# Assigning an Index Template to an ILM Policy Gets Periodically Removed

**URL:** <https://discuss.elastic.co/t/assigning-an-index-template-to-an-ilm-policy-gets-periodically-removed/389274>\
**Category:** Kibana\
**Created:** [August 6, 2026, 11:46am UTC](https://discuss.elastic.co/t/assigning-an-index-template-to-an-ilm-policy-gets-periodically-removed/389274 "2026-08-06T11:46:24Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![YousefNein](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yousefnein/32/145549_2.png) [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Post date:** [August 6, 2026, 11:46am UTC](https://discuss.elastic.co/t/assigning-an-index-template-to-an-ilm-policy-gets-periodically-removed/389274/1 "2026-08-06T11:46:24Z")

</div>

As the title suggests, I keep assigning the index template that I want to be linked with a certain ILM, then after some time I go check it and find that they went back to the previous one.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/7/276f2d62fad1562784d1dd6d8fd74b7a82c8e4fb.png)

This happened to me numerous times, and I can't find any related problem like it online. Idk why. Would really appreciate the support.

---

<div class="post-metadata">

**Author:** ![Shaoranlaos](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Shaoranlaos](https://discuss.elastic.co/u/Shaoranlaos)\
**Post date:** [August 6, 2026, 12:03pm UTC](https://discuss.elastic.co/t/assigning-an-index-template-to-an-ilm-policy-gets-periodically-removed/389274/2 "2026-08-06T12:03:32Z")

</div>

I encountered a similar issue when the corresponding template is generated by an Integration (over Fleet).

Alle components of an integration (so templates, ingest pipelines, etc.) are periodically refreshed from the definition in the integration.

To change these there is in most cases a dedicated name of the corresponding component to customize these (in ingest pipelines these are named with "@custom" at the end).

I don't know if there is a similar mechenic for index template or if that is something to be done in the integration configuration.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 6, 2026, 12:15pm UTC](https://discuss.elastic.co/t/assigning-an-index-template-to-an-ilm-policy-gets-periodically-removed/389274/3 "2026-08-06T12:15:14Z")

</div>

> [@YousefNein](#):
>
> As the title suggests, I keep assigning the index template that I want to be linked with a certain ILM, then after some time I go check it and find that they went back to the previous one.

Please, provide more context, what template are you changing?

If you make changes to any `managed` template they may not persist and be reverted on integration updates.

If you want to make any changes to data that is ingested using any of Elastic Integrations, you need to make the changes on the equivalent `@custom` component template.

The `@custom` component templates will persist during integration updates.

There are 3 levels of custom settings on those templates, one that affects **all** integrations on the `logs@custom` component template, one that will affect all datasets in the integration, normallly the `integration_name@custom` and one that will affect only a specific dataset in the integration, which will be on something like `logs-datastrream.dataset@custom`.

Those `@custom` template does not exist per default, you need to create them by selecting the main index template and them clicking on the component template name, like this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/5/353478fd4bdc56c075d89a19ddd2fea7bcb6174e.png)

This will open the interface for you to edit the template.

---

<div class="post-metadata">

**Author:** ![YousefNein](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yousefnein/32/145549_2.png) [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Post date:** [August 6, 2026, 12:28pm UTC](https://discuss.elastic.co/t/assigning-an-index-template-to-an-ilm-policy-gets-periodically-removed/389274/4 "2026-08-06T12:28:53Z")

</div>

Thanks @Shaoranlaos I will check it

@leandrojmp Thanks for the reply

Normally I move any integration index, let's say, logs-system.syslog-default to a customly made `logs@custom`ILM

I'm not changing a template itself, I'm only adding it to the ILM policy.

So like I have said, periodically, it will move back to `logs@lifecycle` or the deprecated `logs` ILM.

If I understand correctly, a component template does this, and I will have to create a custom component template and add it to the ILM I want, is that what you're saying?

Appreciate the help!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 6, 2026, 12:43pm UTC](https://discuss.elastic.co/t/assigning-an-index-template-to-an-ilm-policy-gets-periodically-removed/389274/5 "2026-08-06T12:43:47Z")

</div>

> [@YousefNein](#):
>
> Normally I move any integration index, let's say, logs-system.syslog-default to a customly made `logs@custom`ILM
> 
> I'm not changing a template itself, I'm only adding it to the ILM policy.

This is a change, adding an ILM policy to a template will change the setting in that template, which can be reverted on an integration update.

You should not make any changes to any managed index template, all customizations needs to be done using the `@custom` component template.

If you want to change the ILM policy for the data stream `logs-system.syslog-default`, then you need to edit the custom component template `logs-system.syslog@custom` and add something like this in the settings:

```auto
{
  "index": {
    "lifecycle": {
      "name": "policy-name"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![YousefNein](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yousefnein/32/145549_2.png) [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Post date:** [August 6, 2026, 12:46pm UTC](https://discuss.elastic.co/t/assigning-an-index-template-to-an-ilm-policy-gets-periodically-removed/389274/6 "2026-08-06T12:46:22Z")

</div>

Got it, now I understand, thank you.

Another related question is, what if I want to automate this? I tried doing this with the `_index_template` API endpoint and if did something like that it will overwrite the entire template which is something we do not want.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 6, 2026, 1:55pm UTC](https://discuss.elastic.co/t/assigning-an-index-template-to-an-ilm-policy-gets-periodically-removed/389274/7 "2026-08-06T13:55:52Z")

</div>

> [@YousefNein](#):
>
> Another related question is, what if I want to automate this? I tried doing this with the `_index_template` API endpoint and if did something like that it will overwrite the entire template which is something we do not want.

You just need to use the correct API, for component templates it is `_component_template`.

Then you could use something like this:

```auto
PUT _component_template/logs-system.syslog@custom
{ component template payload }

```

You can do this process through the UI and in the review part you can see what will be the final request.

To change just the ILM policy, it would be something like this:

```auto
PUT _component_template/logs-system.syslog@custom
{
  "template": {
    "settings": {
      "index": {
        "lifecycle": {
          "name": "policy-name"
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![YousefNein](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yousefnein/32/145549_2.png) [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Post date:** [August 6, 2026, 2:20pm UTC](https://discuss.elastic.co/t/assigning-an-index-template-to-an-ilm-policy-gets-periodically-removed/389274/8 "2026-08-06T14:20:25Z")

</div>

Thank you, but my question is automating putting the components templates onto the templates that I want to add the ILM onto.

So I want to also update logs-system.auth as well for example and many others. So going to each one isn't really optimal, so I tried adding them using the API endpoint index\_template overwrites the previous template.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 6, 2026, 2:30pm UTC](https://discuss.elastic.co/t/assigning-an-index-template-to-an-ilm-policy-gets-periodically-removed/389274/9 "2026-08-06T14:30:17Z")

</div>

> [@YousefNein](#):
>
> So I want to also update logs-system.auth as well for example and many others. So going to each one isn't really optimal

It depends, if you want to use the same ILM policy in all datasets for an integration, you can make the customization on the package level as mentioned, if you want `logs-system.auth` to use one ILM policy and `logs-system.syslog` to use a different policy, then you will need to edit the component templates per dataset, this is how this was build.

For example, considering the system integration.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/2/027b4b8cc22d1a063fd23ab99cb45006ad139943.png)

If you want to change any settings for just the syslog dataset, you use the `logs-system.syslog@custom`, if you want to change for **all** datasets in the system integration, you use `system@custom` and if you want to change for **all** datasets in **all** logs integrations, you use `logs@custom`.

The following request will change the policy for `logs-system.syslog`, `logs-system.security`, `logs-system.system`, `logs-system.auth` and `logs-system.applications`

```auto
PUT _component_template/system@custom
{
  "template": {
    "settings": {
      "index": {
        "lifecycle": {
          "name": "policy-name"
        }
      }
    }
  }
}

```
