# Logstash config to delete records in elastic?

**URL:** <https://discuss.elastic.co/t/logstash-config-to-delete-records-in-elastic/88366>\
**Category:** Logstash\
**Created:** [June 6, 2017, 7:08am UTC](https://discuss.elastic.co/t/logstash-config-to-delete-records-in-elastic/88366 "2017-06-06T07:08:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![west415](https://avatars.discourse-cdn.com/v4/letter/w/919ad9/32.png) [@west415](https://discuss.elastic.co/u/west415)\
**Post date:** [June 6, 2017, 7:08am UTC](https://discuss.elastic.co/t/logstash-config-to-delete-records-in-elastic/88366/1 "2017-06-06T07:08:25Z")

</div>

Hi,

I'm using Logstash 5.1.1 and new to the ELK stack. I have a logstash config file setup that does an upsert of records from my Microsoft SQL Server database every 5 minutes into an index in Elastic. When a record or records(s) are deleted from SQL Server, I want to somehow delete the records in the elastic index to keep things in sync.

Can someone kindly share a config that will do that or point me maybe somewhere that illustrates how this is done? I'm happy to learn, just need a bit of help. My end goal is to ensure that if a record is deleted in my source database, it also gets deleted in elastic.

I can provide my current config if it helps.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 8, 2017, 7:33pm UTC](https://discuss.elastic.co/t/logstash-config-to-delete-records-in-elastic/88366/2 "2017-06-08T19:33:26Z")

</div>

You might be able to pull this off with an elasticsearch input and a jdbc\_streaming filter. The idea would be to fetch all documents from ES and look them up in the database. If you don't get a match you need to issue a deletion request. This is probably possible but the configuration might become non-trivial and most likely won't be very efficient.

---

<div class="post-metadata">

**Author:** ![west415](https://avatars.discourse-cdn.com/v4/letter/w/919ad9/32.png) [@west415](https://discuss.elastic.co/u/west415)\
**Post date:** [June 8, 2017, 11:22pm UTC](https://discuss.elastic.co/t/logstash-config-to-delete-records-in-elastic/88366/3 "2017-06-08T23:22:59Z")

</div>

Thanks for the reply, it was helpful and made me think a bit more about the requirement I was trying to solve for. I think I may be better of when a user needs to delete something I delete it **first** from elasticsearch index and then from my database versus the other way around. Or perhaps just do a soft delete (e.g. active flag or something) in my database and do an update on the index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 11:24pm UTC](https://discuss.elastic.co/t/logstash-config-to-delete-records-in-elastic/88366/4 "2017-07-06T23:24:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
