# Are date indexes not allowed anymore?

**URL:** <https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941>\
**Category:** Elasticsearch\
**Created:** [December 9, 2025, 7:37pm UTC](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941 "2025-12-09T19:37:56Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![ethrbunny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethrbunny/32/34603_2.png) [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Post date:** [December 9, 2025, 7:37pm UTC](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941/1 "2025-12-09T19:37:56Z")

</div>

My indexes are created from a template as ‘name-year.month.date’. It seems that this isn’t acceptable for index-lifecycle-policies anymore. I get this error “index name [name-2025.12.09] does not match pattern '^.\*-\d+$'“.

At one point this process was working. I was able to rollover/delete indexes based on age.

Is there a workaround?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 9, 2025, 9:27pm UTC](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941/2 "2025-12-09T21:27:09Z")

</div>

That regular expression pattern does as far as I can see not appear to match the index name so I would recommend fixing the pattern. (You need to account for the dots in the date) If this at some point has worked that must have been a bug that has been fixed.

---

<div class="post-metadata">

**Author:** ![ethrbunny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethrbunny/32/34603_2.png) [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Post date:** [December 9, 2025, 10:45pm UTC](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941/3 "2025-12-09T22:45:56Z")

</div>

Is there something I can do to change the regex pattern? I rather like having a date stamp on my indexes.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [December 9, 2025, 10:56pm UTC](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941/4 "2025-12-09T22:56:13Z")

</div>

There are 2 things related to date pattern indices.

The first is when indices roll over, many have their birthdate in the name. This is still done by many of the Elastic provided integrations.

The second type is where the date from the event is used in the index name. That causes a new index to be created daily. That can lead to a lot of smaller indices, which can cause problems. Another problem that can happen is a new beats/agent starts harvesting host logs that go back for years and the config doesn’t block the older events (I don’t remember the parameter). If you have 2 years of data, you can suddenly create 720 new indices. (I’ve done it, not fun)

---

<div class="post-metadata">

**Author:** ![ethrbunny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethrbunny/32/34603_2.png) [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Post date:** [December 10, 2025, 6:07pm UTC](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941/5 "2025-12-10T18:07:32Z")

</div>

I need them to rollover daily. Beats create a large amount of data and I need to be able to prune it by date on the regular. This is what I was trying to achieve with the index-lifecycle.

Otherwise it’s a bash script. Boo.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 10, 2025, 6:19pm UTC](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941/6 "2025-12-10T18:19:01Z")

</div>

> [@ethrbunny](#):
>
> '^.\*-\d+$'“

For the regex pattern I think something like `^.*-[\d\.]+$` might work, but I have not tested it. That pattern should look for a sequence of dots and digits to end the index name.

> [@ethrbunny](#):
>
> I need them to rollover daily. Beats create a large amount of data and I need to be able to prune it by date on the regular.

How many different time based indices are you creating?

What is your retention period for these?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 10, 2025, 6:28pm UTC](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941/7 "2025-12-10T18:28:29Z")

</div>

> [@ethrbunny](#):
>
> I need them to rollover daily. Beats create a large amount of data and I need to be able to prune it by date on the regular. This is what I was trying to achieve with the index-lifecycle.

How are you indexing your data? With Logstash or beats?

Daily indices are not good practice as they can lead to big or small indices, it would be better to rollover by size.

In this case if you want to keep daily indices I would not use ILM to rollover them, just to delete.

You can have a policy that only deletes the index after some time.

---

<div class="post-metadata">

**Author:** ![ethrbunny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethrbunny/32/34603_2.png) [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Post date:** [December 10, 2025, 7:27pm UTC](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941/8 "2025-12-10T19:27:05Z")

</div>

Data goes from beat → kafka → logstash → elastic. Logstash creates the indexes.

I tried creating a simple policy to delete but got the regex error that started this thread.

Im experimenting with data streams to see if they are more helpful w/re lifecycle.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 10, 2025, 10:40pm UTC](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941/9 "2025-12-10T22:40:52Z")

</div>

> [@ethrbunny](#):
>
> Data goes from beat → kafka → logstash → elastic. Logstash creates the indexes.
> 
> I tried creating a simple policy to delete but got the regex error that started this thread.

So you are creating the indices with something like `index => indexName-%{yyyy.MM.dd}` right?

You need to create a policy with rollover disabled and configure the delete phase.

Something like this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5d67c5d3408394834a063795174bee35d61113fa.png)

```auto
PUT _ilm/policy/<policyName>
{
  "policy": {
    "phases": {
      "hot": {
        "actions": {},
        "min_age": "0ms"
      },
      "delete": {
        "min_age": "7d",
        "actions": {
          "delete": {
            "delete_searchable_snapshot": false
          }
        }
      }
    }
  }
}

```

This will delete the index after 7 days of the creation.

> [@ethrbunny](#):
>
> Im experimenting with data streams to see if they are more helpful w/re lifecycle.

If you want to have the dates on the index name, it will add some more complications, first data streams require rollover by size or age, you will not have daily indices anymore, also the date of the backing index will be the date when it rolled over.

Even if you rollover every 24 hours, it is counted by age, not like logstash that creates a new index when the day changes.

Another issue is that if you use custom naming, Logstash per default does not support writing data to custom data streams, it would require your indices to start with `logs-*` for example, which forces you to be careful with the template because there is a built-in template that would match `logs-*`.

You can have custom data streams names with Logstash, I have some, but you need to use an output like this:

```auto
output {
    elasticsearch {
        user => "username"
        password => "password"
        index => "custom-datastream-name"
        action => "create"
        compression_level => 3
        data_stream => false
        manage_template => false
        ilm_enabled => false
    }
}

```

---

<div class="post-metadata">

**Author:** ![ethrbunny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethrbunny/32/34603_2.png) [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Post date:** [December 11, 2025, 6:06pm UTC](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941/10 "2025-12-11T18:06:58Z")

</div>

Ok. I disabled rollover and started some new indexes. Hopefully this will fix the problem.

W/re streams - I have this setting:

```auto
"lifecycle": {
    "enabled": true,
    "data_retention": "7d"
}

```

looks like it’s deleting the indexes under the streams but not the streams. Is this something that can be set?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 11, 2025, 6:31pm UTC](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941/11 "2025-12-11T18:31:56Z")

</div>

This is the data stream retention, a different way of managing retention on data streams.

I'm not sure how this works as I do not use it, but it seems that the retention is configured in the index settings instead of using an ILM.
