# Elasticsearch docs purging

**URL:** <https://discuss.elastic.co/t/elasticsearch-docs-purging/219656>\
**Category:** Elasticsearch\
**Created:** [February 17, 2020, 4:47pm UTC](https://discuss.elastic.co/t/elasticsearch-docs-purging/219656 "2020-02-17T16:47:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ron\_ITS](https://avatars.discourse-cdn.com/v4/letter/r/d78d45/32.png) [@Ron\_ITS](https://discuss.elastic.co/u/Ron_ITS)\
**Post date:** [February 17, 2020, 4:47pm UTC](https://discuss.elastic.co/t/elasticsearch-docs-purging/219656/1 "2020-02-17T16:47:49Z")

</div>

Hi,

Is there a ES function that can replace the epoch time? Currently we purge the doc according to ttl for past 35 days. is there a better way to handle it?

{"size":0,  
"query": {  
"bool": {  
"must": [  
{  
"exists" : {  
"field" : "hubtimestamp"  
}  
},  
{  
"script": {  
"script": {  
"lang": "expression",  
"source": "((doc["ttl\_i"].value ==0 ? 35 :doc["ttl\_i"].value) _24_60_60_1000)+ doc["hubtimestamp"].value \<=datenow",  
"params": {  
"datenow": {$EPOCH\_TIME} \<\<\<\<==== need ES function to populate the value.  
}  
}  
}  
}  
]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 18, 2020, 10:11am UTC](https://discuss.elastic.co/t/elasticsearch-docs-purging/219656/2 "2020-02-18T10:11:48Z")

</div>

Hey,

From the outside it seems to me as if you are trying to solve the wrong problem. How about having time-based indices (weekly, daily, whatever), which will allow you to simply delete a whole index after 35 days. This is much easier and **much** cheaper to do, than trying to delete documents based on a query.

If you have per document TTLs you could index those documents based on their TTL and basically do the same.

If this is not an option, why not add a fixed TTL timestamp on index time, so that deletion becomes easier by just specifying a date range, this way you would not need a script?

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2020, 10:11am UTC](https://discuss.elastic.co/t/elasticsearch-docs-purging/219656/3 "2020-03-17T10:11:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
