# \[BIG-IP ASM\] Could not index event to Elasticsearch

**URL:** <https://discuss.elastic.co/t/big-ip-asm-could-not-index-event-to-elasticsearch/373465>\
**Category:** Logstash\
**Created:** [January 21, 2025, 4:32pm UTC](https://discuss.elastic.co/t/big-ip-asm-could-not-index-event-to-elasticsearch/373465 "2025-01-21T16:32:12Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 22, 2025, 6:49pm UTC](https://discuss.elastic.co/t/big-ip-asm-could-not-index-event-to-elasticsearch/373465/8 "2025-01-22T18:49:06Z")

</div>

See here how to customize ILM for a data stream...

> **[Tutorial: Customize built-in ILM policies | Elasticsearch Guide \[8.17\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/example-using-index-lifecycle-policy.html)**

Basically Clone the existing Policy and Edit to your liking and give it a name... like `logs-custom`

Add a custom template you can do through the UI or this is the whole request in Kibana - Dev Tools

```auto
PUT _component_template/logs@custom
{
  "template": {
    "settings": {
      "index": {
        "lifecycle": {
          "name": "logs-custom"
        }
      }
    }
  }
}

```

If you are going to use agents... you must use data streams

If you want to you indices for some other data fine...

BUT you will then have a mixed approach and you you will still need to define rollover and ILM etc for your non-datastream data

---

_[View the full topic](https://discuss.elastic.co/t/big-ip-asm-could-not-index-event-to-elasticsearch/373465)._
