# Purging when storage is low

**URL:** <https://discuss.elastic.co/t/purging-when-storage-is-low/70600>\
**Category:** Elasticsearch\
**Created:** [January 4, 2017, 7:40pm UTC](https://discuss.elastic.co/t/purging-when-storage-is-low/70600 "2017-01-04T19:40:06Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jimyoo](https://avatars.discourse-cdn.com/v4/letter/j/53a042/32.png) [@jimyoo](https://discuss.elastic.co/u/jimyoo)\
**Post date:** [January 4, 2017, 7:40pm UTC](https://discuss.elastic.co/t/purging-when-storage-is-low/70600/1 "2017-01-04T19:40:06Z")

</div>

I want to develop a SW (c++ or script) that checks the available (cluster level) disk space and deletes old indices if the space is under certain amount. For example, if 85% or more of disk has been used, it deletes the oldest index.  
I can think of using \_cluster/stats to get available space, \_cat/indices to get the list of indices, and DETLET to delete old one(s).  
Better ideas or/and comments?  
(ES version 5.0)

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 4, 2017, 8:06pm UTC](https://discuss.elastic.co/t/purging-when-storage-is-low/70600/2 "2017-01-04T20:06:03Z")

</div>

[Elasticsearch Curator](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html) does all that and more.

---

<div class="post-metadata">

**Author:** ![jimyoo](https://avatars.discourse-cdn.com/v4/letter/j/53a042/32.png) [@jimyoo](https://discuss.elastic.co/u/jimyoo)\
**Post date:** [January 4, 2017, 9:36pm UTC](https://discuss.elastic.co/t/purging-when-storage-is-low/70600/3 "2017-01-04T21:36:22Z")

</div>

Thanks for the information.

I found a command like under. Is this "space 10TB" per cluster (not per index)?  
[curator.py](http://curator.py) --host my-elasticsearch -C space -g 10024  
I need an option for per cluster.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 4, 2017, 9:39pm UTC](https://discuss.elastic.co/t/purging-when-storage-is-low/70600/4 "2017-01-04T21:39:40Z")

</div>

What version are you running?

---

<div class="post-metadata">

**Author:** ![jimyoo](https://avatars.discourse-cdn.com/v4/letter/j/53a042/32.png) [@jimyoo](https://discuss.elastic.co/u/jimyoo)\
**Post date:** [January 4, 2017, 9:41pm UTC](https://discuss.elastic.co/t/purging-when-storage-is-low/70600/5 "2017-01-04T21:41:42Z")

</div>

I haven't installed Curator yet; just reading articles.

> **[Curator: Tending your time-series indices
	  	 | Elastic](https://www.elastic.co/blog/curator-tending-your-time-series-indices)**
>
> NOTE:This article now contains outdated information. Please reference our docs, peruse our latest blogs, and visit our forums for the latest and greatest. Thank you.backgroundA few years ago, I was ma...

  
ES is 5.0.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 4, 2017, 9:48pm UTC](https://discuss.elastic.co/t/purging-when-storage-is-low/70600/6 "2017-01-04T21:48:45Z")

</div>

You probably want to look at [https://www.elastic.co/guide/en/elasticsearch/client/curator/current/filtertype\_space.html](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/filtertype_space.html) instead.

---

<div class="post-metadata">

**Author:** ![jimyoo](https://avatars.discourse-cdn.com/v4/letter/j/53a042/32.png) [@jimyoo](https://discuss.elastic.co/u/jimyoo)\
**Post date:** [January 4, 2017, 10:22pm UTC](https://discuss.elastic.co/t/purging-when-storage-is-low/70600/7 "2017-01-04T22:22:07Z")

</div>

I ran some tests and it seems to be a per index operation - with 1G disk\_space filter, 3 indices with bigger than 1G got removed.

-- purge\_on\_low\_disk.yml --  
actions:  
1:  
action: delete\_indices  
description: "purging on disk low"  
options:  
timeout\_override:  
continue\_if\_exception: False  
disable\_action: False  
filters:  
- filtertype: space  
disk\_space: 1  
reverse: True  
use\_age: False  
source: creation\_date  
timestring:  
field:  
stats\_result:  
exclude: False

$ curator --dry-run purge\_on\_low\_disk.yml --config curator.yml  
--- snip ---  
2017-01-04 15:22:15,895 DEBUG curator.indexlist \_\_not\_actionable:39 Index event-2016.12.12 is not actionable, removing from list.  
2017-01-04 15:22:15,895 DEBUG curator.indexlist \_\_excludify:58 Removed from actionable list: event-2016.12.12, summed disk usage is 932.6MB and disk limit is 1.0GB.  
2017-01-04 15:22:15,896 DEBUG curator.indexlist \_\_not\_actionable:39 Index event-2016.12.11 is not actionable, removing from list.  
2017-01-04 15:22:15,896 DEBUG curator.indexlist \_\_excludify:58 Removed from actionable list: event-2016.12.11, summed disk usage is 1018.2MB and disk limit is 1.0GB.  
2017-01-04 15:22:15,896 DEBUG curator.indexlist \_\_actionable:35 Index event-2016.12.10 is actionable and remains in the list.  
2017-01-04 15:22:15,896 DEBUG curator.indexlist \_\_excludify:58 Remains in actionable list: event-2016.12.10, summed disk usage is 1.1GB and disk limit is 1.0GB.  
2017-01-04 15:22:15,896 DEBUG curator.indexlist \_\_actionable:35 Index event-2016.12.09 is actionable and remains in the list.  
2017-01-04 15:22:15,897 DEBUG curator.indexlist \_\_excludify:58 Remains in actionable list: event-2016.12.09, summed disk usage is 1.2GB and disk limit is 1.0GB.  
2017-01-04 15:22:15,897 DEBUG curator.indexlist \_\_actionable:35 Index event-2016.12.08 is actionable and remains in the list.  
2017-01-04 15:22:15,897 DEBUG curator.indexlist \_\_excludify:58 Remains in actionable list: event-2016.12.08, summed disk usage is 1.2GB and disk limit is 1.0GB.  
2017-01-04 15:22:15,897 DEBUG curator.utils iterate\_filters:847 Post-instance: ['event-2016.12.08', 'event-2016.12.10', 'event-2016.12.09']  
2017-01-04 15:22:15,898 DEBUG curator.actions.delete\_indices **init** :421 master\_timeout value: 30s  
2017-01-04 15:22:15,898 INFO curator.utils show\_dry\_run:636 DRY-RUN MODE. No changes will be made.  
2017-01-04 15:22:15,898 INFO curator.utils show\_dry\_run:639 (CLOSED) indices may be shown that may not be acted on by action "delete\_indices".  
2017-01-04 15:22:15,898 INFO curator.utils show\_dry\_run:646 DRY-RUN: delete\_indices: event-2016.12.08 with arguments: {}  
2017-01-04 15:22:15,898 INFO curator.utils show\_dry\_run:646 DRY-RUN: delete\_indices: event-2016.12.09 with arguments: {}  
2017-01-04 15:22:15,898 INFO curator.utils show\_dry\_run:646 DRY-RUN: delete\_indices: event-2016.12.10 with arguments: {}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2017, 10:22pm UTC](https://discuss.elastic.co/t/purging-when-storage-is-low/70600/8 "2017-02-01T22:22:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
