Skip to content
DataMiner DoJo

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Search in posts
Search in pages
Log in
Menu
  • Blog
  • Questions
  • Learning
    • E-learning Courses
    • Open Classroom Training
    • Certification
      • DataMiner Fundamentals
      • DataMiner Configurator
      • DataMiner Automation
      • Scripts & Connectors Developer: HTTP Basics
      • Scripts & Connectors Developer: SNMP Basics
      • Visual Overview – Level 1
      • Verify a certificate
    • Tutorials
    • Video Library
    • Books We Like
    • >> Go to DataMiner Docs
  • Expert Center
    • Solutions & Use Cases
      • Solutions
      • Use Case Library
    • Markets & Industries
      • Media production
      • Government & defense
      • Content distribution
      • Service providers
      • Partners
      • OSS/BSS
    • DataMiner Insights
      • Security
      • Integration Studio
      • System Architecture
      • DataMiner Releases & Updates
      • DataMiner Apps
    • Agile
      • Agile Webspace
      • Everything Agile
        • The Agile Manifesto
        • Best Practices
        • Retro Recipes
      • Methodologies
        • The Scrum Framework
        • Kanban
        • Extreme Programming
      • Roles
        • The Product Owner
        • The Agile Coach
        • The Quality & UX Coach (QX)
    • DataMiner DevOps Professional Program
  • Downloads
  • More
    • Feature Suggestions
    • Climb the leaderboard!
    • Swag Shop
    • Contact
      • General Inquiries
      • DataMiner DevOps Support
      • Commercial Requests
    • Global Feedback Survey
  • PARTNERS
    • All Partners
    • Technology Partners
    • Strategic Partner Program
    • Deal Registration
  • >> Go to dataminer.services

How can I manually remove all alarms older than 6 months to free up space again in my ES Cluster

Solved945 views12th July 2023alarms Elasticsearch low diskspace
1
Jeroen Nietvelt [SLC] [DevOps Advocate]1.34K 14th October 2022 0 Comments

Dear Community,

We recently have encountered some sever alarm storms which lead to the elasticsearch cluster being flooded with alarm data. As a result from that, the cluster will run out of available space within the next 1 - 2 weeks.

To mitigate the situation on short term, we would like to purge all alarms older than 6 months from the elasticsearch cluster and are happy to perform this action manually through a request sent from postman.

Is it possible to do this with a single post request directly to the alias which combines all individual alarm indices? Would someone be able to provide some assistance on which endpoint + JSON body best can be used to achieve this result?

Marieke Goethals [SLC] [DevOps Catalyst] Selected answer as best 12th July 2023

1 Answer

  • Active
  • Voted
  • Newest
  • Oldest
4
Jeroen Nietvelt [SLC] [DevOps Advocate]1.34K Posted 14th October 2022 0 Comments

With a bit of trial and error I managed to get to the following queries which i executed through postman on the elasticsearch cluster:

search query for all alarms older than 6 months:

endpoint: GET http://[ES NODE IP]:9200/dms-alarms/_search
body:
{
  "query": {
    "bool" : {
      "must" : [
        {
        "range": {
              "CreationTime": {"lte" : "2022-04-15" }}
         }
      ]}
   }
}

delete by query for alarms older than 6 months:

endpoint: POST http://[ES NODE IP]:9200/dms-alarms/_delete_by_query
body:
{
  "query": {
    "bool" : {
      "must" : [
        {
        "range": {
              "CreationTime": {"lte" : "2022-04-15" }}
         }
      ]}
   }
}

Executing the query took approximately 40 minutes. It covered about 10 million documents and managed to delete them without any issue.

exactly the same query can be executed on the information events indices by replacing dms-alarms with dms-info

Example: POST http://[ES NODE IP]:9200/dms-info/_delete_by_query

Marieke Goethals [SLC] [DevOps Catalyst] Selected answer as best 12th July 2023
Please login to be able to comment or post an answer.

My DevOps rank

DevOps Members get more insights on their profile page.

My user earnings

0 Dojo credits

Spend your credits in our swag shop.

0 Reputation points

Boost your reputation, climb the leaderboard.

Promo banner DataMiner DevOps Professiona Program
DataMiner Integration Studio (DIS)
Empower Katas

Recent questions

Web Applications exception in Cube due to invalid certificate 0 Answers | 0 Votes
Redundancy Groups and Alarming – Duplicate Alarms 0 Answers | 0 Votes
Correlation Engine: “Test rule” doesn’t result in a hit, despite functional rule 1 Answer | 3 Votes

Question Tags

adl2099 (115) alarm (62) Alarm Console (82) alarms (100) alarm template (83) Automation (223) automation scipt (111) Automation script (167) backup (71) Cassandra (180) Connector (109) Correlation (69) Correlation rule (52) Cube (151) Dashboard (194) Dashboards (188) database (83) DataMiner Cube (57) DIS (81) DMS (71) DOM (140) driver (65) DVE (56) Elastic (83) Elasticsearch (115) elements (80) Failover (104) GQI (159) HTTP (76) IDP (74) LCA (152) low code app (166) low code apps (93) lowcodeapps (75) MySQL (53) protocol (203) QAction (83) security (88) SNMP (86) SRM (337) table (54) trending (87) upgrade (62) Visio (539) Visual Overview (345)
Privacy Policy • Terms & Conditions • Contact

© 2025 Skyline Communications. All rights reserved.

DOJO Q&A widget

Can't find what you need?

? Explore the Q&A DataMiner Docs

[ Placeholder content for popup link ] WordPress Download Manager - Best Download Management Plugin