# Watcher to delete index

**URL:** <https://discuss.elastic.co/t/watcher-to-delete-index/110333>\
**Category:** Elasticsearch\
**Created:** [December 5, 2017, 11:59am UTC](https://discuss.elastic.co/t/watcher-to-delete-index/110333 "2017-12-05T11:59:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mads\_Frisk\_Sorensen](https://avatars.discourse-cdn.com/v4/letter/m/7cd45c/32.png) [@Mads\_Frisk\_Sorensen](https://discuss.elastic.co/u/Mads_Frisk_Sorensen)\
**Post date:** [December 5, 2017, 11:59am UTC](https://discuss.elastic.co/t/watcher-to-delete-index/110333/1 "2017-12-05T11:59:10Z")

</div>

Hi

I have a watcher, that should delete my logstash indices after 31 days.  
I'm having trouble with the transform part of the watcher.

In the 'source' line I would like it to find the date minus 31 days.

I have the following  
"transform": {  
"script": {  
"source": "return ['indexToDelete' : Instant.ofEpochMilli(ctx.trigger.scheduled\_time.getMillis()).plus(Duration.ofDays(-31))]",  
"lang": "painless"  
}  
}  
but adding a .toString('yyyy-MM-dd') makes the watcher invoke a fail (when simulating).

Full watcher code:  
{  
"trigger": {  
"schedule": {  
"daily": {  
"at": [  
"00:01"  
]  
}  
}  
},  
"input": {  
"simple": {  
"daysToKeep": 31  
}  
},  
"condition": {  
"always": {}  
},  
"actions": {  
"delete\_old\_index": {  
"webhook": {  
"scheme": "http",  
"host": "localhost",  
"port": 9200,  
"method": "delete",  
"path": "/logstash-{{ctx.payload.indexToDelete}}",  
"params": {},  
"headers": {}  
}  
}  
},  
"transform": {  
"script": {  
"source": "return ['indexToDelete' : Instant.ofEpochMilli(ctx.trigger.scheduled\_time.getMillis()).plus(Duration.ofDays(-31)).toString('yyyy')]",  
"lang": "painless"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![JKhondhu](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@JKhondhu](https://discuss.elastic.co/u/JKhondhu)\
**Post date:** [December 5, 2017, 12:07pm UTC](https://discuss.elastic.co/t/watcher-to-delete-index/110333/2 "2017-12-05T12:07:48Z")

</div>

Hi,

Can you share any failures you are seeing?  
Unaware of your use case here however would Curator be a good fit for tending to indices? ([https://www.elastic.co/blog/curator-3-0-released](https://www.elastic.co/blog/curator-3-0-released))

---

<div class="post-metadata">

**Author:** ![Mads\_Frisk\_Sorensen](https://avatars.discourse-cdn.com/v4/letter/m/7cd45c/32.png) [@Mads\_Frisk\_Sorensen](https://discuss.elastic.co/u/Mads_Frisk_Sorensen)\
**Post date:** [December 5, 2017, 12:29pm UTC](https://discuss.elastic.co/t/watcher-to-delete-index/110333/3 "2017-12-05T12:29:31Z")

</div>

It's just a generic 'Watcher: An internal server error occurred' - nothing in the elastic log, so I don't know where to log for futher loginfo.

I would like to avoid Curator, so the setup can be simple and selfcontained.

if I just write '.toString()' it outputs '2017-11-04T12:26:22.487Z' - no errors

EDIT - Added full watcher JSON to case

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [December 5, 2017, 9:19pm UTC](https://discuss.elastic.co/t/watcher-to-delete-index/110333/4 "2017-12-05T21:19:32Z")

</div>

Wow, the Curator 3.0 blog post is a bit old, seeing how version 5.4.0 is the current release. [https://www.elastic.co/guide/en/elasticsearch/client/curator/current/versions.html](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/versions.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2018, 9:19pm UTC](https://discuss.elastic.co/t/watcher-to-delete-index/110333/5 "2018-01-02T21:19:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
