I've gone through about every thread on the topic, and have not found any answer or fix to this issue. I've just installed curator today (5.5.1) on top of an existing ELK 6.0 instance.
I've configured my files using the defaults as that really suits our environment...
My action file...
actions: 1: action: delete_indices description: >- Delete indices older than 30 days (based on index name), for logstash- prefixed indices. Ignore the error if the filter does not result in an actionable list of indices (ignore_empty_list) and exit cleanly. options: ignore_empty_list: False disable_action: False filters: - filtertype: pattern kind: prefix value: logstash- - filtertype: age source: name direction: older timestring: '%Y.%m.%d' unit: days unit_count: 30
And my configuration...
client: hosts: - xxx.xxx.xxx.168 port: 9200 url_prefix: use_ssl: False certificate: client_cert: client_key: ssl_no_validate: False http_auth: timeout: 30 master_only: False logging: loglevel: DEBUG logfile: '/var/log/curator' logformat: default blacklist: 
The blacklist was done as another suggestion.
The log in question:
2018-04-12 14:35:41,394 DEBUG curator.cli run:108 Client and logging options validated. 2018-04-12 14:35:41,394 DEBUG curator.cli run:112 default_timeout = 30 2018-04-12 14:35:41,394 DEBUG curator.cli run:116 action_file: ./delete_30.yml
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size yellow open logstash-2017.11.20 0RhQJVvfQUOuUCkR7w7VYg 5 1 3332817 0 479.5mb 479.5mb yellow open logstash-2018.01.22 EAesN1P5S-CW25G8I8458A 5 1 4416574 0 645.9mb 645.9mb yellow open logstash-2018.01.30 NlXgCEWdS6mGlAwYon_L3Q 5 1 3873730 0 585.3mb 585.3mb yellow open logstash-2017.11.28 2vi8fETSReiB_hQUg1XdvA 5 1 4323272 0 680.3mb 680.3mb etc...
The log files are from the dry runs.
So I'm at a loss as to why this isn't working. As mentioned, I've seen plenty on this topic, but nothing seems to have addressed this issue.