# How do I delete logstash data by query

**URL:** <https://discuss.elastic.co/t/how-do-i-delete-logstash-data-by-query/1226>\
**Category:** Elasticsearch\
**Created:** [May 24, 2015, 12:45pm UTC](https://discuss.elastic.co/t/how-do-i-delete-logstash-data-by-query/1226 "2015-05-24T12:45:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bigfootxxl](https://avatars.discourse-cdn.com/v4/letter/b/4af34b/32.png) [@bigfootxxl](https://discuss.elastic.co/u/bigfootxxl)\
**Post date:** [May 24, 2015, 12:45pm UTC](https://discuss.elastic.co/t/how-do-i-delete-logstash-data-by-query/1226/1 "2015-05-24T12:45:03Z")

</div>

Hello. I have some hosts that I need to delete all the syslog data of. So I try the query:  
curl -XGET '[http://log:9200/logstash-2015.05.23/\_query](http://log:9200/logstash-2015.05.23/_query)' -d '{  
"query": {  
"filtered": {  
"query": {  
"bool": {  
"should": [  
{  
"query\_string": {  
"query": "host:vm\*"  
}  
}  
]  
}  
},  
"filter": {  
"bool": {  
"must": [  
{  
"range": {  
"@timestamp": {  
"from": 1420116612709,  
"to": 1432468230716  
}  
}  
}  
]  
}  
}  
}  
}  
}'

That gives me  
"took" : 63,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 5,  
"successful" : 5,  
"failed" : 0  
},  
"hits" : {  
"total" : 2365117,

etc. some output. So I figure it got something and then I replace the XGET by XDELETE but it gives me:  
{"error":"ElasticsearchIllegalArgumentException[No feature for name [\_query]]","status":400}

Sorry if this a stupid question but I'm completely new to this stuff. How do I delete all the data from hosts host:vm\* ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 24, 2015, 2:33pm UTC](https://discuss.elastic.co/t/how-do-i-delete-logstash-data-by-query/1226/2 "2015-05-24T14:33:27Z")

</div>

On which version?

It should work fine: [https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-delete-by-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-delete-by-query.html)

Are you really running that from the command line using `curl`?

---

<div class="post-metadata">

**Author:** ![bigfootxxl](https://avatars.discourse-cdn.com/v4/letter/b/4af34b/32.png) [@bigfootxxl](https://discuss.elastic.co/u/bigfootxxl)\
**Post date:** [May 25, 2015, 6:50am UTC](https://discuss.elastic.co/t/how-do-i-delete-logstash-data-by-query/1226/3 "2015-05-25T06:50:16Z")

</div>

yes from command line. I have vresion 1.4.4. but I have 1.4.5 available through yum. Or will I need 1.5+?  
Secondly: would the the upgrade work if I just add the 1.5 yum repo ([https://www.elastic.co/guide/en/elasticsearch/reference/current/setup-repositories.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/setup-repositories.html)) and give the yum upgrade command?

---

<div class="post-metadata">

**Author:** ![bigfootxxl](https://avatars.discourse-cdn.com/v4/letter/b/4af34b/32.png) [@bigfootxxl](https://discuss.elastic.co/u/bigfootxxl)\
**Post date:** [May 26, 2015, 8:39am UTC](https://discuss.elastic.co/t/how-do-i-delete-logstash-data-by-query/1226/4 "2015-05-26T08:39:53Z")

</div>

I did upgrade to latest 1.5.2 but this method still did not work.... but I got this working: [https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-delete-by-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-delete-by-query.html)

and the key was not to use '\*' in searches!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:11am UTC](https://discuss.elastic.co/t/how-do-i-delete-logstash-data-by-query/1226/5 "2017-07-06T00:11:55Z")

</div>


