# Correct understanding of "aliases" in elasticsearch

**URL:** <https://discuss.elastic.co/t/correct-understanding-of-aliases-in-elasticsearch/318126>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [November 3, 2022, 4:50pm UTC](https://discuss.elastic.co/t/correct-understanding-of-aliases-in-elasticsearch/318126 "2022-11-03T16:50:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![alex\_96](https://avatars.discourse-cdn.com/v4/letter/a/ec9cab/32.png) [@alex\_96](https://discuss.elastic.co/u/alex_96)\
**Post date:** [November 3, 2022, 4:50pm UTC](https://discuss.elastic.co/t/correct-understanding-of-aliases-in-elasticsearch/318126/1 "2022-11-03T16:50:48Z")

</div>

Hello everyone, the question may be stupid, but I want to clarify: aliases in elasticsearch are essentially like links to one or more indexes or data streams, but recently during the creation of the ILM, I saw an error - "index.lifecycle.rollover\_alias" is empty or not defined, so, this "index.lifecycle.rollover\_alias" is the same as the usual "alias" or something else?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 3, 2022, 9:50pm UTC](https://discuss.elastic.co/t/correct-understanding-of-aliases-in-elasticsearch/318126/2 "2022-11-03T21:50:58Z")

</div>

Take a look at [this part](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-error-handling.html#_setting_index_lifecycle_rollover_alias_for_index_y_is_empty_or_not_defined) of the docs. It relates to the read alias once the underlying index has been rolled over.

> [@alex\_96](#):
>
> the question may be stupid

The only stupid question is the one that is unasked.

---

<div class="post-metadata">

**Author:** ![alex\_96](https://avatars.discourse-cdn.com/v4/letter/a/ec9cab/32.png) [@alex\_96](https://discuss.elastic.co/u/alex_96)\
**Post date:** [November 5, 2022, 11:52am UTC](https://discuss.elastic.co/t/correct-understanding-of-aliases-in-elasticsearch/318126/3 "2022-11-05T11:52:15Z")

</div>

Such a question, I read the manual and I seem to have done everything right, but I still get an error for indices, I use the vazuh template and add the following to it:

```auto
{
  "order": 0,
  "index_patterns": [
    "wazuh-alerts-4.x-*",
    "wazuh-archives-4.x-*"
  ],
  "settings": {
    "index.refresh_interval": "5s",
    "index.number_of_shards": "3",
    "index.number_of_replicas": "0",
    "index.auto_expand_replicas": "0-1",
    "index.lifecycle.name": "wazuh_ilm",
    "index.lifecycle.rollover_alias": "wazuh-alerts-4.x",
    "index.mapping.total_fields.limit": 10000,

```

then restart filebeat  
My wazuh\_ilm:

```auto
PUT _ilm/policy/wazuh_ilm
{
  "policy": {
    "phases": {
      "hot": {
        "min_age": "0ms",
        "actions": {
          "set_priority": {
            "priority": 100
          },
          "rollover": {
            "max_age": "1d"
          }
        }
      },
      "warm": {
        "min_age": "5d",
        "actions": {
          "set_priority": {
            "priority": 50
          }
        }
      },
      "delete": {
        "min_age": "7d",
        "actions": {
          "delete": {
            "delete_searchable_snapshot": true
          }
        }
      }
    }
  }
}

```

And after a while I get an error:

> illegal\_argument\_exception: setting [index.lifecycle.rollover\_alias] for index [wazuh-alerts-4.x-2022.11.02] is empty or not defined

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 5, 2022, 5:09pm UTC](https://discuss.elastic.co/t/correct-understanding-of-aliases-in-elasticsearch/318126/4 "2022-11-05T17:09:11Z")

</div>

I believe you need to create one index template per index pattern as two patterns can not share a rollover alias.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 6, 2022, 5:27pm UTC](https://discuss.elastic.co/t/correct-understanding-of-aliases-in-elasticsearch/318126/5 "2022-11-06T17:27:07Z")

</div>

Closed as duplicate of

> [@ILM elasticsearch not working](https://discuss.elastic.co/t/ilm-elasticsearch-not-working/318263):
>
> Such a question, I read the manual and I seem to have done everything right, but I still get an error for indices, I use the wazuh template and add the following to it: { "order": 0, "index\_patterns": ["wazuh-alerts-4.x-\*", "wazuh-archives-4.x-\*"], "settings": { "index.refresh\_interval": "5s", "index.number\_of\_shards": "3", "index.number\_of\_replicas": "0", "index.auto\_expand\_replicas": "0-1", "index.lifecycle.name": "wazuh\_ilm", "index.lifecycle.rollove…
