# Help deleting data

**URL:** <https://discuss.elastic.co/t/help-deleting-data/121851>\
**Category:** Logstash\
**Created:** [February 28, 2018, 12:31pm UTC](https://discuss.elastic.co/t/help-deleting-data/121851 "2018-02-28T12:31:50Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![keithh](https://avatars.discourse-cdn.com/v4/letter/k/958977/32.png) [@keithh](https://discuss.elastic.co/u/keithh)\
**Post date:** [February 28, 2018, 12:31pm UTC](https://discuss.elastic.co/t/help-deleting-data/121851/1 "2018-02-28T12:31:50Z")

</div>

Hi there,

Forgive my ignorance in advance.

I've inherited an old stack with elasticsearch 1.7. Previously, as has been documented in many threads, it was possible to delete logs using a chrome plugin, which has since been disabled.

I'm reluctant to upgrade the stack because I don't know what else I'll need to do and I have no internal resources to draw on. Previously I would delete logstash logs older than a certain date just by changing the date parameter in a query in the plugin console on Chrome. Please could someone give me some help in how I delete logs older than a specific date going forward?

I can't remember the exact syntax but it went something like "DELETE LOGSTASH ...."

Thanks in advance (and apologies once again if this is a dumb question).  
Keith

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [February 28, 2018, 1:24pm UTC](https://discuss.elastic.co/t/help-deleting-data/121851/2 "2018-02-28T13:24:38Z")

</div>

This seems more appropriate for the ElasticSeach subforum 🙂

Anyhow, [delete-by-query](https://www.elastic.co/guide/en/elasticsearch/reference/1.7/docs-delete-by-query.html) is probably what you're looking for, where you can query for all documents older than a specific date and delete them.

---

<div class="post-metadata">

**Author:** ![keithh](https://avatars.discourse-cdn.com/v4/letter/k/958977/32.png) [@keithh](https://discuss.elastic.co/u/keithh)\
**Post date:** [February 28, 2018, 1:37pm UTC](https://discuss.elastic.co/t/help-deleting-data/121851/3 "2018-02-28T13:37:03Z")

</div>

Thanks @paz,

Apologies for mis-posting. I take it that delete-by-query can only be invoked from the command line?

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [February 28, 2018, 1:39pm UTC](https://discuss.elastic.co/t/help-deleting-data/121851/4 "2018-02-28T13:39:26Z")

</div>

I'd assume you can also run it via the head plugin, though I have never tested so myself.

---

<div class="post-metadata">

**Author:** ![keithh](https://avatars.discourse-cdn.com/v4/letter/k/958977/32.png) [@keithh](https://discuss.elastic.co/u/keithh)\
**Post date:** [March 8, 2018, 12:19pm UTC](https://discuss.elastic.co/t/help-deleting-data/121851/5 "2018-03-08T12:19:30Z")

</div>

Thanks @paz ,

Apologies once more for my ignorance. what plugin are you referring to? Is it a Chrome plugin?

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [March 8, 2018, 12:34pm UTC](https://discuss.elastic.co/t/help-deleting-data/121851/6 "2018-03-08T12:34:38Z")

</div>

No worries. It's [this](https://github.com/mobz/elasticsearch-head) one. Depending on your ElasticSearch version you can either install it as an ElasticSearch plugin or a standalone version.

If with "Chrome plugin" you mean [this](https://github.com/TravisTX/elasticsearch-head-chrome), it's practically the same thing as above wrapped in a browser extension, so you can use that indeed.

---

<div class="post-metadata">

**Author:** ![keithh](https://avatars.discourse-cdn.com/v4/letter/k/958977/32.png) [@keithh](https://discuss.elastic.co/u/keithh)\
**Post date:** [April 4, 2018, 10:58am UTC](https://discuss.elastic.co/t/help-deleting-data/121851/7 "2018-04-04T10:58:52Z")

</div>

Thanks @paz,

Sorted now. Installed the plugin. It took me a bit to get my head round it. I couldn't find any docs for the chrome plugin, so was trying all sorts of complicated structured queries, when I stumbled upon the delete option in the Actions dropdown. D'Oh!

Happy now! 😀

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 4, 2018, 3:03pm UTC](https://discuss.elastic.co/t/help-deleting-data/121851/8 "2018-04-04T15:03:47Z")

</div>

Oh wow. Delete by query is a horrible idea for time series data. It's like the difference in SQL between `DELETE from TABLE where timestamp < x` and `DROP TABLE`. Millions of atomic operations in one vs. a single operation for the other.

Use Elasticsearch Curator to delete time series indices on a schedule.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2018, 3:03pm UTC](https://discuss.elastic.co/t/help-deleting-data/121851/9 "2018-05-02T15:03:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
