# Free up disk space

**URL:** <https://discuss.elastic.co/t/free-up-disk-space/245799>\
**Category:** Logstash\
**Tags:** curator\
**Created:** [August 20, 2020, 5:02pm UTC](https://discuss.elastic.co/t/free-up-disk-space/245799 "2020-08-20T17:02:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bruceclegg](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Post date:** [August 20, 2020, 5:02pm UTC](https://discuss.elastic.co/t/free-up-disk-space/245799/1 "2020-08-20T17:02:35Z")

</div>

We have an ELK server that periodically runs out of space. In the spring I worked out a method using curator to delete indices that were more than 30 days old.

But I still don't know much about ELK - Because everyone is working from home nowadays, I can't walk over to the devs and ask. But I still need to solve this problem.

When I run my curator, it frees up the disk space by deleting indices - but many of the indices (and stored queries apparently) are still needed and need to be manually recreated. I figure I could script the creation of the needed files using bash and CLI commands, but that isn't ideal. Is there a way to use curator, or some other tool, to just reduce the index size (clean out data more than 30 days old)?

Here is what I have now:

_[root@ELK elasticsearch]# cat /etc/curator/config.yml_  
_client:_

- hosts:\*
- 
  - 10.X.X.X\*

- port: 9200\*
- url\_prefix: \*
- use\_ssl: False\*
- certificate:\*
- client\_cert: /etc/elasticsearch/config/certs/elk/elk.crt\*
- client\_key: /etc/elasticsearch/config/certs/elk/elk.key\*
- ssl\_no\_validate: False\*
- http\_auth: \*
- timeout: 30\*
- master\_only: False\*

_logging:_

- loglevel: INFO\*
- logfile: /var/log/curator/curator\_log\*
- logformat: default\*
- blacklist: ['elasticsearch', 'urllib3']\*

_[root@ELK elasticsearch]# cat /etc/curator/action.yml_  
_actions:_

- 1:\*
- action: delete\_indices\*
- description: \>-\*
- 

```
 Delete indices older than 30 days (based on creation date).*

```

- options:\*
- 

```
 ignore_empty_list: True*

```

- 

```
 disable_action: False*

```

- filters:\*
- 
  - filtertype: age\*

- 

```
 source: creation_date*

```

- 

```
 direction: older*

```

- 

```
 timestring: '%Y.%m.%d'*

```

- 

```
 unit: days*

```

- 

```
 unit_count: 30*

```

Any help would be very much appreciated!

---

<div class="post-metadata">

**Author:** ![Bruceclegg](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Post date:** [August 20, 2020, 5:03pm UTC](https://discuss.elastic.co/t/free-up-disk-space/245799/2 "2020-08-20T17:03:42Z")

</div>

That looks hard to read - trying again:

[root@ELK elasticsearch]# cat /etc/curator/config.yml  
client:  
hosts:  
- 10.X.X.X  
port: 9200  
url\_prefix:  
use\_ssl: False  
certificate:  
client\_cert: /etc/elasticsearch/config/certs/elk/elk.crt  
client\_key: /etc/elasticsearch/config/certs/elk/elk.key  
ssl\_no\_validate: False  
http\_auth:   
timeout: 30  
master\_only: False

logging:  
loglevel: INFO  
logfile: /var/log/curator/curator\_log  
logformat: default  
blacklist: ['elasticsearch', 'urllib3']  
[root@ELK elasticsearch]# cat /etc/curator/action.yml  
actions:  
1:  
action: delete\_indices  
description: \>-  
Delete indices older than 30 days (based on creation date).  
options:  
ignore\_empty\_list: True  
disable\_action: False  
filters:  
- filtertype: age  
source: creation\_date  
direction: older  
timestring: '%Y.%m.%d'  
unit: days  
unit\_count: 30

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 17, 2020, 5:03pm UTC](https://discuss.elastic.co/t/free-up-disk-space/245799/3 "2020-09-17T17:03:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
