# How many old indices I should have for ElasticSearch?

**URL:** <https://discuss.elastic.co/t/how-many-old-indices-i-should-have-for-elasticsearch/31595>\
**Category:** Elasticsearch\
**Created:** [October 4, 2015, 4:54pm UTC](https://discuss.elastic.co/t/how-many-old-indices-i-should-have-for-elasticsearch/31595 "2015-10-04T16:54:24Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![anujaggarwal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anujaggarwal/32/81418_2.png) [@anujaggarwal](https://discuss.elastic.co/u/anujaggarwal)\
**Post date:** [October 4, 2015, 4:54pm UTC](https://discuss.elastic.co/t/how-many-old-indices-i-should-have-for-elasticsearch/31595/1 "2015-10-04T16:54:24Z")

</div>

I am using ElasticSearch with mainly default configuration and noticed recently that my old indices are eating too much space. I believe they are being created automatically because of default configuration since I have not done any such configuration. Please help me with:

- how many old indices I should generally keep?
- does my today's search use index created yesterday?
- can I live with just one index copy and reuse the same every time?
- what purpose old indices serve?
- where is the setting because of which new indices are getting created automatically every day?

Since ES is running on a Production server, I simply cannot delete old indices hence need expert advice. Thanks.

PS: SO link for this question: [http://stackoverflow.com/questions/32933087/how-many-old-indices-i-should-have-for-elasticsearch](http://stackoverflow.com/questions/32933087/how-many-old-indices-i-should-have-for-elasticsearch)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 4, 2015, 5:46pm UTC](https://discuss.elastic.co/t/how-many-old-indices-i-should-have-for-elasticsearch/31595/2 "2015-10-04T17:46:43Z")

</div>

Are you using time-series indexes created by e.g. Logstash? Or what are these "old indexes" you speak of? Please explain what kind of data you're storing and how it's submitted into ES.

---

<div class="post-metadata">

**Author:** ![anujaggarwal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anujaggarwal/32/81418_2.png) [@anujaggarwal](https://discuss.elastic.co/u/anujaggarwal)\
**Post date:** [October 4, 2015, 6:08pm UTC](https://discuss.elastic.co/t/how-many-old-indices-i-should-have-for-elasticsearch/31595/3 "2015-10-04T18:08:09Z")

</div>

I am seeing multiple index folders in "/var/lib/elasticsearch/elasticsearch/nodes/0/indices/" folder:

.marvel-2015.09.08/ .marvel-2015.09.16/ .marvel-2015.09.24/ .marvel-2015.10.02/  
.marvel-2015.09.01/ .marvel-2015.09.09/ .marvel-2015.09.17/ .marvel-2015.09.25/ .marvel-2015.10.03/  
.marvel-2015.09.02/ .marvel-2015.09.10/ .marvel-2015.09.18/ .marvel-2015.09.26/ .marvel-2015.10.04/  
.marvel-2015.09.03/ .marvel-2015.09.11/ .marvel-2015.09.19/ .marvel-2015.09.27/ .marvel-kibana/  
.marvel-2015.09.04/ .marvel-2015.09.12/ .marvel-2015.09.20/ .marvel-2015.09.28/  
.marvel-2015.09.05/ .marvel-2015.09.13/ .marvel-2015.09.21/ .marvel-2015.09.29/  
.marvel-2015.09.06/ .marvel-2015.09.14/ .marvel-2015.09.22/ .marvel-2015.09.30/  
.marvel-2015.09.07/ .marvel-2015.09.15/ .marvel-2015.09.23/ .marvel-2015.10.01/

They still collectively eat 11GB after I deleted folders specific to the August month.

I am storing textual records (2000 only currently) in the index which are inserted/updated/deleted through CodeIgniter ES library. CodeIgniter config is as follows:

```
$param = array(
    'connectionClass' => '\Elasticsearch\Connections\GuzzleConnection',
    'connectionFactoryClass'=> '\Elasticsearch\Connections\ConnectionFactory',
    'connectionPoolClass' => '\Elasticsearch\ConnectionPool\StaticNoPingConnectionPool',
    'selectorClass' => '\Elasticsearch\ConnectionPool\Selectors\RoundRobinSelector',
    'serializerClass' => '\Elasticsearch\Serializers\SmartSerializer',
    'sniffOnStart' => false,
    'connectionParams' => array(),
    'logging' => false,
    'logObject' => null,
    'logPath' => 'elasticsearch.log',
    
    'traceObject' => null,
    'tracePath' => 'elasticsearch.log',

    'guzzleOptions' => array(),
    'connectionPoolParams' => array(
        'randomizeHosts' => true
    ),
    'retries' => null
);
$params['logging'] = true;
$params['logPath'] = '/var/log/elasticsearch/elasticsearch.log';
$params['logPermission'] = 0664;

$client = new Elasticsearch\Client($params);

```

I don't use Logstash and don't know why the indices are getting created automatically every day. I could not find any such setting in my config files.

Thanks for your reply.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 4, 2015, 6:20pm UTC](https://discuss.elastic.co/t/how-many-old-indices-i-should-have-for-elasticsearch/31595/4 "2015-10-04T18:20:40Z")

</div>

Oh, Marvel indexes. That's Elasticsearch performance metrics stored by the Marvel add-on. You only need to keep those indexes for as long as you need the data for performance analysis or whatever it is that you use them for. Create a cron job that calls [Curator](https://github.com/elastic/curator) to delete indexes after they reach a certain age.

---

<div class="post-metadata">

**Author:** ![anujaggarwal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anujaggarwal/32/81418_2.png) [@anujaggarwal](https://discuss.elastic.co/u/anujaggarwal)\
**Post date:** [October 4, 2015, 6:58pm UTC](https://discuss.elastic.co/t/how-many-old-indices-i-should-have-for-elasticsearch/31595/5 "2015-10-04T18:58:13Z")

</div>

Ohh, I got it now. I was always wondering why my tiny dataset is taking space in GBs.

I deleted all marvel indices and turned off logging as well by adding this my .yml file:

> marvel.agent.enabled = false

Thanks for saving my day and all your support.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 5, 2015, 3:27am UTC](https://discuss.elastic.co/t/how-many-old-indices-i-should-have-for-elasticsearch/31595/6 "2015-10-05T03:27:07Z")

</div>

Never delete indices from the FS like that, always use a delete call via the API.

---

<div class="post-metadata">

**Author:** ![anujaggarwal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anujaggarwal/32/81418_2.png) [@anujaggarwal](https://discuss.elastic.co/u/anujaggarwal)\
**Post date:** [October 5, 2015, 4:28am UTC](https://discuss.elastic.co/t/how-many-old-indices-i-should-have-for-elasticsearch/31595/7 "2015-10-05T04:28:23Z")

</div>

Yes, I know that. I have deleted old indices using the DELETE call only.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 5, 2015, 4:29am UTC](https://discuss.elastic.co/t/how-many-old-indices-i-should-have-for-elasticsearch/31595/8 "2015-10-05T04:29:10Z")

</div>

Great! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:46pm UTC](https://discuss.elastic.co/t/how-many-old-indices-i-should-have-for-elasticsearch/31595/9 "2017-07-05T23:46:50Z")

</div>


