# Can filebeats access the lifecycle policies on Elasticsearch?

**URL:** <https://discuss.elastic.co/t/can-filebeats-access-the-lifecycle-policies-on-elasticsearch/273882>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 25, 2021, 3:19am UTC](https://discuss.elastic.co/t/can-filebeats-access-the-lifecycle-policies-on-elasticsearch/273882 "2021-05-25T03:19:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pk.241011](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pk.241011/32/86285_2.png) [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Post date:** [May 25, 2021, 3:19am UTC](https://discuss.elastic.co/t/can-filebeats-access-the-lifecycle-policies-on-elasticsearch/273882/1 "2021-05-25T03:19:49Z")

</div>

In case of logstash I was able to specify an existing policy name in the Elasticsearch output.  
Something like:

```
output
{
        elasticsearch
        {
                hosts => "http://XXXXXXXXXXX"
                ilm_enabled => "true"
                ilm_rollover_alias => "log-device"
                ilm_pattern => "000001"
                ilm_policy => "my_policy"
                user => 'YYYYYYYY'
                password => 'ZZZZZZZZ'
        }
}

```

However in case of filebeat the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/ilm.html#setup-ilm-policy_name-option) says:

`setup.ilm.policy_name : The name to use for the lifecycle policy. The default is filebeat.`

So can I put `my_policy` here and expect that it will work? Something like this:

`setup.ilm.policy_name : my_policy`

If not I will have to write my own JSON based lifecycle policy to reduce the number days the indices are retained to one week. Is there any other way to achieve the same in a easier way?

It is super useful to manage the number of days the indices are retained at a central place like Kibana console. The deplyoments of the filebeat can be across hundreds of PC. And it will be a nightmare to change the JSON files manually.

I hope my understanding of the situation is wrong and there are better ways to manage the number of days I retain the indices created by filebeat.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 25, 2021, 3:32am UTC](https://discuss.elastic.co/t/can-filebeats-access-the-lifecycle-policies-on-elasticsearch/273882/2 "2021-05-25T03:32:15Z")

</div>

> [@pk.241011](#):
>
> So can I put `my_policy` here and expect that it will work?

If that policy exists, yes,

---

<div class="post-metadata">

**Author:** ![pk.241011](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pk.241011/32/86285_2.png) [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Post date:** [May 25, 2021, 3:34am UTC](https://discuss.elastic.co/t/can-filebeats-access-the-lifecycle-policies-on-elasticsearch/273882/3 "2021-05-25T03:34:44Z")

</div>

Oh that is super nice. Maybe the documentation can be updated as

> [@pk.241011](#):
>
> setup.ilm.policy\_name : The name of the lifecycle policy to be used. (It should exist on Elasticsearch)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 25, 2021, 3:35am UTC](https://discuss.elastic.co/t/can-filebeats-access-the-lifecycle-policies-on-elasticsearch/273882/4 "2021-05-25T03:35:30Z")

</div>

Not sure I follow, it still needs to exist in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 22, 2021, 5:36am UTC](https://discuss.elastic.co/t/can-filebeats-access-the-lifecycle-policies-on-elasticsearch/273882/5 "2021-06-22T05:36:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
