# Elastic agent indices - ILM

**URL:** <https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243>\
**Category:** Elastic Agent\
**Created:** [September 4, 2023, 10:18am UTC](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243 "2023-09-04T10:18:45Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tyty](https://avatars.discourse-cdn.com/v4/letter/t/35a633/32.png) [@Tyty](https://discuss.elastic.co/u/Tyty)\
**Post date:** [September 4, 2023, 10:18am UTC](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243/1 "2023-09-04T10:18:45Z")

</div>

Hi All,

Currently using ELK stack 8.91.  
Fleet enable. Elasticc-agent deployed on around 100 Servers/vm.  
I notice that indexes will never be cleared. Seems to be a default behavior.  
I need to know how to setup an Index Lifecycle Policies to clean old logs.  
Can you let me know how can I setup this ?

Thanks in advance,  
Regards,

Tyty

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 4, 2023, 11:28am UTC](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243/2 "2023-09-04T11:28:34Z")

</div>

Hello and welcome,

You have two options in this case.

One is to simple edit the default lifecycle policy named `logs` to add a delete phase.

The second option is to create a custom template with a custom ILM for **each** dataset of **each** integration, which can be a lot of work.

To create a custom template you need to follow [this documentation](https://www.elastic.co/guide/en/fleet/current/data-streams-ilm-tutorial.html).

---

<div class="post-metadata">

**Author:** ![Tyty](https://avatars.discourse-cdn.com/v4/letter/t/35a633/32.png) [@Tyty](https://discuss.elastic.co/u/Tyty)\
**Post date:** [September 4, 2023, 12:17pm UTC](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243/3 "2023-09-04T12:17:13Z")

</div>

Hi leandrojmp,

Thank you for your reply.  
I've just edit the default lifecycle policy.  
kee you infomr on this.

Regards,  
Tyty

---

<div class="post-metadata">

**Author:** ![Tyty](https://avatars.discourse-cdn.com/v4/letter/t/35a633/32.png) [@Tyty](https://discuss.elastic.co/u/Tyty)\
**Post date:** [September 12, 2023, 2:35pm UTC](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243/4 "2023-09-12T14:35:51Z")

</div>

Hi,

So, I change ILM logs as follow :  
Maximum primary shard size : 10Mb  
Maximum age : 2 days  
Delete phase Move data into phase when: 12 hours

As far as I can see, used space is still growing. Data seems to be deleted but used space is a mess.  
Any ideas ?  
Regards,

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 12, 2023, 3:20pm UTC](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243/5 "2023-09-12T15:20:37Z")

</div>

> [@Tyty](#):
>
> Maximum primary shard size : 10Mb  
> Maximum age : 2 days  
> Delete phase Move data into phase when: 12 hours

You should increase the maxium primary shard size, 10 MB is way too small and not recommended at all. The recommended size for primary shard is something close to 50 GB.

With a primary shard size of 10 MB you risk creating too many indices/shards that can impact your cluster and even block writes if you reach the maximum shards allowed.

> [@Tyty](#):
>
> Data seems to be deleted but used space is a mess.

Are the backing indices for the Elastic Agent data streams being deleted? If they are being deleted, then I'm not sure what is the issue.

Depending on the integrations you are using Elastic Agente can be very noisy.

What is the space available in your cluster?

---

<div class="post-metadata">

**Author:** ![Tyty](https://avatars.discourse-cdn.com/v4/letter/t/35a633/32.png) [@Tyty](https://discuss.elastic.co/u/Tyty)\
**Post date:** [September 13, 2023, 3:30pm UTC](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243/6 "2023-09-13T15:30:02Z")

</div>

So I restore my snaphot VM and adjust my config as follow :  
Maximum primary shard size : 50GB  
Maximum age : 2 days  
Delete phase Move data into phase when: 12 hours

Are the backing indices for the Elastic Agent data streams being deleted?  
How can i know this information ?

Space available actually is around 100gb. If needed I can add more, but I want to control space used before.

Anyway, thanks for your answers.

regards,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2023, 3:30pm UTC](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243/7 "2023-10-11T15:30:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
