# Delete / purge data from fields

**URL:** <https://discuss.elastic.co/t/delete-purge-data-from-fields/200959>\
**Category:** Elasticsearch\
**Created:** [September 25, 2019, 5:22am UTC](https://discuss.elastic.co/t/delete-purge-data-from-fields/200959 "2019-09-25T05:22:44Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![shappy123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shappy123/32/51133_2.png) [@shappy123](https://discuss.elastic.co/u/shappy123)\
**Post date:** [September 25, 2019, 5:22am UTC](https://discuss.elastic.co/t/delete-purge-data-from-fields/200959/1 "2019-09-25T05:22:44Z")

</div>

Hi Guys,

Would highly appreciate if you guys can please assist me on this , I need to delete/purge existing + old data which contains these fields : fields.SourceContext & fields.RequestBody under the fields.applicationName= "xyz" .

Can you please let me know what should be the command or script so I can run & delete/purge them.

Hope to hear from you soon.

Cheers

Shap

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 25, 2019, 11:52am UTC](https://discuss.elastic.co/t/delete-purge-data-from-fields/200959/2 "2019-09-25T11:52:37Z")

</div>

See the [Delete by Query API](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/docs-delete-by-query.html)

If you alternatively could delete a whole index instead of single documents, you should do that due to much faster execution, otherwise the above should work for you.

---

<div class="post-metadata">

**Author:** ![shappy123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shappy123/32/51133_2.png) [@shappy123](https://discuss.elastic.co/u/shappy123)\
**Post date:** [September 25, 2019, 12:16pm UTC](https://discuss.elastic.co/t/delete-purge-data-from-fields/200959/3 "2019-09-25T12:16:53Z")

</div>

hi Alexander,

thanks for your reply, would appreciate if you could plz write the query, as I m very new to elastic and not have much time to try it out on my own, please would appreciate.

thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 25, 2019, 12:42pm UTC](https://discuss.elastic.co/t/delete-purge-data-from-fields/200959/4 "2019-09-25T12:42:08Z")

</div>

Please note, that this is forum completely based on voluntary replies. If you do not have a lot of time, you may want to take a look at commercial support options instead. See [https://www.elastic.co/subscriptions](https://www.elastic.co/subscriptions)

I personally do expect people to invest some time into solving a problem, after shown a potential solution. If you try things out and show examples, error messages, how something is not working or what details you are missing on, it's a completely different thing, but just asking to get the work done by someone else without willingness to learn it yourself is something I consider rude towards others and their time and willingness to help.

---

<div class="post-metadata">

**Author:** ![shappy123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shappy123/32/51133_2.png) [@shappy123](https://discuss.elastic.co/u/shappy123)\
**Post date:** [September 25, 2019, 10:23pm UTC](https://discuss.elastic.co/t/delete-purge-data-from-fields/200959/5 "2019-09-25T22:23:44Z")

</div>

Hi Alexandar,

Thanks for it , i will try it and let know here if still I am on the right path... cheers

---

<div class="post-metadata">

**Author:** ![shappy123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shappy123/32/51133_2.png) [@shappy123](https://discuss.elastic.co/u/shappy123)\
**Post date:** [September 26, 2019, 5:05am UTC](https://discuss.elastic.co/t/delete-purge-data-from-fields/200959/6 "2019-09-26T05:05:07Z")

</div>

## @spinscale..Hi alexandar, can you please let me know if this query is fine , I had a field named as "fields.xyz" under the \_source which has information stored with a these letters " Docabc" , so if i run it would this delete the "fields.xyz" field only:

POST logstash-2019.06.10/\_delete\_by\_query  
{  
"query": {  
"match": {  
"message": "Docabc"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 26, 2019, 7:00am UTC](https://discuss.elastic.co/t/delete-purge-data-from-fields/200959/7 "2019-09-26T07:00:44Z")

</div>

you need to specify the concrete field named `fields.xyz` instead of `message`

---

<div class="post-metadata">

**Author:** ![shappy123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shappy123/32/51133_2.png) [@shappy123](https://discuss.elastic.co/u/shappy123)\
**Post date:** [September 29, 2019, 11:29pm UTC](https://discuss.elastic.co/t/delete-purge-data-from-fields/200959/8 "2019-09-29T23:29:19Z")

</div>

@spinscale, thanks for your reply, i got your point from the last reply , but the problem is that we have 3 different cluster env ( prod, preprod and nonprod ) plus i just want to delete them from under this fields.ApplicationName= abc-abc123-123 , this fileds.applicationName is under the prod cluster and the source words "Docabc" are within the filed.Message ( eventually the filed.message is very huge, so these charcters " Docabc" are part of this field.message)... so eventually i need to delete/purge data that have all these included...... what should i do then... please let me know

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 30, 2019, 12:14pm UTC](https://discuss.elastic.co/t/delete-purge-data-from-fields/200959/9 "2019-09-30T12:14:05Z")

</div>

I do not understand where the problem is regarding a cluster environment and why that means you need to execute a different query.

If you mean, you need to specify more than one criteria to match your query, take a look at the [bool query](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/query-dsl-bool-query.html) with a `must` part, that can be an array.

--Alex

---

<div class="post-metadata">

**Author:** ![shappy123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shappy123/32/51133_2.png) [@shappy123](https://discuss.elastic.co/u/shappy123)\
**Post date:** [October 1, 2019, 11:51pm UTC](https://discuss.elastic.co/t/delete-purge-data-from-fields/200959/10 "2019-10-01T23:51:39Z")

</div>

@spinscale.. Hi .. thanks a lot the bool query works what I was actually looking for, my next question : is there any way around to make these queries automated , so that it may run by itself or by scheduling them.

Cheers

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2019, 11:51pm UTC](https://discuss.elastic.co/t/delete-purge-data-from-fields/200959/11 "2019-10-29T23:51:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
