# Behavior when changing ILM policy

**URL:** <https://discuss.elastic.co/t/behavior-when-changing-ilm-policy/307344>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [June 16, 2022, 5:45am UTC](https://discuss.elastic.co/t/behavior-when-changing-ilm-policy/307344 "2022-06-16T05:45:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Todd\_Lyons](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/todd_lyons/32/62321_2.png) [@Todd\_Lyons](https://discuss.elastic.co/u/Todd_Lyons)\
**Post date:** [June 16, 2022, 5:45am UTC](https://discuss.elastic.co/t/behavior-when-changing-ilm-policy/307344/1 "2022-06-16T05:45:29Z")

</div>

On an ES 7.3 system: I have an index which gets created with 10 primary shards and 1 replica. I have an ILM policy which rolls over at 500GB, and then shrinks 10 days later to 5 shards and 0 replicas, expiring after 60 days (after rollover).

I don't know if this is optimal. I was thinking of changing it to 8 shards + 1 replica, rollover at 400 GB to 4 shards, same expiration. However, I am unsure what will happen when I change the policy. If I change the number of shards in the template and shrink shards to 8 and 4, when the next index rolls over, it will properly create the new index with 8 shards. That part is fine. But when the shrink step fires, it will try to shrink 10 shards to 4, which will error because it's not a multiple.

What's the best way to make these adjustments? My guess is to create a new policy instead of modifying the existing one. Then when I edit the template to change the policy, also change the number of shards. Close? Or is there more coordination required?

Followup question: Is there any purpose to not doing the shrink step until a few days after rollover? This is just for instance and container logs, nothing extravagant. Maybe just as good to do it a day or two later? Gives enough time for late logs to get ingested and indexed if the pipeline stalls for a bit.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 16, 2022, 5:51am UTC](https://discuss.elastic.co/t/behavior-when-changing-ilm-policy/307344/2 "2022-06-16T05:51:17Z")

</div>

7.3 is very much [EOL](https://www.elastic.co/support/eol) and you should upgrade ASAP.

> [@Todd\_Lyons](#):
>
> My guess is to create a new policy instead of modifying the existing one

Yes, that would be suggested.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2022, 5:51am UTC](https://discuss.elastic.co/t/behavior-when-changing-ilm-policy/307344/3 "2022-07-14T05:51:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
