# Policy that deletes Indexes after 30 days

**URL:** <https://forum.opensearch.org/t/policy-that-deletes-indexes-after-30-days/2250>\
**Category:** Index Management\
**Tags:** troubleshoot\
**Created:** [February 19, 2020, 9:57pm UTC](https://forum.opensearch.org/t/policy-that-deletes-indexes-after-30-days/2250 "2020-02-19T21:57:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ech0](https://avatars.discourse-cdn.com/v4/letter/e/db5fbb/32.png) [@Ech0](https://forum.opensearch.org/u/Ech0)\
**Post date:** [February 19, 2020, 9:57pm UTC](https://forum.opensearch.org/t/policy-that-deletes-indexes-after-30-days/2250/1 "2020-02-19T21:57:22Z")

</div>

I’m attempting to create a policy that deletes any index that is older than 30 days but it doesn’t appear to be working. The indexes do not delete.

I would also like this policy to apply to new index when they are created.

{  
“policy”: {  
“policy\_id”: “DELETE\_OLDER\_THAN\_30D”,  
“description”: “Policy that deletes indicies older than 30 days.”,  
“last\_updated\_time”: 1581005749328,  
“schema\_version”: 1,  
“error\_notification”: null,  
“default\_state”: “open”,  
“states”: [  
{  
“name”: “open”,  
“actions”: [  
{  
“open”: {}  
}  
],  
“transitions”: [  
{  
“state\_name”: “delete”,  
“conditions”: {  
“min\_index\_age”: “30d”  
}  
}  
]  
},  
{  
“name”: “delete”,  
“actions”: [  
{  
“delete”: {}  
}  
],  
“transitions”:   
}  
]  
}  
}

---

<div class="post-metadata">

**Author:** ![dbbaughe](https://avatars.discourse-cdn.com/v4/letter/d/bbe5ce/32.png) [@dbbaughe](https://forum.opensearch.org/u/dbbaughe)\
**Post date:** [February 19, 2020, 10:10pm UTC](https://forum.opensearch.org/t/policy-that-deletes-indexes-after-30-days/2250/2 "2020-02-19T22:10:56Z")

</div>

When you say does not appear to be working can you be more specific?  
Assuming you applied the policy to an index, is it stuck at a certain point in the policy?  
Can you do a \_opendistro/\_ism/explain/ call to see what the explain status shows?  
Any extra information/screenshots will help.

As for applying the policy to new indices, you can do that with the help of index templates.

Thanks,  
Drew

---

<div class="post-metadata">

**Author:** ![Ech0](https://avatars.discourse-cdn.com/v4/letter/e/db5fbb/32.png) [@Ech0](https://forum.opensearch.org/u/Ech0)\
**Post date:** [February 20, 2020, 2:15pm UTC](https://forum.opensearch.org/t/policy-that-deletes-indexes-after-30-days/2250/3 "2020-02-20T14:15:25Z")

</div>

It appears to be at the state: “Attempting to transition”

winlogbeat-7.3.2-2020.01.23  
DELETE\_OLDER\_THAN\_30D  
open  
Transition  
Attempting to transition  
Running

winlogbeat-7.3.2-2020.01.24  
DELETE\_OLDER\_THAN\_30D  
open  
Transition  
Attempting to transition  
Running

winlogbeat-7.3.2-2020.01.25  
DELETE\_OLDER\_THAN\_30D  
open  
Transition  
Attempting to transition  
Running

What would that call look like from Devtools? When doing GET \_opendistro/\_ism/explain/ I get:

{  
“error”: {  
“root\_cause”: [  
{  
“type”: “illegal\_argument\_exception”,  
“reason”: “Missing indices”  
}  
],  
“type”: “illegal\_argument\_exception”,  
“reason”: “Missing indices”  
},  
“status”: 400

---

<div class="post-metadata">

**Author:** ![dbbaughe](https://avatars.discourse-cdn.com/v4/letter/d/bbe5ce/32.png) [@dbbaughe](https://forum.opensearch.org/u/dbbaughe)\
**Post date:** [February 21, 2020, 11:20pm UTC](https://forum.opensearch.org/t/policy-that-deletes-indexes-after-30-days/2250/4 "2020-02-21T23:20:05Z")

</div>

Hi @Ech0,

For the explain API call you have to provide the index name(s) or \*, so something like  
`GET _opendistro/_ism/explain/* `

From the index names you provided, it doesn’t look like they are over 30 days old?  
30 days ago appears to be January 22nd as of this post, and those index names show January 23 as the earliest.

---

<div class="post-metadata">

**Author:** ![Ech0](https://avatars.discourse-cdn.com/v4/letter/e/db5fbb/32.png) [@Ech0](https://forum.opensearch.org/u/Ech0)\
**Post date:** [April 24, 2020, 4:53pm UTC](https://forum.opensearch.org/t/policy-that-deletes-indexes-after-30-days/2250/5 "2020-04-24T16:53:44Z")

</div>

Sorry I never replied to this, I forgot I had posted it. But I ended up figuring out my issue.

I needed create a template that added new indexes to the policy automatically, once I had done that, everything began working as expected.
