# Remove docs.deleted

**URL:** <https://discuss.elastic.co/t/remove-docs-deleted/102469>\
**Category:** Elasticsearch\
**Created:** [October 2, 2017, 7:01pm UTC](https://discuss.elastic.co/t/remove-docs-deleted/102469 "2017-10-02T19:01:08Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![joao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joao/32/83447_2.png) [@joao](https://discuss.elastic.co/u/joao)\
**Post date:** [October 2, 2017, 7:01pm UTC](https://discuss.elastic.co/t/remove-docs-deleted/102469/1 "2017-10-02T19:01:08Z")

</div>

Hi guys, good afternoon.

So, I've been trying to remove the docs deleted for some index, but I didn't have success.

Could you help me?

**This is my index:**  
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
yellow open logstash-2017.09.21 L-iREuGaRXqWfxTBIit2ag 5 1 40995549 **857** 18.8gb 18.8gb  
yellow open logstash-2017.09.22 dnHs2S7rSs6rpqmUJbe6sw 5 1 39950568 **380268** 17.4gb 17.4gb

**I followed this link:**  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-forcemerge.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-forcemerge.html)

**I used this command:**  
POST /logstash-2017.09.21/\_forcemerge?only\_expunge\_deletes=true

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [October 2, 2017, 7:14pm UTC](https://discuss.elastic.co/t/remove-docs-deleted/102469/2 "2017-10-02T19:14:57Z")

</div>

A forceMerge takes time. Since you did not tell it to keep the client open until completion, it's running the merge in the background, and there's no real way to tell when it's done.

A forceMerge like that on a 17g index could take hours to complete, especially if merges are throttled in any way.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [October 2, 2017, 7:17pm UTC](https://discuss.elastic.co/t/remove-docs-deleted/102469/3 "2017-10-02T19:17:10Z")

</div>

Since you're using time-series indices from Logstash, you should be deleting indices, rather than deleting data from them. If you need to retain some data longer than others, then you should send the data with a longer retention period to a different index name, and then delete the ones with a shorter retention period.

The index management portion of this can be easily handled by [Elasticsearch Curator](https://www.elastic.co/guide/en/elasticsearch/client/curator/5.2/index.html). Splitting your data into different indices would be handled in the output block of your Logstash configuration.

---

<div class="post-metadata">

**Author:** ![joao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joao/32/83447_2.png) [@joao](https://discuss.elastic.co/u/joao)\
**Post date:** [October 2, 2017, 7:42pm UTC](https://discuss.elastic.co/t/remove-docs-deleted/102469/4 "2017-10-02T19:42:17Z")

</div>

First, thank you very much.  
So, I tryied the last 5 days without success. 😕

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [October 2, 2017, 8:03pm UTC](https://discuss.elastic.co/t/remove-docs-deleted/102469/5 "2017-10-02T20:03:57Z")

</div>

> [@joao](#):
>
> So, I tryied the last 5 days without success.

Please be more specific. Last 5 days, meaning what, exactly? Did you do the delete\_by\_query method you were doing first? Deleting indices in Curator is complete and total. Disk space is recovered immediately, because the index is deleted, rather than documents within it.

---

<div class="post-metadata">

**Author:** ![joao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joao/32/83447_2.png) [@joao](https://discuss.elastic.co/u/joao)\
**Post date:** [October 3, 2017, 12:35pm UTC](https://discuss.elastic.co/t/remove-docs-deleted/102469/6 "2017-10-03T12:35:41Z")

</div>

Good morning,

I didn't use curator, I used delete\_by\_query. I executed this query some times.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [October 3, 2017, 1:47pm UTC](https://discuss.elastic.co/t/remove-docs-deleted/102469/7 "2017-10-03T13:47:53Z")

</div>

Same thing as previously mentioned. Deleted documents aren't actually deleted until a segment merge occurs. The `delete_by_query` only _flags_ them as deleted. The segment merge removes documents flagged for deletion. Segment merges can be throttled by the cluster, and therefore take a considerable amount of time to complete.

I highly recommend not using delete\_by\_query, and using something like Curator so that entire indices can be deleted, not just a percentage of the documents in an index. `delete_by_query` is not a disk space management solution, especially with time-series data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 31, 2017, 1:48pm UTC](https://discuss.elastic.co/t/remove-docs-deleted/102469/8 "2017-10-31T13:48:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
