# Deleting parts of data from an index

**URL:** <https://discuss.elastic.co/t/deleting-parts-of-data-from-an-index/35220>\
**Category:** Elasticsearch\
**Created:** [November 21, 2015, 1:19pm UTC](https://discuss.elastic.co/t/deleting-parts-of-data-from-an-index/35220 "2015-11-21T13:19:20Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![KavyaS](https://avatars.discourse-cdn.com/v4/letter/k/838e76/32.png) [@KavyaS](https://discuss.elastic.co/u/KavyaS)\
**Post date:** [November 21, 2015, 1:19pm UTC](https://discuss.elastic.co/t/deleting-parts-of-data-from-an-index/35220/1 "2015-11-21T13:19:20Z")

</div>

Suppose i have thousands of log lines. Would deleting some of the log lines erase the data completely from disk space or does it just not display in search results and is still present in the disk?

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [November 21, 2015, 1:43pm UTC](https://discuss.elastic.co/t/deleting-parts-of-data-from-an-index/35220/2 "2015-11-21T13:43:20Z")

</div>

Both. At first its just that the documents are marked as deleted. They are  
later removed when the segment they live in is merged with another segment.  
Updates are the same way.

Usually this works fine. If you have data that "rolls away" its usually  
better to make an index per time period and then nuke the whole index.  
There is a tradeoff between the number of indexes and the ease of deleting  
the whole index. That is a balancing act that you have to experiment with.

---

<div class="post-metadata">

**Author:** ![KavyaS](https://avatars.discourse-cdn.com/v4/letter/k/838e76/32.png) [@KavyaS](https://discuss.elastic.co/u/KavyaS)\
**Post date:** [November 23, 2015, 6:09am UTC](https://discuss.elastic.co/t/deleting-parts-of-data-from-an-index/35220/3 "2015-11-23T06:09:12Z")

</div>

Thanks! Will research more about it.

---

<div class="post-metadata">

**Author:** ![mainec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mainec/32/5557_2.png) [@mainec](https://discuss.elastic.co/u/mainec)\
**Post date:** [November 23, 2015, 2:17pm UTC](https://discuss.elastic.co/t/deleting-parts-of-data-from-an-index/35220/4 "2015-11-23T14:17:31Z")

</div>

If you need some starting points for your research:

[https://www.elastic.co/guide/en/elasticsearch/guide/current/time-based.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/time-based.html)

[https://www.elastic.co/guide/en/elasticsearch/guide/current/retiring-data.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/retiring-data.html)

---

<div class="post-metadata">

**Author:** ![KavyaS](https://avatars.discourse-cdn.com/v4/letter/k/838e76/32.png) [@KavyaS](https://discuss.elastic.co/u/KavyaS)\
**Post date:** [November 23, 2015, 2:21pm UTC](https://discuss.elastic.co/t/deleting-parts-of-data-from-an-index/35220/5 "2015-11-23T14:21:09Z")

</div>

Thanks for the links!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:36pm UTC](https://discuss.elastic.co/t/deleting-parts-of-data-from-an-index/35220/6 "2017-07-05T23:36:35Z")

</div>


