# Logstash-ElasticSearch

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch/39448>\
**Category:** Elasticsearch\
**Created:** [January 18, 2016, 1:04pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch/39448 "2016-01-18T13:04:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![srinivas](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@srinivas](https://discuss.elastic.co/u/srinivas)\
**Post date:** [January 18, 2016, 1:04pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch/39448/1 "2016-01-18T13:04:13Z")

</div>

I am using logstash to process the logs and store the data in an elasticsearch index. I need logs of only a week to be stored and the remaining to be removed from the elasticsearch ( because the index is growing large due to many logs) . Is there anyway we can delete logs(like running a daily job) from elasticsearch index and save the disk space ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 18, 2016, 1:08pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch/39448/2 "2016-01-18T13:08:58Z")

</div>

There is a utility called [Curator](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html) that is designed to do exactly that.

---

<div class="post-metadata">

**Author:** ![srinivas](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@srinivas](https://discuss.elastic.co/u/srinivas)\
**Post date:** [January 19, 2016, 7:11am UTC](https://discuss.elastic.co/t/logstash-elasticsearch/39448/3 "2016-01-19T07:11:13Z")

</div>

Curator is used at index level. Is there anything at docs level so we can just delete specific docs and new docs will get added to the same existing index

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 19, 2016, 7:45am UTC](https://discuss.elastic.co/t/logstash-elasticsearch/39448/4 "2016-01-19T07:45:36Z")

</div>

If you are analysing logs, which tends to be immutable, using [time based indices](https://www.elastic.co/guide/en/elasticsearch/guide/current/time-based.html), which Curator heips manage, is the most efficient way to deal with data retention. Explicitly deleting records from an index can be done through the [delete by query plugin](https://www.elastic.co/guide/en/elasticsearch/plugins/2.0/plugins-delete-by-query.html), but is much less efficient than simply deleting indices once the data they hold has exceeded the retention period.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:23pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch/39448/5 "2017-07-05T23:23:34Z")

</div>


