# Delete logs

**URL:** <https://discuss.elastic.co/t/delete-logs/57316>\
**Category:** Elasticsearch\
**Created:** [August 5, 2016, 8:40am UTC](https://discuss.elastic.co/t/delete-logs/57316 "2016-08-05T08:40:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![zen.xen](https://avatars.discourse-cdn.com/v4/letter/z/e495f1/32.png) [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Post date:** [August 5, 2016, 8:40am UTC](https://discuss.elastic.co/t/delete-logs/57316/1 "2016-08-05T08:40:46Z")

</div>

Hello,  
how to properly delete index, eg. winlogbeat-2016.06.30 on Windows ELK?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [August 5, 2016, 8:57am UTC](https://discuss.elastic.co/t/delete-logs/57316/2 "2016-08-05T08:57:55Z")

</div>

We offer a REST api [1] which is accessible from many clients.

- The simplest (in Unix) is using the CURL command-line tool which I'm sure you can find Windows-equivalents of.
- Language clients like Python, Perl, Java, Ruby etc
- Browser-based GUIs
  - General-purpose REST clients [3]
  - elasticsearch-specific UIs [4]

[1] [https://www.elastic.co/guide/en/elasticsearch/reference/2.3/indices-delete-index.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.3/indices-delete-index.html)  
[2] [https://www.elastic.co/elasticon/2015/sf/all-about-elasticsearch-language-clients](https://www.elastic.co/elasticon/2015/sf/all-about-elasticsearch-language-clients)  
[3] [https://chrome.google.com/webstore/detail/insomnia-rest-client/gmodihnfibbjdecbanmpmbmeffnmloel?hl=en](https://chrome.google.com/webstore/detail/insomnia-rest-client/gmodihnfibbjdecbanmpmbmeffnmloel?hl=en)  
[4] [https://www.elastic.co/guide/en/elasticsearch/plugins/2.3/management.html#\_community\_contributed\_management\_and\_site\_plugins](https://www.elastic.co/guide/en/elasticsearch/plugins/2.3/management.html#_community_contributed_management_and_site_plugins)

---

<div class="post-metadata">

**Author:** ![zen.xen](https://avatars.discourse-cdn.com/v4/letter/z/e495f1/32.png) [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Post date:** [August 5, 2016, 11:26am UTC](https://discuss.elastic.co/t/delete-logs/57316/3 "2016-08-05T11:26:00Z")

</div>

Thank you, link [4] is interesting, ElasticHQ looks good.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 5, 2016, 3:21pm UTC](https://discuss.elastic.co/t/delete-logs/57316/4 "2016-08-05T15:21:15Z")

</div>

Have you looked at [Elasticsearch Curator](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html)? It can [delete indices](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/actions.html) based on definable criteria, as well as many other actions.

As a bonus, there is a [Windows binary](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/installation.html#windows-binary) package available.

---

<div class="post-metadata">

**Author:** ![zen.xen](https://avatars.discourse-cdn.com/v4/letter/z/e495f1/32.png) [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Post date:** [August 6, 2016, 6:04pm UTC](https://discuss.elastic.co/t/delete-logs/57316/5 "2016-08-06T18:04:15Z")

</div>

I looked at [curator](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html) but it is a little bit complicated tool as for me, but I try to learn it, thanks for help.

---

<div class="post-metadata">

**Author:** ![zen.xen](https://avatars.discourse-cdn.com/v4/letter/z/e495f1/32.png) [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Post date:** [August 8, 2016, 8:52am UTC](https://discuss.elastic.co/t/delete-logs/57316/6 "2016-08-08T08:52:21Z")

</div>

I try to use `Windows curator` but I have troubles, I'd like to delete indices ex. from `winlogbeat-2016.07.20` to `winlogbeat-2016.07.30`, how can I do this?

I noticed something and it is a little bit strange, when I delete index with ElasticHQ and then add other machine to send events, the deleted index is re-created, although is small. How can I permanently delete it?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 8, 2016, 3:13pm UTC](https://discuss.elastic.co/t/delete-logs/57316/7 "2016-08-08T15:13:03Z")

</div>

> [@zen.xen](#):
>
> I noticed something and it is a little bit strange, when I delete index with ElasticHQ and then add other machine to send events, the deleted index is re-created, although is small. How can I permanently delete it?

If it is being recreated, it is because something is still being sent to be indexed to that index. You will simply have to re-delete it until nothing else is sending data.

As far as using Curator is concerned, try the [delete\_indices example](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/examples.html#ex_delete_indices) as a starting place.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:29pm UTC](https://discuss.elastic.co/t/delete-logs/57316/8 "2017-07-05T22:29:22Z")

</div>


