# Purge elasticsearch data older than 1month

**URL:** <https://discuss.elastic.co/t/purge-elasticsearch-data-older-than-1month/356909>\
**Category:** Elasticsearch\
**Created:** [April 6, 2024, 6:43pm UTC](https://discuss.elastic.co/t/purge-elasticsearch-data-older-than-1month/356909 "2024-04-06T18:43:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kaushalshriyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaushalshriyan/32/44563_2.png) [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Post date:** [April 6, 2024, 6:43pm UTC](https://discuss.elastic.co/t/purge-elasticsearch-data-older-than-1month/356909/1 "2024-04-06T18:43:39Z")

</div>

Hi,

I am running ELK on Red Hat Enterprise Linux release 8.9 (Ootpa)

elasticsearch-8.13.1-1.x86\_64  
logstash-8.13.1-1.x86\_64  
kibana-8.13.1-1.x86\_64  
filebeat-8.13.1-1.x86\_64

Is there a way to purge elasticsearch data older than 1month? Any REST API call or something similar.....?

Please guide me. Thanks in advance

Best Regards,

Kaushal

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 7, 2024, 5:48am UTC](https://discuss.elastic.co/t/purge-elasticsearch-data-older-than-1month/356909/2 "2024-04-07T05:48:54Z")

</div>

If you are using time-based indices (indices with timestamp in name, rollover or data streams) you can use [index lifecycle management](https://www.elastic.co/guide/en/elasticsearch/reference/8.13/index-lifecycle-management-api.html) to delete indices that exceed a certain age. Deleting complete indices is the by far most efficient way to manage retention in Elasticsearch.

If you are not using time-based indices you need to use [the delete by query API](https://www.elastic.co/guide/en/elasticsearch/reference/8.13/docs-delete-by-query.html) to delete data from indices. Note that this is much more expensive than deleting indices and you have to trigger these APIs yourself.

---

<div class="post-metadata">

**Author:** ![kaushalshriyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaushalshriyan/32/44563_2.png) [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Post date:** [April 7, 2024, 12:58pm UTC](https://discuss.elastic.co/t/purge-elasticsearch-data-older-than-1month/356909/3 "2024-04-07T12:58:23Z")

</div>

@Christian_Dahlqvist Thanks a lot for a detailed response. Also Is there a way to archive/backup the elasticsearch data older than 1month and move it to a centralised storage location instead of purging or deleting the data which is a specific compliance requirement as per the customer.

Please guide me. Thanks in advance

Best Regards,

Kaushal

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 7, 2024, 1:35pm UTC](https://discuss.elastic.co/t/purge-elasticsearch-data-older-than-1month/356909/4 "2024-04-07T13:35:43Z")

</div>

Hi @kaushalshriyan

Perhaps take. Look at the documents for [Snapshot and Restore](https://www.elastic.co/guide/en/elasticsearch/reference/8.13/snapshot-restore.html) this is the only / official method for backing up Elasticsearch data.

---

<div class="post-metadata">

**Author:** ![kaushalshriyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaushalshriyan/32/44563_2.png) [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Post date:** [April 11, 2024, 2:44pm UTC](https://discuss.elastic.co/t/purge-elasticsearch-data-older-than-1month/356909/5 "2024-04-11T14:44:41Z")

</div>

Thanks a lot @Christian_Dahlqvist and @stephenb for the detailed response. Much appreciated. I will go through this and try it out on my sandbox environment. Thanks once again.
