# How can I delete documents 3 months older?

**URL:** <https://discuss.elastic.co/t/how-can-i-delete-documents-3-months-older/335351>\
**Category:** Kibana\
**Created:** [June 6, 2023, 1:34pm UTC](https://discuss.elastic.co/t/how-can-i-delete-documents-3-months-older/335351 "2023-06-06T13:34:43Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mary2022](https://avatars.discourse-cdn.com/v4/letter/m/e8c25b/32.png) [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Post date:** [June 6, 2023, 1:34pm UTC](https://discuss.elastic.co/t/how-can-i-delete-documents-3-months-older/335351/1 "2023-06-06T13:34:43Z")

</div>

I have Elasticsearch and Kibana 8.6 and I have an index with a size of 115GB. I would like to query by @timestamp and delete documents older than April 1, 2023. How can I do that? I am new to the query part and not sure what is the best syntax to query and delete.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 6, 2023, 2:42pm UTC](https://discuss.elastic.co/t/how-can-i-delete-documents-3-months-older/335351/2 "2023-06-06T14:42:53Z")

</div>

Hi @Mary2022,

You can use the [`delete_by_query`](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-delete-by-query.html) API to delete the documents that match a given query. Using that combined with a [`range`](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html#ranges-on-dates) query will allow you to delete documents within a given date range, similar to the below:

```auto
POST /my-index/_delete_by_query
{
  "query": {
    "range": {
      "timestamp": {    
        "lte": "2023-004-01T00:00:00", 
      }
    }
  }
}

```

I would recommend running the query via a basic `_search` first to make sure you are capturing the results you want before deletion. Hope that helps!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 6, 2023, 11:33pm UTC](https://discuss.elastic.co/t/how-can-i-delete-documents-3-months-older/335351/3 "2023-06-06T23:33:23Z")

</div>

You are also best off migrating your index approach to use time based [ILM](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-management.html). It's far more efficient.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 7, 2023, 9:46am UTC](https://discuss.elastic.co/t/how-can-i-delete-documents-3-months-older/335351/4 "2023-06-07T09:46:52Z")

</div>

Absolutely @warkolm! ILM will take care of it for you with regular deletion rather than using `delete_by_query` for a one off. 😄

---

<div class="post-metadata">

**Author:** ![Mary2022](https://avatars.discourse-cdn.com/v4/letter/m/e8c25b/32.png) [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Post date:** [June 7, 2023, 10:38am UTC](https://discuss.elastic.co/t/how-can-i-delete-documents-3-months-older/335351/5 "2023-06-07T10:38:13Z")

</div>

> [@carly.richmond](#):
>
> ```auto
> POST /my-index/_delete_by_query
> {
> "query": {
> "range": {
> "timestamp": {    
> "lte": "2023-004-01T00:00:00", 
> }
> }
> }
> }
> 
> ```

Sorry if I am a little lost but does ILM only apply for new documents?

I use the reindex API to reindex only the results/documents obtained from the API to a new index. Ones that id done I will delete the index.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 7, 2023, 1:41pm UTC](https://discuss.elastic.co/t/how-can-i-delete-documents-3-months-older/335351/6 "2023-06-07T13:41:09Z")

</div>

> [@Mary2022](#):
>
> Sorry if I am a little lost but does ILM only apply for new documents?

It can be applied to older indices as well. Check out [this section of the documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/ilm-with-existing-indices.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2023, 1:41pm UTC](https://discuss.elastic.co/t/how-can-i-delete-documents-3-months-older/335351/7 "2023-07-05T13:41:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
