# Add ILM to existing index 7.17.9

**URL:** <https://discuss.elastic.co/t/add-ilm-to-existing-index-7-17-9/333003>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [May 9, 2023, 10:12pm UTC](https://discuss.elastic.co/t/add-ilm-to-existing-index-7-17-9/333003 "2023-05-09T22:12:25Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bruceclegg](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Post date:** [May 9, 2023, 10:12pm UTC](https://discuss.elastic.co/t/add-ilm-to-existing-index-7-17-9/333003/1 "2023-05-09T22:12:25Z")

</div>

I have an existing index I've applied the 30 day default lifecycle management policy to. But it doesn't seem to be working. I've read through the documentation and I/m obviously missing something.

The index I'm attempting to add the lifecycle to was not created with a template. Could that be my problem? If so, is there a way to build a template from the index - then use this template to launch a new index and apply the lifecycle management policy to that?

I don't see a way to create a template from an index.  
I don't see a way to apply a template (for ilm purposes) to an existing index.

This is how the index was created:

```auto
PUT /dfbi.log-prod
{
  "settings": {
    "index": {
      "routing": {
        "allocation": {
          "include": {
            "_tier_preference": "data_content"
          }
        }
      },
      "number_of_shards": "3",
      "number_of_replicas": "1"
      }
  }
}

```

the alias of 'dfbi.log-prod' was set up later

\_ilm\explain shows me this:

```auto
{
  "indices" : {
    "dfbi.log-prod-000001" : {
      "index" : "dfbi.log-prod-000001",
      "managed" : true,
      "policy" : "30-days-default",
      "lifecycle_date_millis" : 1683152809675,
      "age" : "5.92d",
      "phase" : "hot",
      "phase_time_millis" : 1683216402487,
      "action" : "rollover",
      "action_time_millis" : 1683216402687,
      "step" : "check-rollover-ready",
      "step_time_millis" : 1683216402687,
      "phase_execution" : {
        "policy" : "30-days-default",
        "phase_definition" : {
          "min_age" : "0ms",
          "actions" : {
            "rollover" : {
              "max_primary_shard_size" : "50gb",
              "max_age" : "30d"
            }
          }
        },
        "version" : 1,
        "modified_date_in_millis" : 1681853018351
      }
    }
  }
}

```

Any help here is very much appreciated.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 9, 2023, 10:19pm UTC](https://discuss.elastic.co/t/add-ilm-to-existing-index-7-17-9/333003/2 "2023-05-09T22:19:35Z")

</div>

Did you see [Configure a lifecycle policy | Elasticsearch Guide [8.7] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.7/set-up-lifecycle-policy.html#apply-policy-multiple)? That should let you attach the existing indices.

---

<div class="post-metadata">

**Author:** ![Bruceclegg](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Post date:** [May 12, 2023, 4:52pm UTC](https://discuss.elastic.co/t/add-ilm-to-existing-index-7-17-9/333003/3 "2023-05-12T16:52:19Z")

</div>

I'm running 7.17.9 - Will I be able to attach to an existing index with this version?

Forgive me, I'm the Linux Admin here - I haven't used ELK much - I set up the hardware, got the cluster running, and am doing my best to answer user questions and set up parameters required by our ELK users.

In this 3 node cluster, we're just running one index. All data from our production platform is loading into this one index. After I set up the lifecycle management policy, I expected that after the hot period the lifecycle management processes would strip out the 'old' entries in the index and put them into a new, warm, version of the index that queries could be run against if my colleagues need access to older logs. Am I correct in this? What should I be seeing in Kibana (or elsewhere) to let me know lifecycle management is working?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 16, 2023, 11:56pm UTC](https://discuss.elastic.co/t/add-ilm-to-existing-index-7-17-9/333003/4 "2023-05-16T23:56:02Z")

</div>

> [@Bruceclegg](#):
>
> Will I be able to attach to an existing index with this version?

Yep, it's version agnostic.

> [@Bruceclegg](#):
>
> After I set up the lifecycle management policy, I expected that after the hot period the lifecycle management processes would strip out the 'old' entries in the index and put them into a new, warm, version of the index that queries could be run against if my colleagues need access to older logs. Am I correct in this?

Your theory is sound! We'd need to see the actual ILM policy to comment if your implementation is correct.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 17, 2023, 12:52am UTC](https://discuss.elastic.co/t/add-ilm-to-existing-index-7-17-9/333003/5 "2023-05-17T00:52:05Z")

</div>

ILM assumes that you are using time based indices ,e.g. through rollover or a data stream, and manages the lifecycle by moving and deleting complete indices. It does not delete partial data from within an index or move data between indices.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 17, 2023, 1:15am UTC](https://discuss.elastic.co/t/add-ilm-to-existing-index-7-17-9/333003/6 "2023-05-17T01:15:43Z")

</div>

Ahh yeah good catch!

---

<div class="post-metadata">

**Author:** ![Bruceclegg](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Post date:** [May 18, 2023, 4:15am UTC](https://discuss.elastic.co/t/add-ilm-to-existing-index-7-17-9/333003/7 "2023-05-18T04:15:46Z")

</div>

Thanks guys - that was my suspicion. We have just one big index that keeps growing. On our old (now test) instance running an old version I have cron job that just deletes the index once a month.  
I will see what it takes to get this set up properly. I can google myself, but it could be helpful if you point me to a resource that goes through setting up the indexes/templates/policies from scratch in a way that will support ilm? Much appreciated!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2023, 4:16am UTC](https://discuss.elastic.co/t/add-ilm-to-existing-index-7-17-9/333003/8 "2023-06-15T04:16:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
