I’m looking for some help on how to better handle log data generated by Elastic. For example, what looks to be Elastic Agent log data is consuming almost 4.5tb on our frozen tier, double the size of any other dataset on our cluster.
Looks like its using the builtin ‘logs’ ILM policy, which has a 25GB/5day rollover to frozen before being deleted at 365 days. This is also causing a shard capacity issue.
tl;dr; You have complete control over the Lifecycle of all those indices
Some appear to be agent related, others like the system one are just normal logs from integrations etc...
Pretty sure that is not the default of the built-in policy; I suspect that those policies have been edited at some point.... which is fine.
Curious What version are you on... and what version did you come from?
But in short, you can Create and Apply policy to any / all indices/data streams you like, using the custom ILM policies and applying them by the @custom templates (or directly editing the defaults, which is generally discouraged)
Hi @stephenb, thanks for getting back to me. We are on 8.17 and I think thats the version we started on when we moved to Elastic Cloud. Before that we started our on prem instance on version 5 or 6… i think.
Our SE and I didnt make any changes to the default “logs” policy as far as I know because we started making custom policies that matched our on prem indices. But maybe we did. Whats the default settings for that policy?
I can work on creating custom policies, with hopes of getting them back under control. I can look at the index and see the assigned ILM policy, but I havent figured out how to identify what template that is associated with. I assume there is a way, right?
Also, is there any documentation on what data goes into these types of indexes? It would help me identify what retention policy is needed.
Side question, whats the best way to move existing indices to these new policy? I can do it one-by-one within Index Management, but it wont let me bulk change.
I have tried using Dev Tools
PUT partial-.ds-logs-elastic_agent.filebeat-default-2025.10*/_settings
{"index.lifecycle.name": "new-test-policy"}
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.