# Confused about ilm, index templates and new indices

**URL:** <https://discuss.elastic.co/t/confused-about-ilm-index-templates-and-new-indices/271996>\
**Category:** Beats\
**Tags:** ilm-index-lifecycle-management, packetbeat\
**Created:** [May 3, 2021, 1:57pm UTC](https://discuss.elastic.co/t/confused-about-ilm-index-templates-and-new-indices/271996 "2021-05-03T13:57:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tterranigma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tterranigma/32/48360_2.png) [@tterranigma](https://discuss.elastic.co/u/tterranigma)\
**Post date:** [May 3, 2021, 1:57pm UTC](https://discuss.elastic.co/t/confused-about-ilm-index-templates-and-new-indices/271996/1 "2021-05-03T13:57:56Z")

</div>

I have a serve where I install some beats (e.g. packetbeat) but I don't enable the systemd service. I only use `packetbeat setup --index-management` on this server so that the packetbeat index template and the ILM policy get inserted into elasticsearch. This works fine, I can see the index template and ILM policy in Kibana. These are the settings I use:

```auto
setup:
  ilm:
    check_exists: false
    enabled: true
    overwrite: true
    pattern: '{now/d}-000001'
    rollover_alias: packetbeat-%{[agent.version]}
  template:
    enabled: true
    overwrite: true
    pattern: '%{[agent.name]}-%{[agent.version]}-*'
    type: legacy

```

On a second server, I install packetbeat with the following settings:

```auto
setup:
  ilm:
    check_exists: false
    enabled: true
    overwrite: false
    pattern: '{now/d}-000001'
    rollover_alias: packetbeat-%{[agent.version]}
  template:
    enabled: false

```

On the second server I enable the packetbeat service. I can see logs being sent to elasticsearch. But there are some problems and some questions that I have:

- The index packetbeat creates is `packetbeat-7.12.1`. This does not match the template pattern that has a dash at the end: `packetbeat-7.12.1-` and ILM is not enforced neither are the template settings used.
- If I enable the ILM policy, then I can't change the `setup.template.pattern` in the first server.
- If I set `setup.template.enabled: true` on the second server, then the index template gets used and ILM is enabled.

However, I cannot understand why I need to set `setup.template.enabled: true` to the second packetbeat for the whole chain to workk. This setting seems like a setting that is used on beat startup and instructs it whether to push the tempate to elasticsearch or not. At least, this is the case with the `setup.ilm.enabled` and `setup.dashboards.enabled` settings. My approach was to disable templating loading on the second server, because the elastic user that packetbeat uses in that installation does not have permissions to manage index templates.

Still, `setup.template.enabled` seems to affect the name of the index that packetbeat will push to. If this is correct and intended, it should be documented in the `packetbeat.reference.yml` at least.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2021, 3:58pm UTC](https://discuss.elastic.co/t/confused-about-ilm-index-templates-and-new-indices/271996/2 "2021-05-31T15:58:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
