Create a Delete Elasticsearch Data Task

The Delete Elasticsearch Data Task deletes log data that has been forwarded to an Elasticsearch cluster.

For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Select Configuration, then browse to Administration.
  2. Browse to Tasks.
  3. Right-click Tasks, then select New > Delete Elasticsearch Data Task.
  4. Configure the settings, then click OK.

Result

The task appears under Task Definitions in the Tasks branch of the Administration tree. You can run the task either manually or according to a fixed schedule.
CAUTION:
When this task runs, all logs matching the selected filter and time range are permanently deleted from the active storage. Make sure that the data you want to keep is exported or copied to a safe location before the operation is started.

Delete Elasticsearch Data Task dialog box

Use this dialog box to delete log data that has been forwarded to an Elasticsearch cluster.

Option Definition
General tab
Name The name of the element.
Comment

(Optional)

A comment for your own reference.
Target Data Select the type of log data to delete.
Time Range Specifies the time range of the log entries. You have several options to limit the time range.

For example, select Absolute Time Range in the Time Range list and define the Start and End Time.

Filter for Deletion Select a filter to narrow the scope of the logs to be deleted. Click Select to select an element.
Script to Execute After the Task This script runs after the task finishes.

The script is located at /data/script sub-folder in the SMC installation directory.

The LOG_SCRIPT_DIR parameter defines this script directory path in the LogServerConfiguration.txt