# How to delete logs from index which came from a particular IP?

**URL:** <https://discuss.elastic.co/t/how-to-delete-logs-from-index-which-came-from-a-particular-ip/118306>\
**Category:** Elasticsearch\
**Created:** [February 3, 2018, 10:25am UTC](https://discuss.elastic.co/t/how-to-delete-logs-from-index-which-came-from-a-particular-ip/118306 "2018-02-03T10:25:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikhil\_Jaiswal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_jaiswal/32/39326_2.png) [@Nikhil\_Jaiswal](https://discuss.elastic.co/u/Nikhil_Jaiswal)\
**Post date:** [February 3, 2018, 10:25am UTC](https://discuss.elastic.co/t/how-to-delete-logs-from-index-which-came-from-a-particular-ip/118306/1 "2018-02-03T10:25:39Z")

</div>

Hi folks,

I need to delete logs from elasticsearch which came from a particular IP, i ran below query in sense to delete those logs.

```
POST logstash-*/_delete_by_query
{
   "query": {
     "match_phrase": {
       "src_ip": "10.10.20.91"
     }
   }
}

```

and i got below output:

```
"deleted": 368, 

```

But i am still able to see logs in kibana.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 3, 2018, 10:54am UTC](https://discuss.elastic.co/t/how-to-delete-logs-from-index-which-came-from-a-particular-ip/118306/2 "2018-02-03T10:54:58Z")

</div>

What is the output of:

```auto
GET logstash-*/_search
{
   "query": {
     "match_phrase": {
       "src_ip": "10.10.20.91"
     }
   }
}

```

---

<div class="post-metadata">

**Author:** ![Nikhil\_Jaiswal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_jaiswal/32/39326_2.png) [@Nikhil\_Jaiswal](https://discuss.elastic.co/u/Nikhil_Jaiswal)\
**Post date:** [February 3, 2018, 11:10am UTC](https://discuss.elastic.co/t/how-to-delete-logs-from-index-which-came-from-a-particular-ip/118306/3 "2018-02-03T11:10:50Z")

</div>

> [@dadoonet](#):
>
> GET logstash-\*/\_search  
> {  
> "query": {  
> "match\_phrase": {  
> "src\_ip": "10.10.20.91"  
> }  
> }  
> }

Output:

```auto
    {
 "took": 112,

   "timed_out": false,
   "_shards": {
      "total": 470,
      "successful": 220,
      "failed": 0
   },
   "hits": {
      "total": 0,
      "max_score": null,
      "hits": []
   }
}
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 3, 2018, 11:17am UTC](https://discuss.elastic.co/t/how-to-delete-logs-from-index-which-came-from-a-particular-ip/118306/4 "2018-02-03T11:17:43Z")

</div>

Please format your code using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

Please edit your post. (I edited your first post but please edit your response)

You don't have any result anymore for this query. Could you check what is the query sent by kibana? I believe it's something different. May be post a screenshot of what Kibana is displaying?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2018, 11:18am UTC](https://discuss.elastic.co/t/how-to-delete-logs-from-index-which-came-from-a-particular-ip/118306/5 "2018-03-03T11:18:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
