# Change template and ILM policy from an existing Datastream

**URL:** <https://discuss.elastic.co/t/change-template-and-ilm-policy-from-an-existing-datastream/296608>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management, datastreams\
**Created:** [February 8, 2022, 1:52pm UTC](https://discuss.elastic.co/t/change-template-and-ilm-policy-from-an-existing-datastream/296608 "2022-02-08T13:52:55Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Angelos](https://avatars.discourse-cdn.com/v4/letter/a/4bbf92/32.png) [@Angelos](https://discuss.elastic.co/u/Angelos)\
**Post date:** [February 8, 2022, 1:52pm UTC](https://discuss.elastic.co/t/change-template-and-ilm-policy-from-an-existing-datastream/296608/1 "2022-02-08T13:52:55Z")

</div>

Hey!

In our Elasticsearch we use Datastreams which split our data to several streams like bellow.

So all the Datastreams have the same template and ILM policy. Since one of them has increased a lot I want to apply different ILM policy so I can delete data.

How can I change the ILM policy from only one of those templates, for example prod-data-metric2-ds?

**Our index\_template:**

```auto
Index pattern
   prod-data-*

Priority
    200

Component templates
    None

Data stream
    Yes

Version
    None

```

```auto
{
  "template": {
    "settings": {
      "index": {
        "lifecycle": {
          "name": "prod_data_metrics_policy"
        },
        "search": {
          "slowlog": {
            "level": "info",
            "threshold": {
              "fetch": {
                "warn": "-1",
                "trace": "-1",
                "debug": "-1",
                "info": "-1"
              },
              "query": {
                "warn": "60s",
                "trace": "0ms",
                "debug": "0ms",
                "info": "0ms"
              }
            }
          }
        },
        "refresh_interval": "60s",
        "number_of_shards": "3",
        "number_of_replicas": "1"
      }
    },
    "aliases": {},
    "mappings": {}
  }
}

```

**Datastreams:**

prod-data-metric1-ds  
prod-data-metric2-ds  
prod-data-metric3-ds  
prod-data-metric4-ds

/Angelos

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 8, 2022, 2:11pm UTC](https://discuss.elastic.co/t/change-template-and-ilm-policy-from-an-existing-datastream/296608/2 "2022-02-08T14:11:13Z")

</div>

If you are using component templates, you will need a new template with a [higher priority](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/indices-put-template.html#put-index-template-api-request-body) number.

This new template should match only the desired data-stream, for example `prod-data-metric2-*`.

If you are using legacy templates you will also need a new template matching only the desired data-stream, but in this case you will need it to have a higher `order` value.

---

<div class="post-metadata">

**Author:** ![Angelos](https://avatars.discourse-cdn.com/v4/letter/a/4bbf92/32.png) [@Angelos](https://discuss.elastic.co/u/Angelos)\
**Post date:** [February 8, 2022, 2:23pm UTC](https://discuss.elastic.co/t/change-template-and-ilm-policy-from-an-existing-datastream/296608/3 "2022-02-08T14:23:20Z")

</div>

I am using Index Template and it is configured to have

```auto
index pattern: 
prod-data-*

ILM policy:
prod_data_metrics_policy

```

If I create a new index template with

```auto
index pattern:
prod-data-metric2-*

ILM policy:
prod_data_metric2_policy

```

won't I have conflicts with duplicate datastreams with different templates?  
Since `prod-data-metric2-ds` is included in both `prod-data-metric2-*` and `prod-data-*`

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 8, 2022, 3:18pm UTC](https://discuss.elastic.co/t/change-template-and-ilm-policy-from-an-existing-datastream/296608/4 "2022-02-08T15:18:41Z")

</div>

You will need to use a higher priority or order for the specific template, depending if you are using the component templates or the legacy template.

A template with a higher order or priority will override the settings of a template with a lower order or priority.

---

<div class="post-metadata">

**Author:** ![Angelos](https://avatars.discourse-cdn.com/v4/letter/a/4bbf92/32.png) [@Angelos](https://discuss.elastic.co/u/Angelos)\
**Post date:** [February 9, 2022, 8:05am UTC](https://discuss.elastic.co/t/change-template-and-ilm-policy-from-an-existing-datastream/296608/5 "2022-02-09T08:05:02Z")

</div>

Thank you for your fast responses!  
I have Lifecycle errors:

```auto
Index lifecycle error
exception: Concurrent modification of alias [prod-data-metric2-ds] during rollover

```

Should I put rollover\_alias in the template?  
If I do that should I create an initial index?

```auto
PUT test-000001
{
  "aliases": {
    "test-alias":{
      "is_write_index": true 
    }
  }
}

```

The problem is that there are already indices for that datastream.

---

<div class="post-metadata">

**Author:** ![Angelos](https://avatars.discourse-cdn.com/v4/letter/a/4bbf92/32.png) [@Angelos](https://discuss.elastic.co/u/Angelos)\
**Post date:** [February 11, 2022, 10:04am UTC](https://discuss.elastic.co/t/change-template-and-ilm-policy-from-an-existing-datastream/296608/6 "2022-02-11T10:04:21Z")

</div>

@leandrojmp It seems the latest implementation works but I still have a lot lifecycling errors and many new empty indices.

> Index lifecycle error  
> exception: Concurrent modification of alias [prod-data-metric2-ds] during rollover

The errors are being reduced but very slowly, is this normal?

/Angelos

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 11, 2022, 2:03pm UTC](https://discuss.elastic.co/t/change-template-and-ilm-policy-from-an-existing-datastream/296608/7 "2022-02-11T14:03:51Z")

</div>

If your policy has a rollover you can't apply it manually to index, you need to use templates.

Check this answer to your other [post](https://discuss.elastic.co/t/switching-policies-for-an-index/296200/5).

When you have a rollover in a policy, do not change the policies manually, change it in the templates and let the template take care of the change.

---

<div class="post-metadata">

**Author:** ![Angelos](https://avatars.discourse-cdn.com/v4/letter/a/4bbf92/32.png) [@Angelos](https://discuss.elastic.co/u/Angelos)\
**Post date:** [February 11, 2022, 2:43pm UTC](https://discuss.elastic.co/t/change-template-and-ilm-policy-from-an-existing-datastream/296608/8 "2022-02-11T14:43:28Z")

</div>

So now that I have done that, is there any way I can fix it or should I wait until all the errors will be resolved.

/Angelos

---

<div class="post-metadata">

**Author:** ![Angelos](https://avatars.discourse-cdn.com/v4/letter/a/4bbf92/32.png) [@Angelos](https://discuss.elastic.co/u/Angelos)\
**Post date:** [February 16, 2022, 9:56am UTC](https://discuss.elastic.co/t/change-template-and-ilm-policy-from-an-existing-datastream/296608/9 "2022-02-16T09:56:38Z")

</div>

To solve the errors I removed the ILM policy from all the indices, recreate the policy and applied the new policy to the latest index.  
Now the rollover works correctly with the data ingestion.

Note that when I tried to remove the policy targeting the Datastream,

```auto
POST prod-data-metric2-ds/_ilm/remove

```

didn't remove it from all the indices. I needed to remove it manually from each remaining index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2022, 9:57am UTC](https://discuss.elastic.co/t/change-template-and-ilm-policy-from-an-existing-datastream/296608/10 "2022-03-16T09:57:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
