# Dynamic rollover alias and template name

**URL:** <https://discuss.elastic.co/t/dynamic-rollover-alias-and-template-name/280371>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [August 4, 2021, 12:02am UTC](https://discuss.elastic.co/t/dynamic-rollover-alias-and-template-name/280371 "2021-08-04T00:02:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![tong6462](https://avatars.discourse-cdn.com/v4/letter/t/9fc348/32.png) [@tong6462](https://discuss.elastic.co/u/tong6462)\
**Post date:** [August 4, 2021, 12:02am UTC](https://discuss.elastic.co/t/dynamic-rollover-alias-and-template-name/280371/1 "2021-08-04T00:02:42Z")

</div>

Hi.

Could it be possible to allow using variables in the properties " **ilm\_rollover\_alias**" as well as " **template\_name**" in the Elasticsearch output, like we can do with the "index" property?

Index lifecycle error  
illegal\_argument\_exception: index.lifecycle.rollover\_alias [server-log-\*-] does not point to index [server-log-demoproduct-2021.08.03]  
Stack trace

My indices is "server-log-%{product}-%{+YYYY.MM.dd}"

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 4, 2021, 12:14am UTC](https://discuss.elastic.co/t/dynamic-rollover-alias-and-template-name/280371/2 "2021-08-04T00:14:45Z")

</div>

In the output of what sorry?

---

<div class="post-metadata">

**Author:** ![tong6462](https://avatars.discourse-cdn.com/v4/letter/t/9fc348/32.png) [@tong6462](https://discuss.elastic.co/u/tong6462)\
**Post date:** [August 4, 2021, 12:41am UTC](https://discuss.elastic.co/t/dynamic-rollover-alias-and-template-name/280371/3 "2021-08-04T00:41:09Z")

</div>

> [@warkolm](#):
>
> In the output of what sorry?

Hi. This is error in kibana  
java.lang.IllegalArgumentException: index.lifecycle.rollover\_alias [server-log-\*-] does not point to index [server-log-demovn-2021.08.03]  
at org.elasticsearch.xpack.core.ilm.WaitForRolloverReadyStep.evaluateCondition(WaitForRolloverReadyStep.java:124)  
at org.elasticsearch.xpack.ilm.IndexLifecycleRunner.runPeriodicStep(IndexLifecycleRunner.java:175)  
at org.elasticsearch.xpack.ilm.IndexLifecycleService.triggerPolicies(IndexLifecycleService.java:335)  
at org.elasticsearch.xpack.ilm.IndexLifecycleService.triggered(IndexLifecycleService.java:273)  
at org.elasticsearch.xpack.core.scheduler.SchedulerEngine.notifyListeners(SchedulerEngine.java:184)  
at org.elasticsearch.xpack.core.scheduler.SchedulerEngine$ActiveSchedule.run(SchedulerEngine.java:217)  
at java.base/java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:515)  
at java.base/java.util.concurrent.FutureTask.run(FutureTask.java:264)  
at java.base/java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.run(ScheduledThreadPoolExecutor.java:304)  
at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1130)  
at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:630)  
at java.base/java.lang.Thread.run(Thread.java:831)

My template setting  
{  
"index": {  
"lifecycle": {  
"name": "server-log-policy",  
"rollover\_alias": "server-log-\*-"  
},  
"refresh\_interval": "5s",  
"number\_of\_shards": "1",  
"number\_of\_replicas": "0"  
}  
}

logstash output

elasticsearch {  
hosts =\> ["[http://10.10.10.8:9200](http://10.10.10.8:9200)"]  
#ilm\_enabled =\> "true"  
#ilm\_pattern =\> "000001"  
#ilm\_policy =\> "server-log-policy"  
#ilm\_rollover\_alias =\> "server-log"  
#manage\_template =\> false  
user =\> "elastic"  
password =\> "xxx"  
index =\> "server-log-%{product}-%{+YYYY.MM.dd}"  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 4, 2021, 12:42am UTC](https://discuss.elastic.co/t/dynamic-rollover-alias-and-template-name/280371/4 "2021-08-04T00:42:47Z")

</div>

Ok that makes more sense, you mean Logstash not Elasticsearch 🙂  
When you send data from Logstash to an ILM policy in Elasticsearch, you need to send it to the write alias and not the underlying index pattern.

Just a quick ask for the future - please format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

---

<div class="post-metadata">

**Author:** ![tong6462](https://avatars.discourse-cdn.com/v4/letter/t/9fc348/32.png) [@tong6462](https://discuss.elastic.co/u/tong6462)\
**Post date:** [August 4, 2021, 1:22am UTC](https://discuss.elastic.co/t/dynamic-rollover-alias-and-template-name/280371/5 "2021-08-04T01:22:39Z")

</div>

Thank for your reply. I have changed configure in logstash to send data to the write alias.

```auto
elasticsearch {
                        hosts => ["http://10.10.10.8:9200"]
                        ilm_enabled => "true"
                        #ilm_pattern => "000001"
                        ilm_policy => "server-log-policy"
                        ilm_rollover_alias => "server-log-%{product}"
                        #manage_template => false
                        user => "elastic"
                        password => "1DoQN06dmFOIdU3ZZhPJ"
                        #index => "server-log-%{gameid}-%{+YYYY.MM.dd}"
                }

```

But logstash is failed

```auto
[2021-08-04T08:12:33,255][ERROR][logstash.outputs.elasticsearch][log] Failed to install template. {:message=>"Malformed escape pair at index 23: /_template/server-log-%{product}"

```

I found a similar problem here [Impossible to use variables in ilm\_rollover\_alias · Issue #10962 · elastic/logstash · GitHub](https://github.com/elastic/logstash/issues/10962)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 4, 2021, 1:23am UTC](https://discuss.elastic.co/t/dynamic-rollover-alias-and-template-name/280371/6 "2021-08-04T01:23:40Z")

</div>

Correct, you cannot use variables there unfortunately.

---

<div class="post-metadata">

**Author:** ![tong6462](https://avatars.discourse-cdn.com/v4/letter/t/9fc348/32.png) [@tong6462](https://discuss.elastic.co/u/tong6462)\
**Post date:** [August 4, 2021, 1:32am UTC](https://discuss.elastic.co/t/dynamic-rollover-alias-and-template-name/280371/7 "2021-08-04T01:32:57Z")

</div>

Thank for your reply.  
I will disable rollover option in ilm policy And manage rollover by the underlying index pattern in logstash configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2021, 1:33am UTC](https://discuss.elastic.co/t/dynamic-rollover-alias-and-template-name/280371/8 "2021-09-01T01:33:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
