# Adding a warm node

**URL:** https://discuss.elastic.co/t/adding-a-warm-node/301663
**Category:** Elasticsearch
**Tags:** ilm-index-lifecycle-management
**Created:** [April 5, 2022, 7:01pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663 "2022-04-05T19:01:34Z")
**Posts on this page:** 17
**Page:** 1

<div class="post-metadata">

### Author: ![Chris\_Stone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_stone/32/21026_2.png) [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)
#### Post date: [April 5, 2022, 7:01pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/1 "2022-04-05T19:01:34Z")

</div>

I've started with 4 ELK nodes:

Host 1 Logstash & Kibana  
Host 2 Elasticsearch node-1  
Host 3 Elasticsearch node-2  
Host 4 Elasticsearch node-3

The stack is running 7.16.1 and has just over a years' worth of data. I've not added `node.roles` values for the Elasticsearch nodes and everything else is mostly default. Logstash is outputting to all three ES nodes.

So, what I want to do is move all data older than 8 months to an Elasticsearch node-4, which I've built and added to the cluster. I also added this to that new node's config:

```auto
node.roles: ["data_warm"]

```

I then used Kibana to turn on the warm stage as follows:

 ![Screen Shot 2022-04-05 at 11.54.14 AM](https://us1.discourse-cdn.com/elastic/original/3X/8/d/8d02277aea7b6c688105c09b4a810ccffa48e5b0.jpeg)

So, I do see some data getting added to the warm node, but looks like just two days worth, possibly. What I would like is to have _all_ data older than 8 months to be moved off of the hot nodes and to the warm node.

Is there something more I need to do to get this? Also, do the hot nodes need `node.roles` specified, and if so, what would be the proper values? I see this in the docs, but it's not clear why I need them all:

```auto
node.roles: ["master", "ingest", "ml", "data_hot", "data_content"]

```

Thanks in advance for any help!

--C

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [April 5, 2022, 9:43pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/2 "2022-04-05T21:43:56Z")

</div>

Just so it's clear, you are using an ILM policy you've defined in Kibana, right?

---

<div class="post-metadata">

### Author: ![Chris\_Stone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_stone/32/21026_2.png) [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)
#### Post date: [April 5, 2022, 9:45pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/3 "2022-04-05T21:45:39Z")

</div>

Thanks! Correct, just as shown in the screenshot -- I've done nothing else.

--C

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [April 5, 2022, 9:49pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/4 "2022-04-05T21:49:13Z")

</div>

Did you attach the policy to all your indices?

---

<div class="post-metadata">

### Author: ![Chris\_Stone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_stone/32/21026_2.png) [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)
#### Post date: [April 5, 2022, 9:51pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/5 "2022-04-05T21:51:20Z")

</div>

Hmm, so when I updated that policy, it still showed that it's attached to all the indices. I guess that update isn't retroactive? I assume there's a an api call to attach it to all of them?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [April 5, 2022, 9:52pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/6 "2022-04-05T21:52:57Z")

</div>

It's not, nope. Check out [Manage existing indices | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/ilm-with-existing-indices.html#ilm-existing-indices-apply);

> The simplest way to transition to managing your periodic indices with ILM is to [configure an index template](https://www.elastic.co/guide/en/elasticsearch/reference/current/set-up-lifecycle-policy.html#apply-policy-template) to apply a lifecycle policy to new indices. Once the index you are writing to is being managed by ILM, you can [manually apply a policy](https://www.elastic.co/guide/en/elasticsearch/reference/current/set-up-lifecycle-policy.html#apply-policy-multiple) to your older indices.

---

<div class="post-metadata">

### Author: ![Chris\_Stone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_stone/32/21026_2.png) [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)
#### Post date: [April 5, 2022, 9:54pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/7 "2022-04-05T21:54:38Z")

</div>

Oh, I need to reindex everything? Yikes, didn't expect that...OK, I'll look into that. Thanks!

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [April 5, 2022, 10:09pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/8 "2022-04-05T22:09:46Z")

</div>

No, you don't. You can manually apply the policy as per the last link in that - [Configure a lifecycle policy | Elasticsearch Guide [8.1] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/set-up-lifecycle-policy.html#apply-policy-multiple)

---

<div class="post-metadata">

### Author: ![Chris\_Stone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_stone/32/21026_2.png) [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)
#### Post date: [April 5, 2022, 10:36pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/9 "2022-04-05T22:36:08Z")

</div>

Oh, OK, great. So basically, this?

```auto
curl -X POST "localhost:9200/ecs_logstash/_ilm/remove?pretty"

curl -X GET "localhost:9200/ecs_logstash?pretty"

curl -X POST "localhost:9200/ecs_logstash/_open?pretty"

curl -X PUT "localhost:9200/ecs_logstash/_settings?pretty" -H 'Content-Type: application/json' -d'
{
  "index": {
    "lifecycle": {
      "name": "logstash-policy"
    }
  }
}
'

```

---

<div class="post-metadata">

### Author: ![Chris\_Stone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_stone/32/21026_2.png) [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)
#### Post date: [April 5, 2022, 10:48pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/10 "2022-04-05T22:48:35Z")

</div>

Should I use a wildcard or alias name in the curls? I.e., `ecs_logstash-*` or `ecs_logstash`

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [April 5, 2022, 10:58pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/11 "2022-04-05T22:58:31Z")

</div>

Here you have a single index? Alias?

> [@Chris\_Stone](#):
>
> `ecs_logstash`

What are the names of the other existing indices?

---

<div class="post-metadata">

### Author: ![Chris\_Stone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_stone/32/21026_2.png) [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)
#### Post date: [April 5, 2022, 11:02pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/12 "2022-04-05T23:02:52Z")

</div>

They're daily rollover indices from logstash. The alias is `ecs_logstash`, but the indices names are, for example:

`ecs-logstash-2022.03.14-000822`  
`ecs-logstash-2022.04.05-001903`

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [April 5, 2022, 11:04pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/13 "2022-04-05T23:04:47Z")

</div>

Cool, thanks. Then you will want;

```auto
curl -X PUT "localhost:9200/ecs-logstash-2022*/_settings?pretty" -H 'Content-Type: application/json' -d'
{
  "index": {
    "lifecycle": {
      "name": "logstash-policy"
    }
  }
}

```

---

<div class="post-metadata">

### Author: ![Chris\_Stone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_stone/32/21026_2.png) [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)
#### Post date: [April 5, 2022, 11:06pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/14 "2022-04-05T23:06:04Z")

</div>

Awesome, thank you. I'll run this in the morning and update this thread.

Thanks again!

--C

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [April 5, 2022, 11:06pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/15 "2022-04-05T23:06:43Z")

</div>

You might want to drop the last 2 on the year, so it takes everything from 2020 onwards.

---

<div class="post-metadata">

### Author: ![Chris\_Stone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_stone/32/21026_2.png) [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)
#### Post date: [April 5, 2022, 11:07pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/16 "2022-04-05T23:07:26Z")

</div>

Got it! Will do. Thanks....

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 3, 2022, 11:07pm UTC](https://discuss.elastic.co/t/adding-a-warm-node/301663/17 "2022-05-03T23:07:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
