# Issue with \_delete\_by\_query

**URL:** <https://discuss.elastic.co/t/issue-with-delete-by-query/175605>\
**Category:** Elasticsearch\
**Created:** [April 5, 2019, 1:37pm UTC](https://discuss.elastic.co/t/issue-with-delete-by-query/175605 "2019-04-05T13:37:20Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![afassl](https://avatars.discourse-cdn.com/v4/letter/a/aca169/32.png) [@afassl](https://discuss.elastic.co/u/afassl)\
**Post date:** [April 5, 2019, 1:37pm UTC](https://discuss.elastic.co/t/issue-with-delete-by-query/175605/1 "2019-04-05T13:37:21Z")

</div>

Hi,  
we've encountered a kind of strange issue and solved it by a workaround, but not sure, if the issue is caused by a bug or the request string.  
We've had to delete certain entries from an index, according to the documentation the query has to look like this:

curl -XPOST "[http://kibana.company.com:9200/\_delete\_by\_query](http://kibana.company.com:9200/_delete_by_query)" -H 'Content-Type: application/json' -d'  
{  
"query": {  
"bool": {  
"must": [  
{  
"match": {  
"\_index": {  
"query": “xxx-6.5.4-error-\*"  
}  
}  
},  
{  
"match": {  
"context.service.name": {  
"query": “xxx-production"  
}  
}  
},  
{  
"range": {  
"@timestamp": {  
"lt": "2019-04-05",  
"gte": "2019-04-04",  
"format": "yyyy-MM-dd||yyyy-MM-dd||yyyy||yyyy-MM"  
}  
}  
}  
]  
}  
}  
}  
'  
But this call throws an error:  
{"error":"Incorrect HTTP method for uri [/\_delete\_by\_query] and method [POST], allowed: [HEAD, PUT, GET, DELETE]","status":405}

But the corresponding search query is fine:  
curl -XGET "[http://kibana.company.com:9200/\_search](http://kibana.company.com:9200/_search)" -H 'Content-Type: application/json' -d'  
{  
"query": {  
"bool": {  
"must": [  
{  
"match": {  
"\_index": {  
"query": “xxx-6.5.4-error-\*"  
}  
}  
},  
{  
"match": {  
"context.service.name": {  
"query": “xxx-production"  
}  
}  
},  
{  
"range": {  
"@timestamp": {  
"lt": "2019-12-31",  
"gte": "2019-01-01",  
"format": "yyyy-MM-dd||yyyy-MM-dd||yyyy||yyyy-MM"  
}  
}  
}  
]  
}  
}  
}  
'  
and delivered as expected 2800 entries.

we've only been able to get the delete done, by adding the index into the the URI  
curl -XPOST ’[http://kibana.company.com:9200/xxx-6.5.4-error-date/\_delete\_by\_query](http://kibana.company.com:9200/xxx-6.5.4-error-date/_delete_by_query)  
and to execute it per day.

We are currently running elastic 6.3. But I'm assuming this is not related to the version.

Any idea?

Best regards

---

<div class="post-metadata">

**Author:** ![BenTrent](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bentrent/32/33915_2.png) [@BenTrent](https://discuss.elastic.co/u/BenTrent)\
**Post date:** [April 5, 2019, 2:00pm UTC](https://discuss.elastic.co/t/issue-with-delete-by-query/175605/2 "2019-04-05T14:00:27Z")

</div>

Heya @afassl!

`_delete_by_query` requires the index patterns to be included in the url.  
`curl -XPOST "http://kibana.company.com:9200/my-index/_delete_by_query"` should work.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [April 5, 2019, 2:07pm UTC](https://discuss.elastic.co/t/issue-with-delete-by-query/175605/3 "2019-04-05T14:07:47Z")

</div>

I just tested this and it worked. I had 73,000 document count which got deleted.

```
curl -XPOST "http://elkm01:9200/metricbeat_sysstat_2019/_delete_by_query?conflicts=proceed" -H 'Content-Type: application/json' -d'
     {
       "query": {
         "range": {
           "@timestamp": {
             "gte": "01-01-2019",
             "lte": "02-01-2019",
             "format": "MM-dd-yyyy||yyyy-MM-dd||yyyy||yyyy-MM"
           }
         }
       }
     }'
```

---

<div class="post-metadata">

**Author:** ![afassl](https://avatars.discourse-cdn.com/v4/letter/a/aca169/32.png) [@afassl](https://discuss.elastic.co/u/afassl)\
**Post date:** [April 5, 2019, 3:43pm UTC](https://discuss.elastic.co/t/issue-with-delete-by-query/175605/4 "2019-04-05T15:43:50Z")

</div>

Thanks a lot - so - a feature - not a bug.

Last question - possible to use a wildcard in the index? Not sure if this will be parsed, as we've already removed the data - can't test that

But again - thanks a lot

Best regards  
Andreas

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [April 8, 2019, 2:47pm UTC](https://discuss.elastic.co/t/issue-with-delete-by-query/175605/5 "2019-04-08T14:47:05Z")

</div>

yes you can use wildcard in query and delete the data

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2019, 2:47pm UTC](https://discuss.elastic.co/t/issue-with-delete-by-query/175605/6 "2019-05-06T14:47:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
