# How to DELETE logs from elasticsearch index which are older then 90 days?

**URL:** <https://discuss.elastic.co/t/how-to-delete-logs-from-elasticsearch-index-which-are-older-then-90-days/166125>\
**Category:** Elasticsearch\
**Created:** [January 29, 2019, 9:47am UTC](https://discuss.elastic.co/t/how-to-delete-logs-from-elasticsearch-index-which-are-older-then-90-days/166125 "2019-01-29T09:47:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vinit\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinit_kumar/32/74784_2.png) [@Vinit\_Kumar](https://discuss.elastic.co/u/Vinit_Kumar)\
**Post date:** [January 29, 2019, 9:47am UTC](https://discuss.elastic.co/t/how-to-delete-logs-from-elasticsearch-index-which-are-older-then-90-days/166125/1 "2019-01-29T09:47:39Z")

</div>

Is it possible to delete logs from elasticsearch index which are older than 3 months?

`NOTE:` I don't want to create daily based or monthly based index and but want only one index and want to delete 3-month-old data inside that index based on timestamps.

Does anybody have any idea how to delete data after three months automatically?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 29, 2019, 10:02am UTC](https://discuss.elastic.co/t/how-to-delete-logs-from-elasticsearch-index-which-are-older-then-90-days/166125/2 "2019-01-29T10:02:59Z")

</div>

> [@Vinit\_Kumar](#):
>
> I don't want to create daily based or monthly based index and but want only one index and want to delete 3-month-old data inside that index based on timestamps.

As long as you know this is really inefficient and absolutely not what is recommended by elastic, you can do whatever you want. 😊  
I just want to make sure you know what you are doing.

> Does anybody have any idea how to delete data after three months?

Use the Delete By Query API: [Delete by query API | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-delete-by-query.html)

> Does anybody have any idea how to delete data after three months **automatically**?

Add this query in a crontab or something like this to run it everyday for example.

---

<div class="post-metadata">

**Author:** ![Vinit\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinit_kumar/32/74784_2.png) [@Vinit\_Kumar](https://discuss.elastic.co/u/Vinit_Kumar)\
**Post date:** [January 29, 2019, 10:08am UTC](https://discuss.elastic.co/t/how-to-delete-logs-from-elasticsearch-index-which-are-older-then-90-days/166125/3 "2019-01-29T10:08:07Z")

</div>

Hi @dadoonet,

Thank you so much for replying. It's deleting the data as I want but I'm doing hard code the the timestemp column as given below.

```
POST metricbeat-system-monitor/_delete_by_query
{
"query": {
"range" : {
"@timestamp" : {
"gte" : "01/27/2019",
"lte" : "01/29/2019",
"format": "MM/dd/yyyy||yyyy"
}
}
}
} 

```

@dadoonet, Could you please suggest me the better way to maintain the 3-month historical data so that I can compare historical data to current data.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 29, 2019, 10:21am UTC](https://discuss.elastic.co/t/how-to-delete-logs-from-elasticsearch-index-which-are-older-then-90-days/166125/4 "2019-01-29T10:21:50Z")

</div>

> [@Vinit\_Kumar](#):
>
> It's deleting the data as I want but I'm doing hard code the the timestemp column as given below.

Is it a question?

> [@Vinit\_Kumar](#):
>
> Could you please suggest me the better way to maintain the 3-month historical data so that I can compare historical data to current data.

Not sure I understood the question.  
To manage time series data with a retention period the solution is to use time based indices. But you said that you don't want this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2019, 10:21am UTC](https://discuss.elastic.co/t/how-to-delete-logs-from-elasticsearch-index-which-are-older-then-90-days/166125/5 "2019-02-26T10:21:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
