# Configure global retention time (ILM) for all logs and metrics

**URL:** <https://discuss.elastic.co/t/configure-global-retention-time-ilm-for-all-logs-and-metrics/353722>\
**Category:** Elastic Agent\
**Tags:** fleet, ilm-index-lifecycle-management, integrations\
**Created:** [February 20, 2024, 6:51pm UTC](https://discuss.elastic.co/t/configure-global-retention-time-ilm-for-all-logs-and-metrics/353722 "2024-02-20T18:51:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lpeter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lpeter/32/99176_2.png) [@lpeter](https://discuss.elastic.co/u/lpeter)\
**Post date:** [February 20, 2024, 6:51pm UTC](https://discuss.elastic.co/t/configure-global-retention-time-ilm-for-all-logs-and-metrics/353722/1 "2024-02-20T18:51:42Z")

</div>

Hello!

I'm using Elastic Agent with Fleet and Integrations. I'd like all collected data (metrics and logs) to be deleted after about N days. Is there a more elegant solution to this other than modifying the default "managed" `logs` and `metrics` lifecycle policies?

The method documented [here](https://www.elastic.co/guide/en/fleet/current/data-streams-ilm-tutorial.html) is waaay too granular, I don't know what integrations will be enabled in the future.

Looking at how the shipped index templates include component templates, I don't think creating a `logs@custom` component would work.

Could there be any side-effects of editing the aforementioned managed policies? Also, would a stack update override my changes?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 20, 2024, 7:28pm UTC](https://discuss.elastic.co/t/configure-global-retention-time-ilm-for-all-logs-and-metrics/353722/2 "2024-02-20T19:28:17Z")

</div>

Hi @lpeter

What Version are you on...

What are you using for shipping telemetry Beats / Agent / Both?

> [@lpeter](#):
>
> Looking at how the shipped index templates include component templates, I don't think creating a `logs@custom` component would work.

**Edit:** yup not the right place

---

<div class="post-metadata">

**Author:** ![lpeter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lpeter/32/99176_2.png) [@lpeter](https://discuss.elastic.co/u/lpeter)\
**Post date:** [February 20, 2024, 9:04pm UTC](https://discuss.elastic.co/t/configure-global-retention-time-ilm-for-all-logs-and-metrics/353722/3 "2024-02-20T21:04:37Z")

</div>

Thanks for your input.

Yeah, sorry, forgot to include the version: this is a new system still under planning, so we can assume the latest version for now (8.12.1).

I'd like to only use the Agent if possible, less variety is preferred. Also the docs are giving me the vibe that that's the way forward for new systems. 🙂

Regarding `logs@custom`: As far as I can tell it's only included by the generic `logs` index template, but integrations (usually) have a more specific template (like `logs-auditd_manager.auditd`) with higher priority, and those don't seem to include `logs@custom`. But I'll actually test it tomorrow, maybe it doesn't work the way I think it does.

(Looking around I see there's now a simpler lifecycle API for data streams in tech preview. Cool.)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 20, 2024, 9:54pm UTC](https://discuss.elastic.co/t/configure-global-retention-time-ilm-for-all-logs-and-metrics/353722/4 "2024-02-20T21:54:59Z")

</div>

> [@lpeter](#):
>
> (Looking around I see there's now a simpler lifecycle API for data streams in tech preview. Cool.)

Yes but it will be very simple...

You are right. The `logs@custom` is only used by default... probably not the right place... I will look around

The policy gets set globally in `logs@settings`

And, of course, you can actually edit the default "Managed" `logs` ILM policy .. Kibana will yell at you, but you absolutely can... you will just need to be careful when updating, I changed mine long ago and have not had any issues...

It has not been overwritten (but I check after every upgrade)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2024, 9:55pm UTC](https://discuss.elastic.co/t/configure-global-retention-time-ilm-for-all-logs-and-metrics/353722/5 "2024-03-19T21:55:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
