# Plugin to delete index data after some time interval

**URL:** <https://discuss.elastic.co/t/plugin-to-delete-index-data-after-some-time-interval/37430>\
**Category:** Elasticsearch\
**Created:** [December 17, 2015, 5:27am UTC](https://discuss.elastic.co/t/plugin-to-delete-index-data-after-some-time-interval/37430 "2015-12-17T05:27:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ushadatt](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@ushadatt](https://discuss.elastic.co/u/ushadatt)\
**Post date:** [December 17, 2015, 5:27am UTC](https://discuss.elastic.co/t/plugin-to-delete-index-data-after-some-time-interval/37430/1 "2015-12-17T05:27:35Z")

</div>

I want to delete my index's data which exceeds time limit of 30 days, not the index. Is there any plugin available for it?  
or if not, how to do the same?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 17, 2015, 5:29am UTC](https://discuss.elastic.co/t/plugin-to-delete-index-data-after-some-time-interval/37430/2 "2015-12-17T05:29:16Z")

</div>

Yep, check out [https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html)

---

<div class="post-metadata">

**Author:** ![ushadatt](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@ushadatt](https://discuss.elastic.co/u/ushadatt)\
**Post date:** [December 17, 2015, 6:39am UTC](https://discuss.elastic.co/t/plugin-to-delete-index-data-after-some-time-interval/37430/3 "2015-12-17T06:39:28Z")

</div>

> **[Examples | Curator Reference \[8.0\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/examples.html)**

Delete all indices with matching --timestring which are older than 30 days

> ```
> curator --host 10.0.0.2 alias --name lastmonth indices --newer-than 60 \
> --older-than 30 --timestring '%Y.%m.%d' --time-unit days --prefix logstash
> 
> ```

It specifies deletion of indexes which are older than 30 days, but I want to delete the data within a specified index which is older than 30 days. How to proceed with that?

---

<div class="post-metadata">

**Author:** ![jimczi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimczi/32/47985_2.png) [@jimczi](https://discuss.elastic.co/u/jimczi)\
**Post date:** [December 17, 2015, 9:20am UTC](https://discuss.elastic.co/t/plugin-to-delete-index-data-after-some-time-interval/37430/4 "2015-12-17T09:20:30Z")

</div>

You can check this page [https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-ttl-field.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-ttl-field.html)  
Though it might not be a good idea to use a deprecated feature, you should probably try the delete by query plugin ([https://www.elastic.co/guide/en/elasticsearch/plugins/current/plugins-delete-by-query.html](https://www.elastic.co/guide/en/elasticsearch/plugins/current/plugins-delete-by-query.html)).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 18, 2015, 9:14am UTC](https://discuss.elastic.co/t/plugin-to-delete-index-data-after-some-time-interval/37430/5 "2015-12-18T09:14:01Z")

</div>

Don't use TTL!  
Also don't use DBQ!

If you have data that is retained according to a time window, then use time based indices.

---

<div class="post-metadata">

**Author:** ![ushadatt](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@ushadatt](https://discuss.elastic.co/u/ushadatt)\
**Post date:** [December 18, 2015, 11:25am UTC](https://discuss.elastic.co/t/plugin-to-delete-index-data-after-some-time-interval/37430/6 "2015-12-18T11:25:08Z")

</div>

> [@warkolm](#):
>
> time based indices.

Thanks @Warkolm  
Yes , I was thinking the same to create the time based indices . But the issue is if I want to delete data after 30 days , I will have to create different indexes on per day basis.  
So for one application I will be having 30 indexes , and will delete the indexes whose time-span is more than 30 days.  
But when these application numbers is increased, creating 30 indexes/application , would not be a feasible solution.  
So How should I proceed to use the time based indices ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 19, 2015, 5:41am UTC](https://discuss.elastic.co/t/plugin-to-delete-index-data-after-some-time-interval/37430/7 "2015-12-19T05:41:32Z")

</div>

You can still do that, just reduce the shard count for smaller datasets.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:29pm UTC](https://discuss.elastic.co/t/plugin-to-delete-index-data-after-some-time-interval/37430/8 "2017-07-05T23:29:51Z")

</div>


