# Deleting Indexs that are X day old

**URL:** <https://discuss.elastic.co/t/deleting-indexs-that-are-x-day-old/26811>\
**Category:** Elasticsearch\
**Created:** [August 4, 2015, 3:15pm UTC](https://discuss.elastic.co/t/deleting-indexs-that-are-x-day-old/26811 "2015-08-04T15:15:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![michaellizhou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaellizhou/32/4143_2.png) [@michaellizhou](https://discuss.elastic.co/u/michaellizhou)\
**Post date:** [August 4, 2015, 3:15pm UTC](https://discuss.elastic.co/t/deleting-indexs-that-are-x-day-old/26811/1 "2015-08-04T15:15:49Z")

</div>

As a requirement I am trying to delete indexes that are, lets say 2 or 3 days old. I think it would just be simple to write a cron job to simply do this type of task. But is there anything ES provides that can delete indexes as such? Or is there a GUI plugin that allows you to delete old indexes in this manner? All my indexes are in this format

logstash-dd.MM.YYYY-TYPE

So they are pretty consistent.

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [August 4, 2015, 3:26pm UTC](https://discuss.elastic.co/t/deleting-indexs-that-are-x-day-old/26811/2 "2015-08-04T15:26:49Z")

</div>

Take a look at [Curator](https://github.com/elastic/curator), It was built specifically for doing these kinds of tasks on time series indices. You will still need to run a cron job but it simplifies the command greatly

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 4, 2015, 3:31pm UTC](https://discuss.elastic.co/t/deleting-indexs-that-are-x-day-old/26811/3 "2015-08-04T15:31:33Z")

</div>

The official documentation is at [https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html)

It was written specifically for this use case.

---

<div class="post-metadata">

**Author:** ![michaellizhou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaellizhou/32/4143_2.png) [@michaellizhou](https://discuss.elastic.co/u/michaellizhou)\
**Post date:** [August 4, 2015, 9:38pm UTC](https://discuss.elastic.co/t/deleting-indexs-that-are-x-day-old/26811/4 "2015-08-04T21:38:02Z")

</div>

@theuntergeek and @colings86

Didn't even know this existed. I just want to check if this is right approach or common way to this problem:  
Its not that intuitive with the link you provided but I found this which is straight forward just not sure of the version compatibility since I am on ES 1.5.1

> [Elasticsearch Curator -- Version 1.1.0 Released | Elastic Blog](https://www.elastic.co/blog/elasticsearch-curator-version-1-1-0-released)

From this link it's as simple as

```
curator delete --older-than 2

```

But the link by @theuntergeek it seems to be more like

```
curator delete indices --time-unit hours --older-than 2 --timestring '%Y.%m.%d.%H' --prefix logstash --suffix -server

```

My indexes are actually logstash-YYYY.mm.DD-{type}... I have 5 types so I should probably use a regex

And like @colings86 said use cron at the end of the day

Just out of curiosity can v1.1.0 (above) delete indices that aren't even indexed as logstash-YYYY.MM.dd  
So for example I index everything without timestamps like logstash-{type} so it will just delete documents older then 2 days. I ask because I read somewhere that too many indices really hurts performance. More indices == more shards. Something I want to keep in mind.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 4, 2015, 10:28pm UTC](https://discuss.elastic.co/t/deleting-indexs-that-are-x-day-old/26811/5 "2015-08-04T22:28:34Z")

</div>

That blog post is old, go by the docs that Aaron linked to as things have changed.

Curator does require indices with some time indicator attached to their name, ie it doesn't look at the index creation date, it looks at the name of the index and figures things out from that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:57pm UTC](https://discuss.elastic.co/t/deleting-indexs-that-are-x-day-old/26811/6 "2017-07-05T23:57:24Z")

</div>


