# Elastic ILM Configuration

**URL:** <https://discuss.elastic.co/t/elastic-ilm-configuration/310401>\
**Category:** Beats\
**Tags:** ilm-index-lifecycle-management, filebeat\
**Created:** [July 22, 2022, 12:45pm UTC](https://discuss.elastic.co/t/elastic-ilm-configuration/310401 "2022-07-22T12:45:00Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![tractor\_boy](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Post date:** [July 22, 2022, 12:45pm UTC](https://discuss.elastic.co/t/elastic-ilm-configuration/310401/1 "2022-07-22T12:45:00Z")

</div>

I have filebeat writing directly into elastic and now need to configure ILM. My task is to do this through configuration so that it is deployable without user intervention.

Is there are documentation that details how to set up a configuration file?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 22, 2022, 12:50pm UTC](https://discuss.elastic.co/t/elastic-ilm-configuration/310401/2 "2022-07-22T12:50:55Z")

</div>

Did you check the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-management.html) in the official site?

---

<div class="post-metadata">

**Author:** ![tractor\_boy](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Post date:** [July 22, 2022, 12:57pm UTC](https://discuss.elastic.co/t/elastic-ilm-configuration/310401/3 "2022-07-22T12:57:03Z")

</div>

Indeed, it however doesn't have that information that explains how to set up a file. What am I missing?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 22, 2022, 1:02pm UTC](https://discuss.elastic.co/t/elastic-ilm-configuration/310401/4 "2022-07-22T13:02:18Z")

</div>

You do not setup an ILM with a file, you need to make a request to the API.

The documentation shows you how to do it using Kibana and also how the request should be if you do not want to use Kibana.

For example, this link on how to [configure a lifecycle policy](https://www.elastic.co/guide/en/elasticsearch/reference/current/set-up-lifecycle-policy.html), click in the _API example_ item to expand the code block and see the request.

You can also follow the link in that same page to the [API documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/ilm-put-lifecycle.html).

---

<div class="post-metadata">

**Author:** ![tractor\_boy](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Post date:** [July 22, 2022, 1:21pm UTC](https://discuss.elastic.co/t/elastic-ilm-configuration/310401/5 "2022-07-22T13:21:27Z")

</div>

Thank you.

What do I need to do to get that api code run when deploying a new filebeat deployment?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 22, 2022, 3:49pm UTC](https://discuss.elastic.co/t/elastic-ilm-configuration/310401/6 "2022-07-22T15:49:45Z")

</div>

Actually you are right and you can set this using a file as you already discovered the setting in your other post.

This [answer in your other post](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396/9) is how the file needs to look like.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 22, 2022, 4:51pm UTC](https://discuss.elastic.co/t/elastic-ilm-configuration/310401/7 "2022-07-22T16:51:43Z")

</div>

this is how you do it via filebeat. need to change filebeat.yml file once. run it.  
let filebeat create all and then disable it.

```auto
output.elasticsearch.index: "yourindexname-*"
setup.template.name: "yourindexname"
setup.template.pattern: "yourindexname-*"

setup.template.fields: "/etc/filebeat/fields.yml"
setup.ilm.overwrite: true
setup.ilm.enabled: auto
setup.ilm.policy_name: "yourindexname"
setup.ilm.rollover_alias: "yourindexname-%{[agent.version]}"
setup.ilm.pattern: "{now/d}-000001"

```

What this will do is create IML name yourindexname ( you can adjust everything in it afterward)  
it will create index pattern yourindexname-\*  
it will create index template yourindexname ( you can adjust number of shard, number of replica etc.. afterward if you like)  
it will create index yourindexname--\<today\_date\>-000001  
and alias

`yourindexname-<agent_version> ---> yourindexname-<filebeat version>-<today_date>-000001`

and when your index will rollover it will create new index with  
yourindexname--\<today\_date\>-000002

and now your alias pointing to this index. and all that will be manage by ILM

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2022, 6:51pm UTC](https://discuss.elastic.co/t/elastic-ilm-configuration/310401/8 "2022-08-19T18:51:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
