d","unit":"days","unit_count":30}'

```

as you had it above.

---

<div class="post-metadata">

**Author:** ![waterwalker23](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/waterwalker23/32/19707_2.png) [@waterwalker23](https://discuss.elastic.co/u/waterwalker23)\
**Post date:** [August 11, 2017, 8:12pm UTC](https://discuss.elastic.co/t/delete-indices-older-than-30-days/96630/8 "2017-08-11T20:12:09Z")

</div>

I tried that, but got the same result, then changed to IP and got the following:

```
    `curator_cli --host 10.240.1.130 show_indices --filter_list '{"filtertype":"age","source":"name","timestring":"%Y.%m.%d","unit":"days","unit_count":30}'

```

2017-08-11 14:50:32,593 ERROR Schema error: required key not provided @ data['direction']  
2017-08-11 14:50:32,593 ERROR Schema error: Configuration: filter: Location: singleton, filter #0: {'filtertype': 'age', 'source': 'name', 'timestring': '%Y.%m.%d', 'unit': 'days', 'unit\_count': 30}: Bad Value: "(could not determine)", required key not provided @ data['direction']. Check configuration file.  
Configuration: filters: Location: open singleton action "filters": Bad Value: "None", Configuration: filter: Location: singleton, filter #0: {'filtertype': 'age', 'source': 'name', 'timestring': '%Y.%m.%d', 'unit': 'days', 'unit\_count': 30}: Bad Value: "(could not determine)", required key not provided @ data['direction']. Check configuration file.. Check configuration file.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 11, 2017, 9:12pm UTC](https://discuss.elastic.co/t/delete-indices-older-than-30-days/96630/9 "2017-08-11T21:12:43Z")

</div>

So sorry! That's my bad for trying to recall all of the necessary options for the `age` filtertype off the top of my head.

Add `"direction":"older"` into the filter, like this:

```auto
curator_cli --host 10.240.1.130 show_indices --filter_list '{"filtertype":"age","source":"name","timestring":"%Y.%m.%d","unit":"days","unit_count":30,"direction":"older"}'

```

or in the yaml file:

```auto
---
actions:
  1:
    action: delete_indices
    description: Delete indices with %Y.%m.%d in the name where that date is older than 30 days
    options:
      ignore_empty_list: True
    filters:
      - filtertype: age
        source: name
        timestring: '%Y.%m.%d'
        unit: days
        unit_count: 30
        direction: older

```

---

<div class="post-metadata">

**Author:** ![waterwalker23](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/waterwalker23/32/19707_2.png) [@waterwalker23](https://discuss.elastic.co/u/waterwalker23)\
**Post date:** [August 13, 2017, 5:28am UTC](https://discuss.elastic.co/t/delete-indices-older-than-30-days/96630/10 "2017-08-13T05:28:56Z")

</div>

OK, I ran it by hand and that did it. Thanks. Now I want to look into scripting it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2017, 5:28am UTC](https://discuss.elastic.co/t/delete-indices-older-than-30-days/96630/11 "2017-09-10T05:28:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
