# Wiping data from ELK

**URL:** <https://discuss.elastic.co/t/wiping-data-from-elk/147467>\
**Category:** Elasticsearch\
**Created:** [September 5, 2018, 7:54pm UTC](https://discuss.elastic.co/t/wiping-data-from-elk/147467 "2018-09-05T19:54:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![RussellBateman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russellbateman/32/34928_2.png) [@RussellBateman](https://discuss.elastic.co/u/RussellBateman)\
**Post date:** [September 5, 2018, 7:54pm UTC](https://discuss.elastic.co/t/wiping-data-from-elk/147467/1 "2018-09-05T19:54:35Z")

</div>

I'm in rabid experimentation mode here. I'm set up like this:

Filebeat -\> Elasticsearch | Logstash | nginx | Kibana.

I'd like to know how to wipe data from an ELK stack (6.4.0) I'm running (on Ubuntu Server 18.04) without tossing everything and starting over from scratch. What files? Etc. In particular, when I relaunch Kibana, I don't want to see any vestiges of what was in there previously.

Thanks for any comments, advice, etc.  
Russ

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 5, 2018, 7:58pm UTC](https://discuss.elastic.co/t/wiping-data-from-elk/147467/2 "2018-09-05T19:58:22Z")

</div>

Just delete all the filebeat/logstash indices and you should be good.

---

<div class="post-metadata">

**Author:** ![RussellBateman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russellbateman/32/34928_2.png) [@RussellBateman](https://discuss.elastic.co/u/RussellBateman)\
**Post date:** [September 5, 2018, 8:02pm UTC](https://discuss.elastic.co/t/wiping-data-from-elk/147467/3 "2018-09-05T20:02:17Z")

</div>

I'm new at this. What are these? Where do I delete them? Are they in files or this something I do from Kibana?

---

<div class="post-metadata">

**Author:** ![evilbit77](https://avatars.discourse-cdn.com/v4/letter/e/a6a055/32.png) [@evilbit77](https://discuss.elastic.co/u/evilbit77)\
**Post date:** [September 5, 2018, 8:33pm UTC](https://discuss.elastic.co/t/wiping-data-from-elk/147467/4 "2018-09-05T20:33:12Z")

</div>

Make sure you're not sending new data into the cluster, first. Then, you could do it by either issuing a call to the API:

curl -XDELETE localhost:9200/\_all

Or by stopping the elasticsearch service and then going into your data directory and deleting all data.

If you're running Security with X-pack, this will render your cluster inaccessible, since you're deleting the security index on top of everything else.

---

<div class="post-metadata">

**Author:** ![RussellBateman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russellbateman/32/34928_2.png) [@RussellBateman](https://discuss.elastic.co/u/RussellBateman)\
**Post date:** [September 5, 2018, 9:28pm UTC](https://discuss.elastic.co/t/wiping-data-from-elk/147467/5 "2018-09-05T21:28:36Z")

</div>

Great, this sounds easily done. Shut down Filebeat, use the curl command. I'll take this opportunity to play with Elasticsearch anyway that way, finding its data directory, etc. since part of this trip is to get my arms all the way around all of this. (Oh, yeah, I'm not using security or X-pack stuff yet.)

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![RussellBateman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russellbateman/32/34928_2.png) [@RussellBateman](https://discuss.elastic.co/u/RussellBateman)\
**Post date:** [September 5, 2018, 10:16pm UTC](https://discuss.elastic.co/t/wiping-data-from-elk/147467/6 "2018-09-05T22:16:30Z")

</div>

Ah, hence _indices_: Elasticsearch's data is on the path _/var/lib/elasticsearch/nodes_ and there's a subdirectory named _indices_. Now I understand the first answer.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 6, 2018, 12:42am UTC](https://discuss.elastic.co/t/wiping-data-from-elk/147467/7 "2018-09-06T00:42:05Z")

</div>

Don't delete the filesystem, use the APIs as suggested.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2018, 12:42am UTC](https://discuss.elastic.co/t/wiping-data-from-elk/147467/8 "2018-10-04T00:42:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
