# Delete old data

**URL:** <https://discuss.elastic.co/t/delete-old-data/29640>\
**Category:** Elasticsearch\
**Created:** [September 19, 2015, 5:28pm UTC](https://discuss.elastic.co/t/delete-old-data/29640 "2015-09-19T17:28:32Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![chinmoyd](https://avatars.discourse-cdn.com/v4/letter/c/e495f1/32.png) [@chinmoyd](https://discuss.elastic.co/u/chinmoyd)\
**Post date:** [September 19, 2015, 5:28pm UTC](https://discuss.elastic.co/t/delete-old-data/29640/1 "2015-09-19T17:28:32Z")

</div>

I want to delete all data from elastic search that is more than one week old. I have tried a command as below:  
curl -XDELETE '[http://localhost:9200/logstash\_2015\_09\_12](http://localhost:9200/logstash_2015_09_12)'. But the data for that day is still displayed in Kibana. The index name in my settings page in Kibana is logstash-\*. Am I missing anything?

Also, please suggest the best methodology to set up a job that will remove all data more than one week, assuming that the job will run once a day.

---

<div class="post-metadata">

**Author:** ![eliasah](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eliasah/32/34741_2.png) [@eliasah](https://discuss.elastic.co/u/eliasah)\
**Post date:** [September 19, 2015, 5:33pm UTC](https://discuss.elastic.co/t/delete-old-data/29640/2 "2015-09-19T17:33:57Z")

</div>

Have you refreshed your index in Kibana?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [September 19, 2015, 5:43pm UTC](https://discuss.elastic.co/t/delete-old-data/29640/3 "2015-09-19T17:43:49Z")

</div>

> [@chinmoyd](#):
>
> Also, please suggest the best methodology to set up a job that will remove all data more than one week, assuming that the job will run once a day.

Use [curator](https://github.com/elastic/curator).

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [September 19, 2015, 5:50pm UTC](https://discuss.elastic.co/t/delete-old-data/29640/4 "2015-09-19T17:50:42Z")

</div>

I concur with @dadoonet. Curator is the tool to use for Logstash indices. The usage documentation for Curator can be found at [https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html) (@dadoonet provided the link to the source code).

And one possible reason you see data for the 12th of September is that Logstash creates datestamps based on UTC time. Depending on your offset from UTC, you could see a little or a lot still for that date in _your_ time zone.

---

<div class="post-metadata">

**Author:** ![eliasah](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eliasah/32/34741_2.png) [@eliasah](https://discuss.elastic.co/u/eliasah)\
**Post date:** [September 19, 2015, 5:53pm UTC](https://discuss.elastic.co/t/delete-old-data/29640/5 "2015-09-19T17:53:58Z")

</div>

I tottally agree with @dadoonet and @theuntergeek.

Another solution would be writing your own cron job to do that for you. This might be longer to integrate thought.

---

<div class="post-metadata">

**Author:** ![chinmoyd](https://avatars.discourse-cdn.com/v4/letter/c/e495f1/32.png) [@chinmoyd](https://discuss.elastic.co/u/chinmoyd)\
**Post date:** [October 8, 2015, 5:15am UTC](https://discuss.elastic.co/t/delete-old-data/29640/6 "2015-10-08T05:15:01Z")

</div>

Thanks. This helped.

I have around eight fields in my queries with ELK, viz. bank name, transaction id, timestamp, response code, transaction type, notes, transaction channel, transaction amount. In Kibana I have used the following in different dashboards:  
_exists_:bankname  
_exists_:transactionid  
Besides I have different pie charts based on transaction channel ( example: mobile, internet, ATM ), transaction type and response code ( success/failure).

Can you please suggest whether I need to tune something in Elastic search, such that the dashboard gives good performance with large amount of data?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [October 9, 2015, 6:11pm UTC](https://discuss.elastic.co/t/delete-old-data/29640/7 "2015-10-09T18:11:22Z")

</div>

@chinmoyd This question should be its own topic.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:45pm UTC](https://discuss.elastic.co/t/delete-old-data/29640/8 "2017-07-05T23:45:36Z")

</div>


