# How to delete all entries based on the contents of two fields

**URL:** <https://discuss.elastic.co/t/how-to-delete-all-entries-based-on-the-contents-of-two-fields/17820>\
**Category:** Elasticsearch\
**Created:** [May 29, 2014, 11:28pm UTC](https://discuss.elastic.co/t/how-to-delete-all-entries-based-on-the-contents-of-two-fields/17820 "2014-05-29T23:28:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [May 29, 2014, 11:28pm UTC](https://discuss.elastic.co/t/how-to-delete-all-entries-based-on-the-contents-of-two-fields/17820/1 "2014-05-29T23:28:25Z")

</div>

I imported a LOT of apache logs the other day. Via Logstash. 'Course, I  
messed up and didn't set the timestamp correctly. Now that I've figured out  
how to set the timestamp correctly, I want to remove the logs I imported.

For the life of me I can't figure it out.

I've been looking  
at [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/0.90/docs-delete-by-query.html#docs-delete-by-query)  
(Yes, I'm running 0.90.9) to figure out what to do, but I'm obviously  
missing something....

This is what I've tried so far:.

curl -XDELETE '[http://node01.domain.tld:9200/logstash-2014.05.27/\_query](http://node01.domain.tld:9200/logstash-2014.05.27/_query)' -d

> '{  
> "query": {  
> "filtered" : {  
> "query" : {  
> "query\_string" : {  
> "query" : "message:"_subdomain.main.tld_" AND  
> host:"hostimportedon""  
> }  
> }  
> }  
> }  
> }  
> '

the results:

{"ok":true,"\_indices":{"logstash-2014.05.27":{"\_shards":{"total":5,"successful":0,"failed":5}}}}

So, how would I delete something based on two criteria? The host field  
matches "hostimportedon" and the messaged field has "subdomain.main.tld" in  
it.

I have a total of 4 elasticsearch nodes.

Thanks!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/5fb3ec86-76b3-4536-9605-6774784f9d31%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/5fb3ec86-76b3-4536-9605-6774784f9d31%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [May 30, 2014, 7:20pm UTC](https://discuss.elastic.co/t/how-to-delete-all-entries-based-on-the-contents-of-two-fields/17820/2 "2014-05-30T19:20:53Z")

</div>

With some tips from whack in the #logstash irc channel, I was able to  
delete what I wanted with this:

curl -XDELETE '[http://node1:9200/logstash-2014.05.27/\_query](http://node1:9200/logstash-2014.05.27/_query)' -d '{

> ```
> "query_string" : {
> "query" : "path:\"folderLogFileLoadedFrom\""
> }
> 
> ```
> 
> }  
> '

On Thursday, May 29, 2014 4:28:25 PM UTC-7, David Reagan wrote:

> I imported a LOT of apache logs the other day. Via Logstash. 'Course, I  
> messed up and didn't set the timestamp correctly. Now that I've figured out  
> how to set the timestamp correctly, I want to remove the logs I imported.
> 
> For the life of me I can't figure it out.
> 
> I've been looking at  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/0.90/docs-delete-by-query.html#docs-delete-by-query)  
> (Yes, I'm running 0.90.9) to figure out what to do, but I'm obviously  
> missing something....
> 
> This is what I've tried so far:.
> 
> curl -XDELETE '[http://node01.domain.tld:9200/logstash-2014.05.27/\_query](http://node01.domain.tld:9200/logstash-2014.05.27/_query)'
> 
> > -d '{  
> > "query": {  
> > "filtered" : {  
> > "query" : {  
> > "query\_string" : {  
> > "query" : "message:"_subdomain.main.tld_" AND  
> > host:"hostimportedon""  
> > }  
> > }  
> > }  
> > }  
> > }  
> > '
> 
> the results:
> 
> > {"ok":true,"\_indices":{"logstash-2014.05.27":{"\_shards":{"total":5,"successful":0,"failed":5}}}}
> 
> So, how would I delete something based on two criteria? The host field  
> matches "hostimportedon" and the messaged field has "subdomain.main.tld" in  
> it.
> 
> I have a total of 4 elasticsearch nodes.
> 
> Thanks!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/eacf7664-f662-4a5b-8bbf-29145e85ee36%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/eacf7664-f662-4a5b-8bbf-29145e85ee36%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:25am UTC](https://discuss.elastic.co/t/how-to-delete-all-entries-based-on-the-contents-of-two-fields/17820/3 "2017-07-06T01:25:41Z")

</div>


