# TTL Documents

**URL:** <https://discuss.elastic.co/t/ttl-documents/162712>\
**Category:** Elasticsearch\
**Created:** [January 2, 2019, 8:30pm UTC](https://discuss.elastic.co/t/ttl-documents/162712 "2019-01-02T20:30:57Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [January 2, 2019, 8:30pm UTC](https://discuss.elastic.co/t/ttl-documents/162712/1 "2019-01-02T20:30:57Z")

</div>

Per [TTL Documents, Shield and Found | Elastic](https://www.elastic.co/blog/ttl-documents-shield-and-found):

> Note that in the current version of Elasticsearch, `_ttl` is deprecated.

What is the approach for modern elasticsearch 6.5+ (in terms of documents that needs to be expired)?

Please advise.

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [January 2, 2019, 9:19pm UTC](https://discuss.elastic.co/t/ttl-documents/162712/2 "2019-01-02T21:19:50Z")

</div>

Do these documents have the same expiration period or it vary widely?

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [January 2, 2019, 11:21pm UTC](https://discuss.elastic.co/t/ttl-documents/162712/3 "2019-01-02T23:21:50Z")

</div>

each doc to have own expiration, but they all would have same ttl

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [January 2, 2019, 11:27pm UTC](https://discuss.elastic.co/t/ttl-documents/162712/4 "2019-01-02T23:27:23Z")

</div>

In this case the cheapest solution would be to create a new index periodically. For example, if you have 6 months ttl, you can create a new index every month. While searching you can add a filter that will filter out documents that are older than 6 months. After 6 month, you will create a new index and delete completely the oldest index. You can automate this operation using [curator](https://www.elastic.co/guide/en/elasticsearch/client/curator/5.5/index.html).

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [January 3, 2019, 6:27pm UTC](https://discuss.elastic.co/t/ttl-documents/162712/5 "2019-01-03T18:27:37Z")

</div>

What about if ttl of document is like 7 days (not 6 month)? also isn't curator for 5.x?

---

<div class="post-metadata">

**Author:** ![Charles.w](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charles.w/32/15486_2.png) [@Charles.w](https://discuss.elastic.co/u/Charles.w)\
**Post date:** [January 3, 2019, 7:17pm UTC](https://discuss.elastic.co/t/ttl-documents/162712/6 "2019-01-03T19:17:15Z")

</div>

Hi Alexus,

Curator 5.x can be used with elasticsearch 6.x, as can be seen in this [Curator Version Compatibility Matrix](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/version-compatibility.html).

Furthermore, in this scenario, you might want to combine Igor's solution and the use of [the rollover api](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-rollover-index.html). You can take a look at this [this blog post](https://www.elastic.co/blog/managing-time-based-indices-efficiently) to learn more 😉

Best regards,

Charles Casadei

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [January 3, 2019, 8:49pm UTC](https://discuss.elastic.co/t/ttl-documents/162712/7 "2019-01-03T20:49:40Z")

</div>

> [@alexus](#):
>
> What about if ttl of document is like 7 days (not 6 month)?

Just create and a new index and delete the week-old index every day.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [January 7, 2019, 3:51pm UTC](https://discuss.elastic.co/t/ttl-documents/162712/8 "2019-01-07T15:51:09Z")

</div>

... not ideal solution like ttl per doc, but I guess that could work too)

Thank you!

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [January 7, 2019, 4:19pm UTC](https://discuss.elastic.co/t/ttl-documents/162712/9 "2019-01-07T16:19:51Z")

</div>

That's the most optimal solution. You can obviously periodically run [`delete_by_query`](https://www.elastic.co/guide/en/elasticsearch/reference/6.5/docs-delete-by-query.html) request, but this is going to be very inefficient since you will be deleting the oldest records that will end up in biggest segments by the time you will be deleting them, which means your biggest segments will have a lot of holes in them, requiring merging, wasting space and CPU and slowing things down. This is pretty much the worst-case scenario performance wise.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 4, 2019, 4:19pm UTC](https://discuss.elastic.co/t/ttl-documents/162712/10 "2019-02-04T16:19:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
