# Data streams vs ILM when using Fleet

**URL:** <https://discuss.elastic.co/t/data-streams-vs-ilm-when-using-fleet/324017>\
**Category:** Elastic Agent\
**Tags:** fleet, ilm-index-lifecycle-management\
**Created:** [January 26, 2023, 11:23am UTC](https://discuss.elastic.co/t/data-streams-vs-ilm-when-using-fleet/324017 "2023-01-26T11:23:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![djkprojects](https://avatars.discourse-cdn.com/v4/letter/d/d2c977/32.png) [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Post date:** [January 26, 2023, 11:23am UTC](https://discuss.elastic.co/t/data-streams-vs-ilm-when-using-fleet/324017/1 "2023-01-26T11:23:56Z")

</div>

Hello,

We are moving away from Beats towards the Centralised Elastic Agent / Fleet but struggling to understand the concept behind how the new approach is meant to work with ILM. We have multiple infrastructures to pull metrics from and we use namespace to differentiate between them e.g.:

**Infrastructure 1**  
metrics-system.cpu-infra1  
metrics-system.metrics-infra1  
... and so on

**Infrastructure 2**  
metrics-system.cpu-infra2  
metrics-system.metrics-infra2  
... and so on

By default they all use the built-in metrics ILM but we want to have different policies for Infra1 and Infra2.

We can create new templates and apply new ILMs but that would mean creating new template for each data stream which would make it really difficult to maintain with many infrastructures.

We are trying to understand the correct approach here is.

Thanks

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 26, 2023, 1:02pm UTC](https://discuss.elastic.co/t/data-streams-vs-ilm-when-using-fleet/324017/2 "2023-01-26T13:02:42Z")

</div>

> [@djkprojects](#):
>
> We are trying to understand the correct approach here is.

Unfortunately what you said is already the recommended approach by elastic, it is [documented here](https://www.elastic.co/guide/en/fleet/current/data-streams-ilm-tutorial.html).

You would need to to create a custom template for every dataset and every namespace, which is something really hard to maintain.

I had the same [issue](https://discuss.elastic.co/t/is-there-an-easy-way-to-change-the-lifecycle-policy-of-a-fleet-managed-data-stream/316941/4) when I started to use the integrations to get some logs and by suggestion of someone from Elastic I opened this [issue](https://github.com/elastic/kibana/issues/146792) on Github proposing some changes.

Iif you can wait I would suggest that you keep using Beats instead of Elastic Agent, in my experience Elastic Agent makes it easier to get the data, but make the management of the indices twice or more hard.

---

<div class="post-metadata">

**Author:** ![djkprojects](https://avatars.discourse-cdn.com/v4/letter/d/d2c977/32.png) [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Post date:** [January 26, 2023, 1:48pm UTC](https://discuss.elastic.co/t/data-streams-vs-ilm-when-using-fleet/324017/3 "2023-01-26T13:48:20Z")

</div>

We've been very reluctant to switch over to Elastic Agent because of that and other issues we've encountered but the decision has already been made.

What we were thinking of is rather than creating a copy of a template for each data stream we would create a combined template which would contain all the individual components e.g.:

 ![Screenshot 2023-01-26 134644](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d42d0550732056701dc9ed4590c321db3c2d504a.png)

and then apply ILM to the template.

but I'm not sure if this is not going to cause mapping conflicts

Any ideas if this is an option?

Thanks

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 26, 2023, 2:59pm UTC](https://discuss.elastic.co/t/data-streams-vs-ilm-when-using-fleet/324017/4 "2023-01-26T14:59:34Z")

</div>

I'm not sure, but I think that this approach may lead to some mapping conflicts and maybe also need to be redone when you update an agent.

Customizing anything related to mappings and ingest pipelines with the Elastic Agent gives you a lot of work, there are some [work](https://github.com/elastic/elasticsearch/issues/92426) being done to help this, but at this moment I would avoid doing that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 23, 2023, 2:59pm UTC](https://discuss.elastic.co/t/data-streams-vs-ilm-when-using-fleet/324017/5 "2023-02-23T14:59:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
