# \### i delete one index of yesterday,but 8 hours data of today is gone! help me pls

**URL:** <https://discuss.elastic.co/t/i-delete-one-index-of-yesterday-but-8-hours-data-of-today-is-gone-help-me-pls/83152>\
**Category:** Elasticsearch\
**Created:** [April 21, 2017, 6:33am UTC](https://discuss.elastic.co/t/i-delete-one-index-of-yesterday-but-8-hours-data-of-today-is-gone-help-me-pls/83152 "2017-04-21T06:33:16Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![nwpu.yangqing](https://avatars.discourse-cdn.com/v4/letter/n/9fc29f/32.png) [@nwpu.yangqing](https://discuss.elastic.co/u/nwpu.yangqing)\
**Post date:** [April 21, 2017, 6:33am UTC](https://discuss.elastic.co/t/i-delete-one-index-of-yesterday-but-8-hours-data-of-today-is-gone-help-me-pls/83152/1 "2017-04-21T06:33:16Z")

</div>

【replay angin】

1、first，check my indices before i do any detele operations

> % curl -XGET '172.18.102.5:9200/\_cat/indices/migu\_csms\_debug\*'  
> green open migu\_csms\_debug-2017-04-20 SlGTE1A0TWSDerSuwDs0rA 5 1 273033 0 236.3mb 118.2mb  
> green open migu\_csms\_debug-2017-04-21 gxl3wmLORdiISZXq16PNHA 5 1 26845 0 28.5mb 14.2mb
> 
> ![](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a05a57945aa7e127a8f5468bcb740c201eb7312a.jpg)  
> 2、then i delete the index migu\_csms\_debug-2017-04-20  
> [kibana@MGHJ-YW-mg-web05 ~]$ curl -XDELETE '[http://172.18.102.5:9200/migu\_csms\_debug-2017-04-20?pretty](http://172.18.102.5:9200/migu_csms_debug-2017-04-20?pretty)'  
> {  
> "acknowledged" : true  
> }

3、look into kibana again

 ![](https://us1.discourse-cdn.com/elastic/original/3X/1/2/12087373b836159120b011b1ec969c7844b90640.jpg)

As you can see,some (exactly 8 hours) data of today is gone.  
i don't know why,and doubt sth is wrong elasticsearch node

pls help me!!  
thk you very much from China!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 21, 2017, 6:45am UTC](https://discuss.elastic.co/t/i-delete-one-index-of-yesterday-but-8-hours-data-of-today-is-gone-help-me-pls/83152/2 "2017-04-21T06:45:30Z")

</div>

Time-based indices generated by Logstash are based on UTC time. Each index will therefore not necessarily contain a full days of data in the time zone you are in. If you create an index pattern just matching a single index, you would be able to see this in Kibana.

---

<div class="post-metadata">

**Author:** ![nwpu.yangqing](https://avatars.discourse-cdn.com/v4/letter/n/9fc29f/32.png) [@nwpu.yangqing](https://discuss.elastic.co/u/nwpu.yangqing)\
**Post date:** [April 21, 2017, 7:00am UTC](https://discuss.elastic.co/t/i-delete-one-index-of-yesterday-but-8-hours-data-of-today-is-gone-help-me-pls/83152/4 "2017-04-21T07:00:26Z")

</div>

I wrote a shell to delete historical indices automatically,as follws:

[kibana@MGHJ-YW-mg-web05 shell]$ more del\_index.sh  
#!/bin/bash  
source ~/.bash\_profile  
del\_date=`date -d "4 days ago" +%Y-%m-%d`  
curl -XDELETE ''[http://172.18.102.5:9200/migu\_csms\_debug-${del\_date}?pretty](http://172.18.102.5:9200/migu_csms_debug-%24%7Bdel_date%7D?pretty)''

so ,how could i modify it to delete a precise day's data?not +8(-8) hours?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 21, 2017, 7:10am UTC](https://discuss.elastic.co/t/i-delete-one-index-of-yesterday-but-8-hours-data-of-today-is-gone-help-me-pls/83152/5 "2017-04-21T07:10:28Z")

</div>

Retention is generally managed by deleting entire indices, as this is much more efficient than deleting records individually from an index. You could keep an extra days worth of indices, which would ensure the full time period is covered or possibly modify the index naming in Logstash and override the default to get a date based on your time zone.

---

<div class="post-metadata">

**Author:** ![nwpu.yangqing](https://avatars.discourse-cdn.com/v4/letter/n/9fc29f/32.png) [@nwpu.yangqing](https://discuss.elastic.co/u/nwpu.yangqing)\
**Post date:** [April 21, 2017, 7:20am UTC](https://discuss.elastic.co/t/i-delete-one-index-of-yesterday-but-8-hours-data-of-today-is-gone-help-me-pls/83152/6 "2017-04-21T07:20:03Z")

</div>

**thk you for your replies.**

**if i add config belows into my logstash\_config file,would it help?**  
date {  
timezone =\> "Asia/Shanghai"  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 21, 2017, 7:25am UTC](https://discuss.elastic.co/t/i-delete-one-index-of-yesterday-but-8-hours-data-of-today-is-gone-help-me-pls/83152/7 "2017-04-21T07:25:29Z")

</div>

Kibana and Elasticsearch require/assume that the timestamp is is UTC, so changing this to something else will cause problems. A better way may be to parse the raw event date and use this to build the index name for the elastic search output.

---

<div class="post-metadata">

**Author:** ![nwpu.yangqing](https://avatars.discourse-cdn.com/v4/letter/n/9fc29f/32.png) [@nwpu.yangqing](https://discuss.elastic.co/u/nwpu.yangqing)\
**Post date:** [April 21, 2017, 7:41am UTC](https://discuss.elastic.co/t/i-delete-one-index-of-yesterday-but-8-hours-data-of-today-is-gone-help-me-pls/83152/8 "2017-04-21T07:41:10Z")

</div>

Thank you for all your assistance. 🙂

As you'd advised,i decide to keep it a bit longer time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2017, 7:50am UTC](https://discuss.elastic.co/t/i-delete-one-index-of-yesterday-but-8-hours-data-of-today-is-gone-help-me-pls/83152/9 "2017-05-19T07:50:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
