# Can anyone confirm my use of the \_ttl feature?

**URL:** <https://discuss.elastic.co/t/can-anyone-confirm-my-use-of-the--ttl-feature/11872>\
**Category:** Elasticsearch\
**Created:** [May 8, 2013, 6:41am UTC](https://discuss.elastic.co/t/can-anyone-confirm-my-use-of-the--ttl-feature/11872 "2013-05-08T06:41:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robert\_Campbell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robert_campbell/32/59172_2.png) [@Robert\_Campbell](https://discuss.elastic.co/u/Robert_Campbell)\
**Post date:** [May 8, 2013, 6:41am UTC](https://discuss.elastic.co/t/can-anyone-confirm-my-use-of-the--ttl-feature/11872/1 "2013-05-08T06:41:20Z")

</div>

My elasticsearch install is pretty simple, but I am having trouble  
verifying the use of the \_ttl parameter. It would seem from the  
documentation it needs to be in the "mapping" part of the config file (  
[http://www.elasticsearch.org/guide/reference/mapping/ttl-field/](http://www.elasticsearch.org/guide/reference/mapping/ttl-field/)) I have  
created the follwing config:  
{  
"template": "logstash\*",  
"settings": {  
"index.cache.filter.expire": "5m",  
"index.cache.field.expire": "5m",  
"index.refresh\_interval": "5s",  
"[index.store.compress.tv](http://index.store.compress.tv)": true,  
"index.store.compress.stored": true  
"\_ttl": {  
"enabled": true,  
"default": "7d"  
},  
},  
"mappings": {  
"_default_": {  
"\_all": {  
"enabled": false  
}  
}  
}  
}

I tried using the \_ttl field in the mappings part, but that was disastrous  
(elasticsearch basically refused to create logstash\* indexes, not good at  
00:00 ☹ ).

Thanks in advance for any replies.

Robert Campbell

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Robert\_Campbell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robert_campbell/32/59172_2.png) [@Robert\_Campbell](https://discuss.elastic.co/u/Robert_Campbell)\
**Post date:** [May 8, 2013, 6:45am UTC](https://discuss.elastic.co/t/can-anyone-confirm-my-use-of-the--ttl-feature/11872/2 "2013-05-08T06:45:00Z")

</div>

It seems my settings are not working ☹

Doing a GET from logstash\*/\_settings give me this for the index created a  
00:00 tonight.

logstash-2013.05.08: {  
settings: {  
index.cache.field.expire: 5m  
index.refresh\_interval: 5s  
index.cache.filter.expire: 5m  
[index.store.compress.tv](http://index.store.compress.tv): true  
index.store.compress.stored: true  
index.number\_of\_shards: 5  
index.number\_of\_replicas: 1  
index.version.created: 200699  
}  
}

On Wednesday, May 8, 2013 8:41:20 AM UTC+2, Robert Campbell wrote:

> My elasticsearch install is pretty simple, but I am having trouble  
> verifying the use of the \_ttl parameter. It would seem from the  
> documentation it needs to be in the "mapping" part of the config file (  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/mapping/ttl-field/)) I have  
> created the follwing config:  
> {  
> "template": "logstash\*",  
> "settings": {  
> "index.cache.filter.expire": "5m",  
> "index.cache.field.expire": "5m",  
> "index.refresh\_interval": "5s",  
> "[index.store.compress.tv](http://index.store.compress.tv)": true,  
> "index.store.compress.stored": true  
> "\_ttl": {  
> "enabled": true,  
> "default": "7d"  
> },  
> },  
> "mappings": {  
> "_default_": {  
> "\_all": {  
> "enabled": false  
> }  
> }  
> }  
> }
> 
> I tried using the \_ttl field in the mappings part, but that was disastrous  
> (elasticsearch basically refused to create logstash\* indexes, not good at  
> 00:00 ☹ ).
> 
> Thanks in advance for any replies.
> 
> Robert Campbell

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Kevin\_Decherf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_decherf/32/2351_2.png) [@Kevin\_Decherf](https://discuss.elastic.co/u/Kevin_Decherf)\
**Post date:** [May 8, 2013, 7:46am UTC](https://discuss.elastic.co/t/can-anyone-confirm-my-use-of-the--ttl-feature/11872/3 "2013-05-08T07:46:09Z")

</div>

Le 8 mai 2013 08:41, "Robert Campbell" [camprr@gmail.com](mailto:camprr@gmail.com) a écrit :

> My elasticsearch install is pretty simple, but I am having trouble  
> verifying the use of the \_ttl parameter. It would seem from the  
> documentation it needs to be in the "mapping" part of the config file (  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/mapping/ttl-field/)) I have  
> created the follwing config:  
> {  
> "template": "logstash\*",  
> "settings": {  
> "index.cache.filter.expire": "5m",  
> "index.cache.field.expire": "5m",  
> "index.refresh\_interval": "5s",  
> "[index.store.compress.tv](http://index.store.compress.tv)": true,  
> "index.store.compress.stored": true  
> "\_ttl": {  
> "enabled": true,  
> "default": "7d"  
> },  
> },  
> "mappings": {  
> "_default_": {  
> "\_all": {  
> "enabled": false  
> }  
> }  
> }  
> }
> 
> I tried using the \_ttl field in the mappings part, but that was  
> disastrous (elasticsearch basically refused to create logstash\* indexes,  
> not good at 00:00 ☹ ).

Hi,

The \_ttl field must be set in the mapping section. Please paste your  
updated configuration and the error returned by ES when you try to create a  
new index.

Sent from my phone

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Robert\_Campbell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robert_campbell/32/59172_2.png) [@Robert\_Campbell](https://discuss.elastic.co/u/Robert_Campbell)\
**Post date:** [May 8, 2013, 9:27am UTC](https://discuss.elastic.co/t/can-anyone-confirm-my-use-of-the--ttl-feature/11872/4 "2013-05-08T09:27:40Z")

</div>

This:

{  
"template": "logstash\*",  
"settings": {  
"index.cache.filter.expire": "5m",  
"index.cache.field.expire": "5m",  
"index.refresh\_interval": "5s",  
"[index.store.compress.tv](http://index.store.compress.tv)": true,  
"index.store.compress.stored": true  
},  
"mappings": {  
"\_ttl": {  
"enabled": true,  
"default": "7d"  
},  
"_default_": {  
"\_all": {  
"enabled": false  
}  
}  
}  
}

Results in (in the logfile):

[2013-05-08 11:15:51,696][WARN][cluster.metadata] [Space Turnip]  
[logstash-2013.05.08] failed to create  
org.elasticsearch.index.mapper.MapperParsingException: mapping [\_ttl]  
at  
org.elasticsearch.cluster.metadata.MetaDataCreateIndexService$1.execute(MetaDataCreateIndexService.java:285)  
at  
org.elasticsearch.cluster.service.InternalClusterService$2.run(InternalClusterService.java:223)  
at  
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1146)  
at  
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)  
at java.lang.Thread.run(Thread.java:679)  
Caused by: org.elasticsearch.indices.InvalidTypeNameException: mapping type  
name [_ttl] can't start with '_'  
at  
org.elasticsearch.index.mapper.MapperService.merge(MapperService.java:201)  
at  
org.elasticsearch.index.mapper.MapperService.merge(MapperService.java:189)  
at  
org.elasticsearch.cluster.metadata.MetaDataCreateIndexService$1.execute(MetaDataCreateIndexService.java:282)  
... 4 more

On Wed, May 8, 2013 at 9:46 AM, Kevin Decherf [kevin@kdecherf.com](mailto:kevin@kdecherf.com) wrote:

> Le 8 mai 2013 08:41, "Robert Campbell" [camprr@gmail.com](mailto:camprr@gmail.com) a écrit :
> 
> > My elasticsearch install is pretty simple, but I am having trouble  
> > verifying the use of the \_ttl parameter. It would seem from the  
> > documentation it needs to be in the "mapping" part of the config file (  
> > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/mapping/ttl-field/)) I have  
> > created the follwing config:  
> > {  
> > "template": "logstash\*",  
> > "settings": {  
> > "index.cache.filter.expire": "5m",  
> > "index.cache.field.expire": "5m",  
> > "index.refresh\_interval": "5s",  
> > "[index.store.compress.tv](http://index.store.compress.tv)": true,  
> > "index.store.compress.stored": true  
> > "\_ttl": {  
> > "enabled": true,  
> > "default": "7d"  
> > },  
> > },  
> > "mappings": {  
> > "_default_": {  
> > "\_all": {  
> > "enabled": false  
> > }  
> > }  
> > }  
> > }
> > 
> > I tried using the \_ttl field in the mappings part, but that was  
> > disastrous (elasticsearch basically refused to create logstash\* indexes,  
> > not good at 00:00 ☹ ).
> 
> Hi,
> 
> The \_ttl field must be set in the mapping section. Please paste your  
> updated configuration and the error returned by ES when you try to create a  
> new index.
> 
> Sent from my phone
> 
> --  
> You received this message because you are subscribed to a topic in the  
> Google Groups "elasticsearch" group.  
> To unsubscribe from this topic, visit  
> [https://groups.google.com/d/topic/elasticsearch/rxhZhrsNaTg/unsubscribe?hl=en-US](https://groups.google.com/d/topic/elasticsearch/rxhZhrsNaTg/unsubscribe?hl=en-US)  
> .  
> To unsubscribe from this group and all its topics, send an email to  
> [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Kevin\_Decherf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_decherf/32/2351_2.png) [@Kevin\_Decherf](https://discuss.elastic.co/u/Kevin_Decherf)\
**Post date:** [May 8, 2013, 10:02am UTC](https://discuss.elastic.co/t/can-anyone-confirm-my-use-of-the--ttl-feature/11872/5 "2013-05-08T10:02:45Z")

</div>

Le 8 mai 2013 11:27, "Robert Campbell" [camprr@gmail.com](mailto:camprr@gmail.com) a écrit :

> This:
> 
> {  
> "template": "logstash\*",  
> "settings": {  
> "index.cache.filter.expire": "5m",  
> "index.cache.field.expire": "5m",  
> "index.refresh\_interval": "5s",  
> "[index.store.compress.tv](http://index.store.compress.tv)": true,  
> "index.store.compress.stored": true  
> },  
> "mappings": {  
> "\_ttl": {  
> "enabled": true,  
> "default": "7d"  
> },  
> "_default_": {  
> "\_all": {  
> "enabled": false  
> }  
> }  
> }  
> }

I don't know how templating exactly works but you should move "\_ttl" into  
"_default_" object

Sent from my phone

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Robert\_Campbell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robert_campbell/32/59172_2.png) [@Robert\_Campbell](https://discuss.elastic.co/u/Robert_Campbell)\
**Post date:** [May 8, 2013, 10:58am UTC](https://discuss.elastic.co/t/can-anyone-confirm-my-use-of-the--ttl-feature/11872/6 "2013-05-08T10:58:10Z")

</div>

Ok, will try, thanks for the hint!

On Wed, May 8, 2013 at 12:02 PM, Kevin Decherf [kevin@kdecherf.com](mailto:kevin@kdecherf.com) wrote:

> Le 8 mai 2013 11:27, "Robert Campbell" [camprr@gmail.com](mailto:camprr@gmail.com) a écrit :
> 
> > This:
> > 
> > {  
> > "template": "logstash\*",  
> > "settings": {  
> > "index.cache.filter.expire": "5m",  
> > "index.cache.field.expire": "5m",  
> > "index.refresh\_interval": "5s",  
> > "[index.store.compress.tv](http://index.store.compress.tv)": true,  
> > "index.store.compress.stored": true  
> > },  
> > "mappings": {  
> > "\_ttl": {  
> > "enabled": true,  
> > "default": "7d"  
> > },  
> > "_default_": {  
> > "\_all": {  
> > "enabled": false  
> > }  
> > }  
> > }  
> > }
> 
> I don't know how templating exactly works but you should move "\_ttl" into  
> "_default_" object
> 
> Sent from my phone
> 
> --  
> You received this message because you are subscribed to a topic in the  
> Google Groups "elasticsearch" group.  
> To unsubscribe from this topic, visit  
> [https://groups.google.com/d/topic/elasticsearch/rxhZhrsNaTg/unsubscribe?hl=en-US](https://groups.google.com/d/topic/elasticsearch/rxhZhrsNaTg/unsubscribe?hl=en-US)  
> .  
> To unsubscribe from this group and all its topics, send an email to  
> [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:37am UTC](https://discuss.elastic.co/t/can-anyone-confirm-my-use-of-the--ttl-feature/11872/7 "2017-07-06T02:37:39Z")

</div>


