# Curator rollover with max\_size

**URL:** <https://discuss.elastic.co/t/curator-rollover-with-max-size/129966>\
**Category:** Elasticsearch\
**Created:** [April 29, 2018, 4:50pm UTC](https://discuss.elastic.co/t/curator-rollover-with-max-size/129966 "2018-04-29T16:50:47Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![vonpelz](https://avatars.discourse-cdn.com/v4/letter/v/e9a140/32.png) [@vonpelz](https://discuss.elastic.co/u/vonpelz)\
**Post date:** [April 29, 2018, 4:50pm UTC](https://discuss.elastic.co/t/curator-rollover-with-max-size/129966/1 "2018-04-29T16:50:47Z")

</div>

I'd like to use rollover to roll over indices when they get larger than 5GB.

I have an index called `metricbeat` that is constantly being written to. How do I rollover this to, say `metricbeat-1`, next time `metricbeat-2`, etc? Will setting `index_name:'<metricbeat-1}>'` under `extra_settings` do the trick?

The docs mention using alias for active index name, is this mandatory?

Any help/input appreciated.

Current preliminary config:

```
action: rollover
options:
  name: metricbeat
  conditions:
    max_size: 5gb
  extra_settings:
    index.number_of_shards: 1
    index.number_of_replicas: 1
    index_name:'<metricbeat-1}>'
  timeout_override:
  continue_if_exception: False
  disable_action: False
```

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 29, 2018, 6:36pm UTC](https://discuss.elastic.co/t/curator-rollover-with-max-size/129966/2 "2018-04-29T18:36:06Z")

</div>

> [@vonpelz](#):
>
> Will setting `index_name:'<metricbeat-1}>'` under extra\_settings do the trick?

This is unnecessary. Rollover will auto-increment the index name. I also recommend starting with padded numbers, e.g. `metricbeat-000001`, so that the index name length is always the same.

---

<div class="post-metadata">

**Author:** ![vonpelz](https://avatars.discourse-cdn.com/v4/letter/v/e9a140/32.png) [@vonpelz](https://discuss.elastic.co/u/vonpelz)\
**Post date:** [April 29, 2018, 6:51pm UTC](https://discuss.elastic.co/t/curator-rollover-with-max-size/129966/3 "2018-04-29T18:51:37Z")

</div>

Thank you. Reading the docs on Elasticsearch regarding rollover API helped clear up things as well.

So in a nutshell. As an example, create index called `metricbeat-000001`, create an alias to it with name `metricbeat`. Then use following Curator action. This would work?

```
action: rollover
options:
  name: metricbeat
  conditions:
    max_size: 5gb
  extra_settings:
    index.number_of_shards: 1
    index.number_of_replicas: 1
  timeout_override:
  continue_if_exception: False
  disable_action: False
```

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 29, 2018, 7:16pm UTC](https://discuss.elastic.co/t/curator-rollover-with-max-size/129966/4 "2018-04-29T19:16:46Z")

</div>

Yes. Provided, of course, that your version of Elasticsearch supports `max_size`, as that feature is Elasticsearch 6.1 and newer only.

---

<div class="post-metadata">

**Author:** ![vonpelz](https://avatars.discourse-cdn.com/v4/letter/v/e9a140/32.png) [@vonpelz](https://discuss.elastic.co/u/vonpelz)\
**Post date:** [April 29, 2018, 8:28pm UTC](https://discuss.elastic.co/t/curator-rollover-with-max-size/129966/5 "2018-04-29T20:28:11Z")

</div>

Great stuff! We're just getting started with setting up an Elastic stack cluster, so we're deploying 6.2.4 straight off the bat... Could you help out with another Curator query?  
We'd like to start deleting indices when their cumulative space passes a threshold, say 50GB. Assuming the previously mentioned index naming scheme, e.g. `metricbeat-000001` and `winlogbeat-000001`, will this config assure deletion of older indices when either cumulative index size passes the threshold? Will Curator group and calculate size for `metricbeat` and `winlogbeat` indices separately, or does one need a pattern filter as well?

```
action: delete_indices
description: >-
  Delete indices when their cumulative size is larger than 50GB.
options:
  ignore_empty_list: True
- filtertype: space
    disk_space: 50
    reverse: False
```

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 29, 2018, 9:01pm UTC](https://discuss.elastic.co/t/curator-rollover-with-max-size/129966/6 "2018-04-29T21:01:12Z")

</div>

You should add a filtertype for metricbeat indices, otherwise _all_ indices space consumption will be considered. I would also sort by index age, to guarantee they are deleted oldest first. `reverse: false` is not needed when `use_age` is true.

```auto
- filtertype: pattern
  kind: prefix
  value: metricbeat-
- filtertype: space
  disk_space: 50
  use_age: true
  source: creation_date

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2018, 9:01pm UTC](https://discuss.elastic.co/t/curator-rollover-with-max-size/129966/7 "2018-05-27T21:01:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
