I have an elasticsearch server which has had data shipped to it by logstash. This data is just a dump of a servers windows logs. I've been using it to test the basic setup of ELK.
Now I'd like to move to something closer to production.
I'd like to stop shipping my windows logs (which is fine I know to edit the WinLogBeat config).
Delete data in my ES index (and any data on disk) and populate it with the my new data.
I understand that I'll need to stop ElasticSearch first.
Is the command just DELETE Logstash-*