# Index don't want deleted automatically

**URL:** <https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [May 25, 2022, 4:51am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554 "2022-05-25T04:51:54Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 25, 2022, 4:51am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/1 "2022-05-25T04:51:54Z")

</div>

Hi there,

i wanna ask about index and retention. so here is the question

in my Elasticsearch i have created index automatically and give them policy to go away after 5 days. the problem is they don't want to be deleted automatically. when i check GET \_cat/indices?v I can still see the index from 5 months ago. What do you think caused the incident?. please let me know, your help will mean a lot. thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 25, 2022, 4:57am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/2 "2022-05-25T04:57:05Z")

</div>

Please share your ILM policy and an explain on it as well.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 25, 2022, 5:05am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/3 "2022-05-25T05:05:27Z")

</div>

![data1](https://us1.discourse-cdn.com/elastic/original/3X/3/0/30f7aea287dbc26aaba298edf6e573adf9464c97.png)  
 ![data2](https://us1.discourse-cdn.com/elastic/original/3X/e/a/ea1656a5cde0b73e6948bf9216f7385b55b02183.png)

i just enabled the delete phase. and the other i disabled it

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 25, 2022, 5:09am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/4 "2022-05-25T05:09:12Z")

</div>

FYI i use elastic 7.7.1

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 25, 2022, 5:18am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/5 "2022-05-25T05:18:57Z")

</div>

7.7 is [EOL](https://www.elastic.co/support/eol) and you need to upgrade as a matter of urgency.

I know there was also a bug in older versions where it wouldn't properly set the delete, so upgrading will rule that out.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 25, 2022, 7:33am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/6 "2022-05-25T07:33:37Z")

</div>

can you give me bug reference? so that there is concrete evidence so i can give it to my team

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 25, 2022, 8:08am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/7 "2022-05-25T08:08:32Z")

</div>

> <https://github.com/elastic/kibana/issues/84442>
>
> Kibana version:7.10.0
> Elasticsearch version:7.10.0
> Describe the bug:
> Create a… new policy, activate the delete phase, but the delete action in the generated json request is empty
> !\[image\](https://user-images.githubusercontent.com/24800419/100407077-6c047a00-30a2-11eb-8adb-a08aa926e13d.png)

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 25, 2022, 8:23am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/8 "2022-05-25T08:23:11Z")

</div>

Thank you very much

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 25, 2022, 8:40am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/9 "2022-05-25T08:40:26Z")

</div>

How about 7.17? is this bug still exist?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 25, 2022, 8:58am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/10 "2022-05-25T08:58:11Z")

</div>

No, there it is fixed. 7.17 is the version I would recommend you upgrade to.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 25, 2022, 9:16am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/11 "2022-05-25T09:16:15Z")

</div>

hmmm i don't think so. my team already install 7.17 version about 2 months with retention: 5 days too. but index from a month before still exist  
 ![gambar](https://us1.discourse-cdn.com/elastic/original/3X/a/f/afb9374c450ade06223ef2eeeeaa214617bfad49.png)

 ![gambar](https://us1.discourse-cdn.com/elastic/original/3X/0/0/00c454a5d229de4e59e367575165c2c7e04519ca.png)

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 25, 2022, 9:22am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/12 "2022-05-25T09:22:17Z")

</div>

any suggest?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 25, 2022, 9:28am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/13 "2022-05-25T09:28:04Z")

</div>

What does the `5-days-default` lifecycle policy look like? The fix I linked to was related to how Kibana creates ILM policies. If you have created it using old version or manually you might still have an incorrect policy in place.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 25, 2022, 10:17am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/14 "2022-05-25T10:17:09Z")

</div>

Here is 5-days-default policy look like

```auto
{
  "5-days-default" : {
    "version" : 1,
    "modified_date" : "2022-05-18T02:18:13.088Z",
    "policy" : {
      "phases" : {
        "hot" : {
          "min_age" : "0ms",
          "actions" : {
            "rollover" : {
              "max_primary_shard_size" : "50gb",
              "max_age" : "30d"
            },
            "set_priority" : {
              "priority" : 100
            }
          }
        },
        "delete" : {
          "min_age" : "5d",
          "actions" : {
            "delete" : {
              "delete_searchable_snapshot" : true
            }
          }
        }
      }
    },
    "in_use_by" : {
      "indices" : [
"much index......"
      ],
      "data_streams" : [],
      "composable_templates" : [
        "metric_ocp4_prod_esb",
        "ocp4-index_ngrs",
        "metric_ocp4_index_ngrs",
        "ocp4-prod-esb"
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Flemerle](https://avatars.discourse-cdn.com/v4/letter/f/b5e925/32.png) [@Flemerle](https://discuss.elastic.co/u/Flemerle)\
**Post date:** [May 31, 2022, 9:00am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/17 "2022-05-31T09:00:42Z")

</div>

Hello,  
You are using data stream, can you show the output section regarding the index target of your beat/logstash ?  
The weird thing is that your policy has a rollover every 30d (or when the primary shard is 50gb) but your backing indices are new every day. That is why i'm asking the previous question.

Regarding the ilm policy itself, the "max\_age" inside the hot rollover phase should be 5d instead of 30d, and the "min\_age" inside the delete phase should be 0d. This way the indices will do a rollover after 5 days and be deleted right after. The rollover is used to create a new write index, when using data stream you don't have to create aliases it's automaticaly configured.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2022, 9:01am UTC](https://discuss.elastic.co/t/index-dont-want-deleted-automatically/305554/18 "2022-06-28T09:01:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
