As, due to my job, I will have to get a Production ES environment in the future, I decided to create a testing ES environment at home.
This environment has three multi-role node. The three of them are master nodes, and as I didn't change any of the role option in their respectives Elasticsearch.yml files, I guess that all of them are data nodes aswell, (they all store shards and documents), they all are also cordinatoors and ingest nodes.
I though that this was the best approach as I couldn't count with much RAM and storage, but soon I will have extra hardware resources, so I'm recosidering to convert my three multi-role servers into masternodes dedicated server. I will create also at least a couple of data nodes aswell.
The point here is that I've been using and setting up filebeat and metric beat, which means that I've already uploaded some index templates and created ingesting index to/in those master servers. My indices are rotating on daily basis and they get removed when they are older than seven days. So I guess that once I've got my data dedicated servers the indices will be created in the dataservers as soon as my masterserver stop being dataservers too. Also, after a week, those indices that remained at that point in the dedicated master servers will dissappear.
But there are other indices which purpose are unknown to me and they make me worry.
If I go to Kibana -> Index Management I can find the following indices: .items-default-000001 .lists-default-000001
The following 'Data Streams': filebeat-8.2.1 metricbeat-8.2.1
So. Finally I took the time for investigating and trying to progress.
After applying ILM my beats indices dissapaired from the multirole nodes and started to get created in the datanodes. At that point I've reconfigured the three multiroles nodes to be just masternodes:
node.roles: [ master ]
At that point the environment failed when I tried to start it reporting that a node that contains shards can't stop being a datanode. And the thing is that beat indices are just a part of the whole index set.
So what I've done is transfering the rest of shards from my multirole nodes with IP's: 111, 112 and 113 to my Datanodes with IP's 115 and 116