# Remove old logs from elastic

**URL:** <https://discuss.elastic.co/t/remove-old-logs-from-elastic/87713>\
**Category:** Elasticsearch\
**Created:** [May 31, 2017, 10:07am UTC](https://discuss.elastic.co/t/remove-old-logs-from-elastic/87713 "2017-05-31T10:07:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![moorthyrajesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moorthyrajesh/32/14394_2.png) [@moorthyrajesh](https://discuss.elastic.co/u/moorthyrajesh)\
**Post date:** [May 31, 2017, 10:07am UTC](https://discuss.elastic.co/t/remove-old-logs-from-elastic/87713/1 "2017-05-31T10:07:21Z")

</div>

I have written a query to load two months data to elasticsearch. I would like only two months data to be retained at any point of time. which means in the third month the first months data should not be shown.

Is this possible.

regards  
Rajesh

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [May 31, 2017, 10:11am UTC](https://discuss.elastic.co/t/remove-old-logs-from-elastic/87713/2 "2017-05-31T10:11:52Z")

</div>

You want to delete everything that is +2 months old or simply filter out?

---

<div class="post-metadata">

**Author:** ![moorthyrajesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moorthyrajesh/32/14394_2.png) [@moorthyrajesh](https://discuss.elastic.co/u/moorthyrajesh)\
**Post date:** [May 31, 2017, 10:15am UTC](https://discuss.elastic.co/t/remove-old-logs-from-elastic/87713/3 "2017-05-31T10:15:09Z")

</div>

I would like to delete +2 months old and only keep 2 months data.

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [May 31, 2017, 10:19am UTC](https://discuss.elastic.co/t/remove-old-logs-from-elastic/87713/4 "2017-05-31T10:19:29Z")

</div>

Elasticsearch won't do that automatically for you and you need to schedule an external script to that.

For assisting with that script you can use a tool called [Curator](https://www.elastic.co/guide/en/elasticsearch/client/curator/5.0/index.html) that allows defining high level rules for managing indices and snapshot/restore.

There is also an article that explains for to run [Curator on AWS Lambda](https://www.elastic.co/blog/serverless-elasticsearch-curator-on-aws-lambda)

---

<div class="post-metadata">

**Author:** ![moorthyrajesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moorthyrajesh/32/14394_2.png) [@moorthyrajesh](https://discuss.elastic.co/u/moorthyrajesh)\
**Post date:** [May 31, 2017, 10:20am UTC](https://discuss.elastic.co/t/remove-old-logs-from-elastic/87713/5 "2017-05-31T10:20:15Z")

</div>

Thanks for your help. Let me see how to get that done.😁

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2017, 10:20am UTC](https://discuss.elastic.co/t/remove-old-logs-from-elastic/87713/6 "2017-06-28T10:20:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
