# How To delete/migrate old data from an index

**URL:** <https://discuss.elastic.co/t/how-to-delete-migrate-old-data-from-an-index/77210>\
**Category:** Elasticsearch\
**Created:** [March 2, 2017, 7:36pm UTC](https://discuss.elastic.co/t/how-to-delete-migrate-old-data-from-an-index/77210 "2017-03-02T19:36:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrognone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrognone/32/16034_2.png) [@mrognone](https://discuss.elastic.co/u/mrognone)\
**Post date:** [March 2, 2017, 7:36pm UTC](https://discuss.elastic.co/t/how-to-delete-migrate-old-data-from-an-index/77210/1 "2017-03-02T19:36:56Z")

</div>

Hi people !

My situation: I have 2 logstash-forwarders sending network devices logs to an ELK server. In the past I did create the needed indexes based on time ( YYYY+MM+DD), but I detected that the performance of the server goes down with this config, and i changed it to static indexes, the performance problem was resolved with this change.

But, now i have big indexes on the elk server and i need retrieve data from them to migrate or delete it.  
at the momment i was deleting the indexes and start them again from the scratch , but i want to have capability and the knowledge to select a specific info from an index and make different actions with it.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [March 2, 2017, 10:58pm UTC](https://discuss.elastic.co/t/how-to-delete-migrate-old-data-from-an-index/77210/2 "2017-03-02T22:58:44Z")

</div>

Two routes you could take:

- Reindex has a ["Reindex from Remote"](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html#reindex-from-remote) functionality, that basically streams the data from one index to another on a different cluster. That will give you the flexibility to only select some data, subsets, certain types, etc

- If you just want everything, [Snapshot and Restore](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-snapshots.html) would be faster. But it's less flexible in what it can capture (e.g. it'll grab entire indices)

---

<div class="post-metadata">

**Author:** ![mrognone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrognone/32/16034_2.png) [@mrognone](https://discuss.elastic.co/u/mrognone)\
**Post date:** [March 20, 2017, 1:07pm UTC](https://discuss.elastic.co/t/how-to-delete-migrate-old-data-from-an-index/77210/3 "2017-03-20T13:07:52Z")

</div>

Hi @polyfractal, how are you ??

Thanks for your answer and sorry for take so much time to come back to this topic.

Is possible perform the same operation than " Reindex From Remote" but delete the data directly and not migrate it to another cluster ?  
Is not my intention migrate the info, just delete it, but keeping the last 3 months.

Thanks In advance.

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [March 21, 2017, 3:09pm UTC](https://discuss.elastic.co/t/how-to-delete-migrate-old-data-from-an-index/77210/4 "2017-03-21T15:09:28Z")

</div>

You can reindex into the same cluster, which allows you to move data from one index to another. You can then delete the old index if you want, or run a DeleteByQuery, etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 18, 2017, 3:09pm UTC](https://discuss.elastic.co/t/how-to-delete-migrate-old-data-from-an-index/77210/5 "2017-04-18T15:09:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
