# Delete Old Log elastic search

**URL:** <https://discuss.elastic.co/t/delete-old-log-elastic-search/363314>\
**Category:** Logstash\
**Created:** [July 18, 2024, 5:36am UTC](https://discuss.elastic.co/t/delete-old-log-elastic-search/363314 "2024-07-18T05:36:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Agaaam](https://avatars.discourse-cdn.com/v4/letter/a/b38774/32.png) [@Agaaam](https://discuss.elastic.co/u/Agaaam)\
**Post date:** [July 18, 2024, 5:36am UTC](https://discuss.elastic.co/t/delete-old-log-elastic-search/363314/1 "2024-07-18T05:36:55Z")

</div>

Hallo,

Currently im using Elastic Kibana Filebeat and logstash to colellect log accross server and docker , and suddenly the drive got too bigs and take so much disk space, what can i do to delete 3 old month logs ?

thank you so much,

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 18, 2024, 9:35am UTC](https://discuss.elastic.co/t/delete-old-log-elastic-search/363314/2 "2024-07-18T09:35:31Z")

</div>

Hi @Agaaam,

Welcome! Are you indices dated? If so you can delete the older indices. If not, and you need a quick fix to delete documents from an index, you can do this using a [delete by query](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-delete-by-query.html) using a [range query similar to this one in the documentation for the last day](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html#ranges-on-dates) to identify documents with timestamps greater than 3 months old.

Just a warning that I would check the query first with a `_search` before running the delete to make sure you are happy with the results.

Longer term I would also recommend looking at using [ILM](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-management.html) to manage deletion of older logs and indices automatically.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![Agaaam](https://avatars.discourse-cdn.com/v4/letter/a/b38774/32.png) [@Agaaam](https://discuss.elastic.co/u/Agaaam)\
**Post date:** [July 18, 2024, 10:13am UTC](https://discuss.elastic.co/t/delete-old-log-elastic-search/363314/3 "2024-07-18T10:13:32Z")

</div>

Thank you so much for answer,  
i this can also to implement for log from application running under docker , that i sent using file beat to logstash ?  
i already try using

```auto
http://11.21.12.44:9200/filebeat-8.5.0-*/_search?pretty
request : {
  "query": {
    "range": {
      "timestamp": {
        "gte": "now-1d/d",
        "lte": "now/d"
      }
    }
  }
}

```

only get resp :

```auto
{
    "took": 0,
    "timed_out": false,
    "_shards": {
        "total": 0,
        "successful": 0,
        "skipped": 0,
        "failed": 0
    },
    "hits": {
        "total": {
            "value": 0,
            "relation": "eq"
        },
        "max_score": 0.0,
        "hits": []
    }
}

```

thank you

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 18, 2024, 12:37pm UTC](https://discuss.elastic.co/t/delete-old-log-elastic-search/363314/4 "2024-07-18T12:37:08Z")

</div>

Just a heads up @Agaaam that the above query is for a single day. Can you try using the field `@timestamp` instead of `timestamp` in your range query?

---

<div class="post-metadata">

**Author:** ![Agaaam](https://avatars.discourse-cdn.com/v4/letter/a/b38774/32.png) [@Agaaam](https://discuss.elastic.co/u/Agaaam)\
**Post date:** [July 18, 2024, 12:56pm UTC](https://discuss.elastic.co/t/delete-old-log-elastic-search/363314/5 "2024-07-18T12:56:16Z")

</div>

@carly.richmond alright thank you i already find it , thank you so much for your help 🙏 🙏
