# How to delete documents older than 10 days - cant use daily indices

**URL:** <https://discuss.elastic.co/t/how-to-delete-documents-older-than-10-days-cant-use-daily-indices/259119>\
**Category:** Elasticsearch\
**Created:** [December 18, 2020, 3:58pm UTC](https://discuss.elastic.co/t/how-to-delete-documents-older-than-10-days-cant-use-daily-indices/259119 "2020-12-18T15:58:59Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jana\_P](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jana_p/32/78578_2.png) [@Jana\_P](https://discuss.elastic.co/u/Jana_P)\
**Post date:** [December 18, 2020, 3:58pm UTC](https://discuss.elastic.co/t/how-to-delete-documents-older-than-10-days-cant-use-daily-indices/259119/1 "2020-12-18T15:58:59Z")

</div>

Hello,  
I'm trying to figure out how to delete documents older than 10 days.  
It sounds simple (curator etc.) - but my situation is quite complicated - I have 3 nodes cluster for DEV logs from about 30 environments.  
So our indexes have names like env01-access, env01-app, env-02-access...because its good for searching in Kibana (nice organized for developers)  
Access logs and app logs have different mappings so it need to be in different indexes. I'm trying to handle the number of shards under 20/1gb heap/node - now there is 315 shards and 150 indices in cluster. Daily there are about 60mio new docs in Elastic.

Now I'm using cron every day, but because of the number of documents it's really bad for performance and some of the cron commands are running for really long time (8 hours).

Example of my cron

```auto
/usr/bin/curl --silent -X POST "localhost:9200/ENV01_app*/_delete_by_query?pretty" -H 'Content-Type: application/json' -d'{"query": {"range": {"@timestamp": {"lte": "now-10d" }}}}' >/dev/null 2>&1

```

Can someone help me to handle this? Because of number of shards I cant use daily indices, so all logs of one type are in one index (ENV01\_access...) - curator can delete only whole index. Is there a easier/better way to do that?  
Thanks

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [December 18, 2020, 4:18pm UTC](https://discuss.elastic.co/t/how-to-delete-documents-older-than-10-days-cant-use-daily-indices/259119/2 "2020-12-18T16:18:05Z")

</div>

use weekly index. then you can keep 14 days data and drop older index. Just a thought.

---

<div class="post-metadata">

**Author:** ![Jana\_P](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jana_p/32/78578_2.png) [@Jana\_P](https://discuss.elastic.co/u/Jana_P)\
**Post date:** [December 18, 2020, 7:47pm UTC](https://discuss.elastic.co/t/how-to-delete-documents-older-than-10-days-cant-use-daily-indices/259119/3 "2020-12-18T19:47:17Z")

</div>

I tried it that way but it's not what i'm looking for. If I will use weekly index, at the end of second week it will generate two (or three) times more shards because of number of ENV and it's not ideal for cluster sizing (now it's 150 indicies/300 shards - 1 shard+1 replica...). Thanks for idea, but I'm looking for better way - if there is any :).

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [December 18, 2020, 8:03pm UTC](https://discuss.elastic.co/t/how-to-delete-documents-older-than-10-days-cant-use-daily-indices/259119/4 "2020-12-18T20:03:19Z")

</div>

You could use [ILM](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-management.html), set rollover to 10 days, and then delete the old index.  
Let's say you have an `env01-app-00001` index. After 10 days ILM will create `env01-app-00002` and uses that for your logs. After that You could delete your old `env01-app-00001` or move it to an archive node(reduce number of primary shards and replicas).

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 18, 2020, 8:53pm UTC](https://discuss.elastic.co/t/how-to-delete-documents-older-than-10-days-cant-use-daily-indices/259119/5 "2020-12-18T20:53:04Z")

</div>

Be aware that the number of shards in relation to heap size is a very general recommendation aimed at avoiding ending up with too many shards. In many cases a higher number will work quite well, so I woúld consider the suggestions around using weekly indices or ILM if even if that increases the shard count a bit.

---

<div class="post-metadata">

**Author:** ![Jana\_P](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jana_p/32/78578_2.png) [@Jana\_P](https://discuss.elastic.co/u/Jana_P)\
**Post date:** [December 18, 2020, 11:01pm UTC](https://discuss.elastic.co/t/how-to-delete-documents-older-than-10-days-cant-use-daily-indices/259119/6 "2020-12-18T23:01:08Z")

</div>

But if I will set rollover to 10 days, I need to keep minimum 20 days until next 10 days will be covered :/. I cant delete old rollover (env01-app-00001) next 10 days, because it will delete whole index, so even if I delete it 5th day, I will only have 5 days of logs in second rollover index (env01-app-0002). The problem is that I need to keep 10 days all the time :(. (and unfortunately no archive/cold node is available)

---

<div class="post-metadata">

**Author:** ![Jana\_P](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jana_p/32/78578_2.png) [@Jana\_P](https://discuss.elastic.co/u/Jana_P)\
**Post date:** [December 18, 2020, 11:13pm UTC](https://discuss.elastic.co/t/how-to-delete-documents-older-than-10-days-cant-use-daily-indices/259119/7 "2020-12-18T23:13:14Z")

</div>

Thanks for info. Our cluster is right now quite overloaded (there are also some "ES unreachable or down"/"collector timed out when collecting data" problems) - that's the reason I'm looking for better solution than cron. I'm quite disappointed that there isn't better way to delete logs to keep exactly 10d (management decision) - in both solutions I need to keep more days.  
Second problem with rollover is that we use Logstash and in es output is ENV variable

```auto
output {
  elasticsearch {
    index => "%{env}_app"
    hosts => ["xxx"]
    template_name => "app_logs"
   }
}

```

and there is no possibility to generate alias dynamically :(.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2021, 11:13pm UTC](https://discuss.elastic.co/t/how-to-delete-documents-older-than-10-days-cant-use-daily-indices/259119/8 "2021-01-15T23:13:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
