You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Elasticsearch Curator未按预期删6天前数据,却删除整个索引

问题分析与解决办法

核心问题:creation_date 索引创建时间不可靠

你的Curator配置中使用creation_date作为年龄判断依据,这是导致误删的关键原因:

  • creation_date是索引创建的时间,而非索引内数据的时间。如果索引创建后持续写入新数据(比如滚动索引配置异常,或长期复用同一个索引),哪怕索引内有最新数据,只要创建时间超过6天,就会被判定为“过期”并删除。
  • 若近期有索引通过快照恢复、克隆等方式创建,其creation_date会沿用原索引的创建时间,导致新恢复的索引被误判为过期。

修复方案:根据索引名称中的日期判断(推荐)

如果你的索引命名带有日期后缀(比如pds-cnnfr-usw2-2024.05.20),修改age过滤器,从索引名称提取日期进行判断,这是最可靠的方式:

actions:
  1:
    action: delete_indices
    description: >-
      Delete indices older than 6 days
    options:
     ignore_empty_list: True
     timeout_override:
     continue_if_exception: False
     disable_action: False
    filters:
    - filtertype: pattern
      kind: regex
      value: '^pds-cnnfr-usw2.*$'
    - filtertype: age
      source: name  # 从索引名称提取日期
      direction: older
      unit: days
      unit_count: 6
      timestring: '%Y.%m.%d'  # 对应你索引名称中的日期格式,比如YYYY.MM.DD

备选方案:根据索引内数据的最新时间判断

如果索引命名没有日期后缀,可以基于索引内@timestamp字段的最大值判断:

actions:
  1:
    action: delete_indices
    description: >-
      Delete indices older than 6 days
    options:
     ignore_empty_list: True
     timeout_override:
     continue_if_exception: False
     disable_action: False
    filters:
    - filtertype: pattern
      kind: regex
      value: '^pds-cnnfr-usw2.*$'
    - filtertype: age
      source: field_stats
      field: '@timestamp'  # 用数据的时间字段
      direction: older
      unit: days
      unit_count: 6

排查验证步骤

  1. 先执行Dry Run查看Curator会匹配哪些索引,避免误删:
    curator --dry-run /path/to/your/action.yml
    
  2. 检查目标索引的creation_date是否正常:
    curl -XGET 'http://your-es-host:9200/pds-cnnfr-usw2-*/_settings?pretty'
    
    查看输出中的creation_date字段,确认是否存在不符合预期的时间值。

内容的提问来源于stack exchange,提问作者Harsh Vardhan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 09:22:54