# How to find rolled indices Eligible to Shrink programmatically

**URL:** <https://discuss.elastic.co/t/how-to-find-rolled-indices-eligible-to-shrink-programmatically/166912>\
**Category:** Elasticsearch\
**Created:** [February 4, 2019, 7:39am UTC](https://discuss.elastic.co/t/how-to-find-rolled-indices-eligible-to-shrink-programmatically/166912 "2019-02-04T07:39:36Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eduardo](https://avatars.discourse-cdn.com/v4/letter/e/6a8cbe/32.png) [@Eduardo](https://discuss.elastic.co/u/Eduardo)\
**Post date:** [February 4, 2019, 7:39am UTC](https://discuss.elastic.co/t/how-to-find-rolled-indices-eligible-to-shrink-programmatically/166912/1 "2019-02-04T07:39:36Z")

</div>

Trying to use curator to shrink any indices that have been rolled nightly. Any way to use the filtering in curator to identify a rolled index? I believe is\_write\_index is set to false but I'm having trouble finding that via Curator filters or API.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [February 4, 2019, 2:02pm UTC](https://discuss.elastic.co/t/how-to-find-rolled-indices-eligible-to-shrink-programmatically/166912/2 "2019-02-04T14:02:31Z")

</div>

That's a relatively new thing, and hasn't been added to Curator yet. Not all versions of Elasticsearch support that flag. Certainly not all the ones that the current Curator release supports.

At any rate, it's been added as an issue already: [https://github.com/elastic/curator/issues/1358](https://github.com/elastic/curator/issues/1358)

---

<div class="post-metadata">

**Author:** ![Eduardo](https://avatars.discourse-cdn.com/v4/letter/e/6a8cbe/32.png) [@Eduardo](https://discuss.elastic.co/u/Eduardo)\
**Post date:** [February 4, 2019, 2:19pm UTC](https://discuss.elastic.co/t/how-to-find-rolled-indices-eligible-to-shrink-programmatically/166912/3 "2019-02-04T14:19:18Z")

</div>

That makes sense. How else have you seen people identify their rolled indices for shrinking via Curator?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [February 4, 2019, 2:51pm UTC](https://discuss.elastic.co/t/how-to-find-rolled-indices-eligible-to-shrink-programmatically/166912/4 "2019-02-04T14:51:52Z")

</div>

First use the `pattern` filter to select only indices matching your rollover index pattern. Then, use the `alias` filter with the `exclude` option to select indices not associated with the rollover alias.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [February 4, 2019, 3:25pm UTC](https://discuss.elastic.co/t/how-to-find-rolled-indices-eligible-to-shrink-programmatically/166912/5 "2019-02-04T15:25:18Z")

</div>

For example:

```auto
actions:
  1:
    action: shrink
    description: Shrink rolled indices
    options:
      # ...
    filters:
    - filtertype: pattern
      kind: prefix
      value: indexpattern-
    - filtertype: alias
      aliases: myrolloveralias
      exclude: true

```

---

<div class="post-metadata">

**Author:** ![Eduardo](https://avatars.discourse-cdn.com/v4/letter/e/6a8cbe/32.png) [@Eduardo](https://discuss.elastic.co/u/Eduardo)\
**Post date:** [February 4, 2019, 8:55pm UTC](https://discuss.elastic.co/t/how-to-find-rolled-indices-eligible-to-shrink-programmatically/166912/6 "2019-02-04T20:55:22Z")

</div>

EDIT:  
Nevermind, I think the right approach is to first execute a shrink process and if I want to execute a re-allocation of any indices that have been shrunk I can utilize a allocation job. Thanks again, works like a charm.

ORIGINAL:  
This worked great, thanks!! I think I am having some confusion though with the shrink\_node: field. My setup consists of 2 nodes for testing, 1 box\_type hot, 1 box\_type cold. The idea is all writes will occur on the hot based on index template routing and the shrink target will always go to the cold. However, I am finding that if I set shrink\_node to DETERMINISTIC that in the log output 2019-02-04 20:47:03,138 INFO Moving shards to shrink node: "hot-box" yet, the new index will be created on the "cold-box". This is great, as my goal is for all shrinks to be on the cold box, but I find that once the amount of data on the cold box exceeds the hot-box, the shrink indices will be created on the hot-box. The problem is when I set shrink\_node explicitly to "cold-box" it fails with the error that Failed to complete action: shrink. &lt;class 'curator.exceptions.FailedExecution'&gt;: Exception encountered. Rerun with loglevel DEBUG and/or check Elasticsearch logs for more information. Exception: Unable to shrink index "test-tooling-000004" as not all shards were found on the designated shrink node (cold-box): .

This just seems really odd, because when DETERMINISTIC is set and the data is lower the cold-box is able to allow for the shrink to occur and land the index on it, but when set explicitly this exception is thrown :(. Am I misunderstanding the purpose of the shrink\_node value?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 4, 2019, 8:55pm UTC](https://discuss.elastic.co/t/how-to-find-rolled-indices-eligible-to-shrink-programmatically/166912/7 "2019-03-04T20:55:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
