Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.Sign up
Elasticsearch Curator helps you curate, or manage, your Elasticsearch indices and snapshots by:
- Obtaining the full list of indices (or snapshots) from the cluster, as the actionable list
- Iterate through a list of user-defined filters to progressively remove indices (or snapshots) from this actionable list as needed.
- Perform various actions on the items which remain in the actionable list.
Curator runs as a Docker container within Security Onion. It runs every minute and is controlled by cron jobs defined in
/etc/cron.d/. When Curator completes an action, it logs such activity in a log file found in
Curator defaults to closing indices older than 30 days. To modify this, change
As your disk reaches capacity, Curator starts deleting old indices to prevent your disk from filling up. To change the limit, modify