# Beats not rolling in 7.0.0

**URL:** <https://discuss.elastic.co/t/beats-not-rolling-in-7-0-0/180207>\
**Category:** Beats\
**Created:** [May 8, 2019, 3:11pm UTC](https://discuss.elastic.co/t/beats-not-rolling-in-7-0-0/180207 "2019-05-08T15:11:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![saif3r](https://avatars.discourse-cdn.com/v4/letter/s/49beb7/32.png) [@saif3r](https://discuss.elastic.co/u/saif3r)\
**Post date:** [May 8, 2019, 3:11pm UTC](https://discuss.elastic.co/t/beats-not-rolling-in-7-0-0/180207/1 "2019-05-08T15:11:49Z")

</div>

Hi Guys,

I recently launched server monitoring using Winlogbeat, Packetbeat and Metricbeat. All three agents are running with default settings (except for Elasticsearch/Kibana hosts and winlog narrowed to security). Templates has been created automatically. For some reason, Elasticsearch indices are not rolled by day, which i remember happened by default in 6.7. Any idea why that might happen? Has anything changed in this regard from 6.7?  
Here's today screenshot of my indexes. The services are still running and I'm able to see fresh data in Discover, so there's definitely data from other days than 25 and 26 of April.  
 ![beats](https://us1.discourse-cdn.com/elastic/original/3X/5/3/5354ea8b85e4efe514de7d3ed57d776f47f0f52c.png)

---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [May 8, 2019, 4:26pm UTC](https://discuss.elastic.co/t/beats-not-rolling-in-7-0-0/180207/2 "2019-05-08T16:26:54Z")

</div>

Starting with 7.0, Beats uses index lifecycle management by default when it connects to a cluster that supports it. You can disable this behavior if you want to use daily indices. You just need to set `setup.ilm.enabled: false` and reload the index template. For more information, see the Beats documentation, for example: [https://www.elastic.co/guide/en/beats/packetbeat/current/ilm.html](https://www.elastic.co/guide/en/beats/packetbeat/current/ilm.html)

You can read more about the ILM feature here: [https://www.elastic.co/guide/en/kibana/7.0/index-lifecycle-policies.html](https://www.elastic.co/guide/en/kibana/7.0/index-lifecycle-policies.html).

---

<div class="post-metadata">

**Author:** ![saif3r](https://avatars.discourse-cdn.com/v4/letter/s/49beb7/32.png) [@saif3r](https://discuss.elastic.co/u/saif3r)\
**Post date:** [May 8, 2019, 4:29pm UTC](https://discuss.elastic.co/t/beats-not-rolling-in-7-0-0/180207/3 "2019-05-08T16:29:38Z")

</div>

That explains it, thank you @dedemorton  
Any idea why was is redone that way? Any particular reason why the default behavior was changed like this? I'm asking out of the curiosity.

---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [May 8, 2019, 5:05pm UTC](https://discuss.elastic.co/t/beats-not-rolling-in-7-0-0/180207/4 "2019-05-08T17:05:05Z")

</div>

Elastic strives to provide sensible defaults. Making ILM on by default makes a lot of sense for most users because it's an easier way to manage indices over time. A new index gets created based on criteria that you specify so you avoid situations where you get really big indices or lots of tiny ones. The lifecycle policy controls when indices get created, shrunk down, deleted, and so on.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2019, 7:05pm UTC](https://discuss.elastic.co/t/beats-not-rolling-in-7-0-0/180207/5 "2019-06-05T19:05:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
