Is there anyway post ingestion that we can groom certain messages out of the indexes without dropping them?
I've been able to identify a few message types that I now have a drop filter on, but that won't help me for messages already received and taking up space.
-Andrew
Scrub messages from ElasticSearch
Scrub messages from ElasticSearch
Andrew J. - Do you even grok?
Re: Scrub messages from ElasticSearch
It's possible on the backend but not from the web interface as far as I know:
http://www.elasticsearch.org/guide/en/e ... e-doc.html
http://www.elasticsearch.org/guide/en/e ... elete.html
http://www.elasticsearch.org/guide/en/e ... e-doc.html
http://www.elasticsearch.org/guide/en/e ... elete.html
Former Nagios employee
Re: Scrub messages from ElasticSearch
Ok. Since we're only doing 14 day retention right now, I'm just going to let them expire. 
Andrew J. - Do you even grok?
Re: Scrub messages from ElasticSearch
That is an easy workaround. We'll go ahead and close the thread. Thanks.