Deleting an Elasticsearch index can reclaim storage, remove stale data, or correct a mapping design. It is also irreversible unless a snapshot or another recovery path exists. This guide covers when to delete an index and how to do it with appropriate safeguards.
The examples cover REST API and Kibana workflows, lifecycle management, and checks that developers and DevOps teams can apply before deletion.
Table of Contents
- What Does “Delete Index in Elasticsearch” Actually Mean?
- Why and When to Delete an Index
- Methods to Delete an IndexREST API (cURL or Kibana Dev Tools)Kibana UIScripts & Tools (Curator, Elasticsearch-py)
- REST API (cURL or Kibana Dev Tools)
- Kibana UI
- Scripts & Tools (Curator, Elasticsearch-py)
- Automating Deletion: Index Lifecycle Management (ILM)
- Best Practices & Safeguards
- Common Gotchas and How to Avoid Them
- Bonus: Quick Reference Cheat Sheet
What Does “Delete Index in Elasticsearch” Actually Mean?
Deleting an index in Elasticsearch removes all documents, associated shards, and metadata. This operation does not affect Kibana constructs like dashboards or data views. It’s terminal once gone; there’s no built-in undo. ElasticPulse
Think of it as dropping a database in relational systems; it’s clean, fast, but requires caution.
Why and When to Delete an Index
There are several legitimate scenarios:
- Incorrect mappings - like a field erroneously set as a keyword instead of text
- Huge index size - performance issues or storage constraints
- Obsolete or test data - logs, outdated datasets
- Retention policies - complying with data lifecycle requirements
Sematext highlights typical use cases such as mapping conflicts, oversized indexes, or indices no longer in use. Sematext. Also, TheLinuxCode notes rapid index growth and data removal for compliance and efficiency. The Linux Code
Methods to Delete an Index
REST API (via cURL or Kibana Dev Tools)
Use the DELETE endpoint:
DELETE /my_index
With cURL:
curl -X DELETE “localhost:9200/my_index?pretty”
Wildcards and multiple indices supported:
DELETE /logs-2025-08-*/?pretty
DELETE /index1,index2,index3
Sematext demonstrates both simple and wildcard examples. Sematext Better Stack also details REST API usage with examples. Better Stack
Kibana UI (Dev Tools)
In Kibana’s Dev Tools, the deletion request is:
DELETE /demo_index
Wildcards like DELETE /index* work here too. ObjectRocket shows a convenient way to delete via Kibana.
Scripts & Tools - Curator, Elasticsearch-py
Curator (Command-Line Automation)
Curator is ideal for scheduled cleanup. A YAML example to delete indices older than 30 days:
actions:
1:
action: delete_indices
description: “Delete indices older than 30 days”
options:
ignore_empty_list: True
allow_ilm_indices: False
filters:
- filtertype: age
source: creation_date
direction: older
unit: days
value: 30
Run it with curator –config curator.yml actions.yml Better Stack Overflow
Custom Scripts (Python + Elasticsearch-py)
from elasticsearch import Elasticsearch
es = Elasticsearch([“http://localhost:9200”])
indices = es.cat.indices(index=“logs-2025-*”, format=“json”)
for idx in indices:
es.indices.delete(index=idx[‘index’])
print(f“Deleted index: {idx[‘index’]}”)
Better Stack shows this script-based approach. Better Stack
Automating Deletion with Index Lifecycle Management (ILM)
ILM helps define policies that rollover, shrink, and eventually delete indices based on age, size, or other conditions.
Sample ILM policy:
PUT /_ilm/policy/delete-old-indices
{
“phases”: {
“hot”: {},
“delete”: {
“min_age”: “30d”,
“actions”: {
“delete”: {}
}
Then associate it with your index:
PUT /my_index/_settings
{
“index.lifecycle.name”: “delete-old-indices”
}
,
This ensures automated index deletion - no manual intervention. Better Stack
A recent update from Sematext underscores ILM’s value for managing age-based deletion. Sematext
From Security Onion (April 2025), teams managing multi-node environments are advised to disable legacy deletion scripts in favor of ILM to avoid catastrophic over-deletion. Security Onion Blog
Best Practices & Safeguards
- Double-check the index name to avoid accidental mass deletions.
- Backup or snapshot the index before deletion. Once deleted, you can’t restore. PulseSematext
- Monitor cluster health, deleting large indices triggers shard rebalancing. Opster
- Use index aliases to switch between indices without downtime. Opster
- Limit wildcard use, especially _all, unless verified. PulseDbVisualizer
Ensure permissions for some indices (like system or restricted ones) need special privileges. Discuss the Elastic Stack
Common Gotchas and How to Avoid Them
Issue
Description
Solution
Deleting the current write index in a data stream
Not allowed until index rollover
Perform rollover first, then delete the previous index ElasticSematext
No “acknowledged” response confusion
People worry index still exists
An acknowledged: true response indicates that Elasticsearch accepted the deletion request.
Restricted system indices (e.g., reporting)
Permission errors
Assign allow_restricted_indices: true in API key/role . Discuss the Elastic Stack
Legacy deletion scripts on clusters
May delete too much
Disable and rely on ILM or manual deletion , Security Onion Blog
Summary & Key Takeaways
- Delete index in Elasticsearch via REST API, Kibana, scripts, or ILM.
- Use REST or Kibana for ad hoc deletion. Use Curator or scripts for scheduled cleanup.
- ILM offers the safest automation by setting lifecycle policies.
- Always back up, monitor, and verify that deletion is permanent.
Permissions and index stream status matter. Watch for write-index blocks and restricted indices.
Bonus: Quick Reference Cheat Sheet
1. Delete one index via REST
DELETE /my_index
2. Delete with wildcard
DELETE /logs-*
3. ILM policy for auto-deletion after 30 days
PUT /_ilm/policy/delete-old
{
“phases”: {
“hot”: {},
“delete”: { “min_age”: “30d”, “actions”: { “delete”: {} } }
}
PUT /logs-*/_settings
{ “index.lifecycle.name”: “delete-old” }
4. Curator config to delete older than 30 days
actions:
1:
action: delete_indices
filters:
- filtertype: age
source: creation_date
direction: older
unit: days
value: 30
Feeling more confident about safely deleting Elasticsearch indices?
Want hands-on templates or support for crafting your ILM policies or backup strategy?
If you need help reviewing index deletion controls, ILM policies, or recovery safeguards, SquareShift can support the assessment.
