# Elasticsearch indexes filling up the drive

**URL:** <https://discuss.elastic.co/t/elasticsearch-indexes-filling-up-the-drive/61938>\
**Category:** Elasticsearch\
**Created:** [September 30, 2016, 3:35pm UTC](https://discuss.elastic.co/t/elasticsearch-indexes-filling-up-the-drive/61938 "2016-09-30T15:35:44Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![napoleon182](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/napoleon182/32/11725_2.png) [@napoleon182](https://discuss.elastic.co/u/napoleon182)\
**Post date:** [September 30, 2016, 3:35pm UTC](https://discuss.elastic.co/t/elasticsearch-indexes-filling-up-the-drive/61938/1 "2016-09-30T15:35:44Z")

</div>

Hi All, what will be the best approach to implement policy where only last 3months of logs are being kept and analysed in the elasticsearch?  
I'm currently testing curator- any advise on best approach?  
Thanks a lot guys.

Cheers, Tomek

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 2, 2016, 6:18am UTC](https://discuss.elastic.co/t/elasticsearch-indexes-filling-up-the-drive/61938/2 "2016-10-02T06:18:04Z")

</div>

Curator is 100% the best option.

---

<div class="post-metadata">

**Author:** ![napoleon182](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/napoleon182/32/11725_2.png) [@napoleon182](https://discuss.elastic.co/u/napoleon182)\
**Post date:** [October 3, 2016, 10:10am UTC](https://discuss.elastic.co/t/elasticsearch-indexes-filling-up-the-drive/61938/3 "2016-10-03T10:10:24Z")

</div>

Thanks Mark, any recommendations on the commands I can use to keep logs for only certain time? I'm using curator version 3.5.1

Cheers, Tomek

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 3, 2016, 11:46am UTC](https://discuss.elastic.co/t/elasticsearch-indexes-filling-up-the-drive/61938/4 "2016-10-03T11:46:07Z")

</div>

[https://www.elastic.co/guide/en/elasticsearch/client/curator/3.5/index.html](https://www.elastic.co/guide/en/elasticsearch/client/curator/3.5/index.html) is the best bet for that, I'd have to refer to it anyway 😉

---

<div class="post-metadata">

**Author:** ![napoleon182](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/napoleon182/32/11725_2.png) [@napoleon182](https://discuss.elastic.co/u/napoleon182)\
**Post date:** [October 3, 2016, 11:48am UTC](https://discuss.elastic.co/t/elasticsearch-indexes-filling-up-the-drive/61938/5 "2016-10-03T11:48:57Z")

</div>

That's fine Mark, no probs, I will digest the document and try to figure out some commands,

Will share the most useful in this thread,

Cheers, Tomek

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:15pm UTC](https://discuss.elastic.co/t/elasticsearch-indexes-filling-up-the-drive/61938/6 "2017-07-05T22:15:28Z")

</div>


