# Dynamic index expiration dates

**URL:** <https://discuss.elastic.co/t/dynamic-index-expiration-dates/165963>\
**Category:** Elasticsearch\
**Created:** [January 28, 2019, 9:03am UTC](https://discuss.elastic.co/t/dynamic-index-expiration-dates/165963 "2019-01-28T09:03:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vincentvm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vincentvm/32/40284_2.png) [@vincentvm](https://discuss.elastic.co/u/vincentvm)\
**Post date:** [January 28, 2019, 9:03am UTC](https://discuss.elastic.co/t/dynamic-index-expiration-dates/165963/1 "2019-01-28T09:03:39Z")

</div>

We're using the following curator script to expire data older than 7 days.

```auto
actions:
  1:
    action: delete_indices
    description: >-
      Delete indices older than 7 days (based on index name), for logstash-
      prefixed indices. Ignore the error if the filter does not result in an
      actionable list of indices (ignore_empty_list) and exit cleanly.
    options:
      ignore_empty_list: True
      timeout_override:
      continue_if_exception: False
      disable_action: False
    filters:
    - filtertype: pattern
      kind: prefix
      value: logstash-
      exclude:
    - filtertype: age
      source: name
      direction: older
      timestring: '%Y.%m.%d'
      unit: days
      unit_count: 7
      exclude:

```

We have data from several different users, we would like some users to have a different index retention than others. What would we the best way to achieve this?

Right now the names of our indices start with `logstash-Y.m.d`

One way I thought it would be possible is to have several indices depending on the retention, for example for 14 day retention `logstash14d-%Y.%m.%d` for 30 days `logstash30d-%Y.%m.%d`

The downside to this is that we would have to check before ingesting every log event what the users retention is.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [January 28, 2019, 1:36pm UTC](https://discuss.elastic.co/t/dynamic-index-expiration-dates/165963/2 "2019-01-28T13:36:48Z")

</div>

Retention at the index level can only be achieved with different named indices. You correctly understand this. And, yes, it also means you have to figure out how to route that data in your Logstash configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 25, 2019, 1:43pm UTC](https://discuss.elastic.co/t/dynamic-index-expiration-dates/165963/3 "2019-02-25T13:43:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
