Where does Elastic search stores the data in windows machine

(Thiyagarajan) #1


We have downloaded ELK and unzipped them under c:\Softwares in windows machine. We have started the Elasticsearch, Kibana and Logstash with respective .bat files in bin directory.

Filebeat is installed in our SIT server and it is posting the logs to logstash as expected. Last week our dev machine harddisk became full (This is where we have installed ELK). We got this issue after 3 weeks from when we installed ELK on this machine.

So I was trying to clear the logs of Elasticsearch so that we can free up some space. But I could not find any specific storage location of Elasticsearch.

After searching the installed folders I have noticed c:\Softwares\elasticsearch-5.5.0\data folder. But I am not sure if this is where ELK stores the data. I have been reading other posted queries in this site but could not find the answer.

Our queries are,

  1. Where is Elasticsearch data stored in windows machine for our case
  2. How to delete the data after certain days. We would like to retain only two weeks data during SIT phase. Once we move on to production, we may retain 2 months logs.

Any help would appreciated.

(Mark Walkom) #2

FYI we’ve renamed ELK to the Elastic Stack, otherwise Beats feels left out :wink:

https://www.elastic.co/guide/en/elasticsearch/reference/current/zip-windows.html#windows-layout should answer your first question.
Elasticsearch Curator will answer your second one :slight_smile:

(Thiyagarajan) #3

Hi Mark,

Thanks a lot for your quick reply. Will use the name Elastic Stack here on.

So our storage location must be c:\Softwares\elasticsearch-5.5.0\data? Please correct me if I am wrong.

I am very new to Elastic Stack. So I will spend some time on Curator for data management and come back if I have any queries.

(Mark Walkom) #4

It will be that path because that is the default, yes.
You can change it though, that page explains how a little higher up.

(Thiyagarajan) #5

Hi Mark,

Now I have downloaded curator and unzipped.


When I try to start the curator with above command to verify the installation I am getting below error

The program can't start because VCRUNTIME140.dll is missing from your computer.

I am from Java background. So I do not have knowledge on Python. Please let me know If I am missing something here.

Thanks in advance

(Mark Walkom) #6

Let me cc @theuntergeek here as this is outside my experience with Curator :slight_smile:

(Thiyagarajan) #7

Hi Aaron,

Have you got a chance to look into this issue?

(Aaron Mildenstein) #8

VCRUNTIME140.dll is not something that ships with Curator, even for Windows. I have never heard of its absence before. What version of Windows are you running on?

I found this article that describes some of the conditions where this can occur, and how to fix it.

(Thiyagarajan) #9

Hi Aaron,

We are using Windows 7 Professional 64bit OS.

We are going to do Elastic Stack setup in another machine along with curator to check if there is any machine specific issues.

We will update you after doing the setup.

Thanks for spending your valuable time to share us the article.

(system) #10

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.