# Apply Index Life Cycle Policies

**URL:** <https://discuss.elastic.co/t/apply-index-life-cycle-policies/192754>\
**Category:** Kibana\
**Created:** [July 29, 2019, 5:35pm UTC](https://discuss.elastic.co/t/apply-index-life-cycle-policies/192754 "2019-07-29T17:35:31Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [July 29, 2019, 5:35pm UTC](https://discuss.elastic.co/t/apply-index-life-cycle-policies/192754/1 "2019-07-29T17:35:31Z")

</div>

Hi All,

I have been trying to set up the index life cycle policies to my active index already available.  
My index names are X, Y, Z. Trying to assign a policy to roll over once reaching 25 GB.  
I'm creating the index name in the output part of logstash.  
I went through multiple docs provided by [elastic.co](http://elastic.co). But I feel it is not clear or straight forward.  
The docs mentioned to create alias name for my index and it throws error that it does not match the pattern like X-000001, Y-000001, Z-000001.  
I tried creating an alias of the same way but getting the error "index name does not match pattern '^.\*-\d+$'"  
Could some one share the steps correctly on the following

- how the index name should be present in logstash.
- how to create a template in Kibana to map to an index.
- how to create an index which satisifes the roll over condition.

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [July 30, 2019, 12:04am UTC](https://discuss.elastic.co/t/apply-index-life-cycle-policies/192754/2 "2019-07-30T00:04:32Z")

</div>

[This is the official guide for setting up ILM](https://www.elastic.co/guide/en/elasticsearch/reference/7.2/getting-started-index-lifecycle-management.html). Which steps have you already completed successfully?

The Logstash elasticsearch output plugin has [additional configurations for ILM](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ilm).

---

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [July 30, 2019, 5:34am UTC](https://discuss.elastic.co/t/apply-index-life-cycle-policies/192754/3 "2019-07-30T05:34:14Z")

</div>

Hi @nickpeihl,

Thanks for the correct link related to the elastic search output plugin for logstash.  
As per the example in the doc  
output {  
elasticsearch {  
ilm\_rollover\_alias =\> "custom"  
ilm\_pattern =\> "000001"  
ilm\_policy =\> "custom\_policy"  
}  
}  
once the roll over policy condition is met, will the index pattern gets incremented automatically to 000002, or do we need to set it in any specific regex pattern to get it incremented?

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [July 30, 2019, 7:22pm UTC](https://discuss.elastic.co/t/apply-index-life-cycle-policies/192754/4 "2019-07-30T19:22:13Z")

</div>

According to the docs, the pattern automatically gets incremented when the indices rollover. [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ilm\_pattern](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ilm_pattern)

In order to work correctly your `ilm_pattern` needs a dash before the `000001` (ex. `mypattern-000001`. But you could also remove the `ilm_pattern` from the config and it will use a default pattern of `{now/d}-000001`.

---

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [August 1, 2019, 8:41am UTC](https://discuss.elastic.co/t/apply-index-life-cycle-policies/192754/5 "2019-08-01T08:41:52Z")

</div>

As per the docs, I have created the ilm\_pattern and the indices are mapped to a policy when roll up should trigger when 15 GB reaches. One of my indices to which i have mapped the 15 GB policy has reached the storage size of 15 GB but the indices doesn't seem to roll up and a new index with pattern -000002 is not created.

Did I miss any configuration or a step for the roll over to trigger?

---

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [August 1, 2019, 8:49am UTC](https://discuss.elastic.co/t/apply-index-life-cycle-policies/192754/6 "2019-08-01T08:49:07Z")

</div>

The new index got created with the pattern 000002 after sometime i updated the comment here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2019, 8:49am UTC](https://discuss.elastic.co/t/apply-index-life-cycle-policies/192754/7 "2019-08-29T08:49:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
