# Create ILM on the timestamp field

**URL:** <https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172>\
**Category:** Elasticsearch\
**Created:** [February 13, 2024, 1:06pm UTC](https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172 "2024-02-13T13:06:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Debasis\_Mallick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debasis_mallick/32/123723_2.png) [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Post date:** [February 13, 2024, 1:06pm UTC](https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172/1 "2024-02-13T13:06:07Z")

</div>

Hi Team,

I want to create a ILM on the timestamp field (which received as field in the log file itself as epoch time). So I want create the ILM on basis of that field. Could you please let me know how we can achieve the same. Below is the snippet from index creation where timestamp is a field part of the index.

```auto
PUT /elastic
{
"settings": 
{
 "refresh_interval": "30s",
  "number_of_shards": "6",
  "number_of_replicas": "1"
   },
  "mappings":{
    "properties":{
      "sequence":{
      "type":"keyword"
      },
    "timestamp":{
	  "type": "date",
      "format": "epoch_millis"

```

Thanks,  
Debasis

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 13, 2024, 1:12pm UTC](https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172/2 "2024-02-13T13:12:03Z")

</div>

> [@Debasis\_Mallick](#):
>
> I want to create a ILM on the timestamp field (which received as field in the log file itself as epoch time).

Can you provide more context on what you want to do? It is not clear what you mean by create an ILM on the timestamp field.

---

<div class="post-metadata">

**Author:** ![Debasis\_Mallick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debasis_mallick/32/123723_2.png) [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Post date:** [February 14, 2024, 12:29am UTC](https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172/3 "2024-02-14T00:29:37Z")

</div>

Hi @leandrojmp ,

The log files we are receiving from the app team contain a timestamp (epoch timestamp) as a field within the logfile itself.  
Besides the timestamp, there are other fields that we have created INDEX.  
Following the initial data ingest to the INDEX, its size expands, necessitating the management of the INDEX.  
To effectively handle this, we recommend either splitting the index or implementing index rollover using an ILM policy. So I have been asked to create a new Index (by applying ILM policy) based on the timestamp field found in the log file received from the application team.

Could you please advise how we can achieve the same.

Thanks,  
Debasis

---

<div class="post-metadata">

**Author:** ![Debasis\_Mallick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debasis_mallick/32/123723_2.png) [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Post date:** [February 15, 2024, 6:54am UTC](https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172/4 "2024-02-15T06:54:25Z")

</div>

@leandrojmp Did you get any chance to look into the above request.

Thanks,  
Debasis

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 15, 2024, 7:12am UTC](https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172/5 "2024-02-15T07:12:52Z")

</div>

> [@Debasis\_Mallick](#):
>
> To effectively handle this, we recommend either splitting the index or implementing index rollover using an ILM policy. So I have been asked to create a new Index (by applying ILM policy) based on the timestamp field found in the log file received from the application team.

ILM works on complete indices and not data within the indices. It does not support creation of new indices through reindexing, if that is what you are looking for.

The best way to use ILM is to use time-based indices, e.g. data stream. This periodically creates a new index, e.g. when the size of the last index grown beyond a specified size or a time period has passed, and all new indexing goes into this last index. Complete indices are then deleted by ILM once the age (based on rollover timestamp) of the index exceed the configured retention period. This approach generally assume your data is immutable, so if that is not the case you may need to do something different.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2024, 7:13am UTC](https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172/6 "2024-03-14T07:13:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
