# Confg \`setup.template.settings.index.lifecycle.name\` is not working

**URL:** <https://discuss.elastic.co/t/confg-setup-template-settings-index-lifecycle-name-is-not-working/166253>\
**Category:** Beats\
**Created:** [January 30, 2019, 3:58am UTC](https://discuss.elastic.co/t/confg-setup-template-settings-index-lifecycle-name-is-not-working/166253 "2019-01-30T03:58:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kimxogus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimxogus/32/41030_2.png) [@kimxogus](https://discuss.elastic.co/u/kimxogus)\
**Post date:** [January 30, 2019, 3:58am UTC](https://discuss.elastic.co/t/confg-setup-template-settings-index-lifecycle-name-is-not-working/166253/1 "2019-01-30T03:58:54Z")

</div>

I'm using official filebeat and metricbeat docker image in kubernetes.

I set `setup.template.settings.index.lifecycle.name` config as `log-policy` and checked that config is properly set in beat pods, but log shows

```auto
2019-01-30T03:51:37.269Z INFO instance/beat.go:850 Set setup.template.name to 'filebeat-6.6.0' as ILM is enabled.
2019-01-30T03:51:37.269Z INFO instance/beat.go:856 Set setup.template.pattern to 'filebeat-6.6.0-*' as ILM is enabled.
2019-01-30T03:51:37.269Z INFO instance/beat.go:863 Set settings.index.lifecycle.rollover_alias in template to filebeat-6.6.0 as ILM is enabled.
2019-01-30T03:51:37.269Z INFO instance/beat.go:868 Set settings.index.lifecycle.name in template to beats-default-policy as ILM is enabled.

```

and lifecycle name in elasticsearch template is also `beats-default-policy`.

It seems lifecycle name config doesn't work and always set default value.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [January 30, 2019, 9:18am UTC](https://discuss.elastic.co/t/confg-setup-template-settings-index-lifecycle-name-is-not-working/166253/2 "2019-01-30T09:18:55Z")

</div>

Could you please share your whole configuration formatted using `</>`?

---

<div class="post-metadata">

**Author:** ![kimxogus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimxogus/32/41030_2.png) [@kimxogus](https://discuss.elastic.co/u/kimxogus)\
**Post date:** [January 30, 2019, 9:46am UTC](https://discuss.elastic.co/t/confg-setup-template-settings-index-lifecycle-name-is-not-working/166253/3 "2019-01-30T09:46:42Z")

</div>

```
filebeat:
  modules:
  - auth:
      enabled: false
      var.paths:
      - /var/log/auth.log
    module: system
    syslog:
      enabled: true
      var.paths:
      - /var/log/syslog
  prospectors:
  - enabled: true
    paths:
    - /var/log/*.log
    - /var/log/messages
    - /var/log/syslog
    type: log
  - containers.ids:
    - '*'
    processors:
    - add_kubernetes_metadata:
        in_cluster: true
    - drop_event:
        when:
          equals:
            kubernetes.container.name: filebeat
    type: docker
filebeat.config:
  modules:
    path: ${path.config}/modules.d/*.yml
    reload.enabled: false
  prospectors:
    path: ${path.config}/prospectors.d/*.yml
    reload.enabled: false
filebeat.prospectors:
- enabled: true
  paths:
  - /var/log/*.log
  - /var/log/messages
  - /var/log/syslog
  type: log
- containers.ids:
  - '*'
  processors:
  - add_kubernetes_metadata:
      in_cluster: true
  - drop_event:
      when:
        equals:
          kubernetes.container.name: filebeat
  type: docker
http.enabled: false
http.port: 5066
output:
  elasticsearch:
    enabled: true
    hosts:
    - es-monitoring-elasticsearch-client.monitoring.svc.cluster.local:9200
    ilm:
      enabled: true
  file:
    enabled: false
    filename: filebeat
    number_of_files: 5
    path: /usr/share/filebeat/data
    rotate_every_kb: 10000
  logstash:
    enabled: false
    hosts:
    - logstash.monitoring.svc.cluster.local:5044
output.file:
  filename: filebeat
  number_of_files: 5
  path: /usr/share/filebeat/data
  rotate_every_kb: 10000
processors:
- add_cloud_metadata: null
- add_kubernetes_metadata:
    in_cluster: true
- drop_event:
    when:
      equals:
        kubernetes.container.name: filebeat
- decode_json_fields:
    fields:
    - message
    max_depth: 1
    overwrite_keys: false
    process_array: false
    target: json
queue.spool:
  file:
    page_size: 16KiB
    path: ${path.data}/spool.dat
    size: 1024MiB
  write:
    buffer_size: 10MiB
    flush.events: 1024
    flush.timeout: 5s
setup:
  dashboards:
    enabled: true
  kibana:
    host: es-monitoring-kibana.monitoring.svc.cluster.local:443
    path: /monitoring
  template:
    enabled: true
    overwrite: true
    settings.index.lifecycle.name: log-policy
xpack:
  monitoring:
    enabled: true
```

---

<div class="post-metadata">

**Author:** ![kimxogus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimxogus/32/41030_2.png) [@kimxogus](https://discuss.elastic.co/u/kimxogus)\
**Post date:** [February 7, 2019, 5:31am UTC](https://discuss.elastic.co/t/confg-setup-template-settings-index-lifecycle-name-is-not-working/166253/4 "2019-02-07T05:31:57Z")

</div>

I also found that es index doesn't roll by day with `ilm.enabled: true`.

logs after jan, 30 are continuously written in `filebeat-6.6.0-2019.01.30-000001` which generated in jan, 30

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2019, 7:32am UTC](https://discuss.elastic.co/t/confg-setup-template-settings-index-lifecycle-name-is-not-working/166253/5 "2019-03-07T07:32:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
