Skip to content
DataMiner DoJo

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Search in posts
Search in pages
Log in
Menu
  • Blog
  • Questions
  • Learning
    • E-learning Courses
    • Open Classroom Training
    • Certification
      • DataMiner Fundamentals
      • DataMiner Configurator
      • DataMiner Automation
      • Scripts & Connectors Developer: HTTP Basics
      • Scripts & Connectors Developer: SNMP Basics
      • Visual Overview – Level 1
      • Verify a certificate
    • Tutorials
    • Video Library
    • Books We Like
    • >> Go to DataMiner Docs
  • Expert Center
    • Solutions & Use Cases
      • Solutions
      • Use Case Library
    • Markets & Industries
      • Media production
      • Government & defense
      • Content distribution
      • Service providers
      • Partners
      • OSS/BSS
    • DataMiner Insights
      • Security
      • Integration Studio
      • System Architecture
      • DataMiner Releases & Updates
      • DataMiner Apps
    • Agile
      • Agile Webspace
      • Everything Agile
        • The Agile Manifesto
        • Best Practices
        • Retro Recipes
      • Methodologies
        • The Scrum Framework
        • Kanban
        • Extreme Programming
      • Roles
        • The Product Owner
        • The Agile Coach
        • The Quality & UX Coach (QX)
    • DataMiner DevOps Professional Program
  • Downloads
  • More
    • Feature Suggestions
    • Climb the leaderboard!
    • Swag Shop
    • Contact
      • General Inquiries
      • DataMiner DevOps Support
      • Commercial Requests
    • Global Feedback Survey
  • PARTNERS
    • All Partners
    • Technology Partners
    • Strategic Partner Program
    • Deal Registration
  • >> Go to dataminer.services

NetFlow – How long is data kept in ElasticSearch and why is it spread across different tables?

Solved1.02K views17th July 2023Elasticsearch logger table NetFlow
0
Jens Vandewalle [SLC] [DevOps Enabler]9.44K 8th January 2022 0 Comments

Hi Dojo,

I have a Netflow data collector running for 2 years now.
Looking at the ElasticSearch indices, I noticed that some logger tables (1000 and 2000) have multiple indices. What's the reason for that?

green open dms-dynamic_elementdata_17_63164_2000-2020.08.17.12-000001 > 5.7gb
green open dms-dynamic_elementdata_17_63164_3000-2020.08.17.12-000001 > 4.7gb
yellow open dms-dynamic_elementdata_17_63164_2000-2021.11.05.13-000002 > 1.1gb
yellow open dms-dynamic_elementdata_17_63164_1000-2021.11.05.13-000002 > 1.5gb
green open dms-dynamic_elementdata_17_63164_1000-2020.08.17.12-000001 > 7.2gb

I also want to investigate how long the data is stored.
Is there a way that I can see the oldest entries? Can I configure how long the data is kept?

Marieke Goethals [SLC] [DevOps Catalyst] Selected answer as best 17th July 2023

1 Answer

  • Active
  • Voted
  • Newest
  • Oldest
1
Gelber Mahecha [SLC] [DevOps Enabler]1.62K Posted 10th January 2022 1 Comment

Hi Jens,

A partial answer to your questions. To see the oldest entries, you can use the assigned alias to the indices created by the logger table:

GET dms-dynamic_elementdata_162101_623_2000/_search
{
"query": {
"match_all": {}
},
"sort": [
{
"SL_Internal_TimeField": {
"order": "asc"
}
}
] }

By default, a total of 10 hits are returned, but you can use the size query parameter (GET dms-dynamic_elementdata_162101_623_2000/_search?size=20) to get additional documents or the Scroll API to iterate over all the documents in a batch of different sizes.

Marieke Goethals [SLC] [DevOps Catalyst] Selected answer as best 17th July 2023
Gelber Mahecha [SLC] [DevOps Enabler] commented 17th January 2022

Hi Jans,

Another partial answer: In a recent case, I had the opportunity to confirm that we can use the Partition tag on column definition with DATETIME and DataMiner will clean the documents older than the specified time window.

For instance, a table’s column with the following definition will keep documents for the last year based on the time values stored in this field:

ColumnDefinition = DATETIME
Partition partitionsToKeep=”12″ = month

As per our development documentation, the column should be filled up with a specific DateTime format (though that part applied to the Cassandra log tables).

You are viewing 1 out of 1 answers, click here to view all answers.
Please login to be able to comment or post an answer.

My DevOps rank

DevOps Members get more insights on their profile page.

My user earnings

0 Dojo credits

Spend your credits in our swag shop.

0 Reputation points

Boost your reputation, climb the leaderboard.

Promo banner DataMiner DevOps Professiona Program
DataMiner Integration Studio (DIS)
Empower Katas

Recent questions

Correlation Engine: “Test rule” doesn’t result in a hit, despite functional rule 1 Answer | 1 Vote
When using the Setter = true attribute, will the copy action always be executed first? 1 Answer | 2 Votes
Multiple Set on Table parameters for DVE’s 1 Answer | 2 Votes

Question Tags

adl2099 (115) alarm (62) Alarm Console (82) alarms (100) alarm template (83) Automation (223) automation scipt (111) Automation script (167) backup (71) Cassandra (180) Connector (109) Correlation (69) Correlation rule (52) Cube (150) Dashboard (194) Dashboards (188) database (83) DataMiner Cube (57) DIS (81) DMS (71) DOM (140) driver (65) DVE (56) Elastic (83) Elasticsearch (115) elements (80) Failover (104) GQI (159) HTTP (76) IDP (74) LCA (152) low code app (166) low code apps (93) lowcodeapps (75) MySQL (53) protocol (203) QAction (83) security (88) SNMP (86) SRM (337) table (54) trending (87) upgrade (62) Visio (539) Visual Overview (345)
Privacy Policy • Terms & Conditions • Contact

© 2025 Skyline Communications. All rights reserved.

DOJO Q&A widget

Can't find what you need?

? Explore the Q&A DataMiner Docs

[ Placeholder content for popup link ] WordPress Download Manager - Best Download Management Plugin