Using ELK 7.11
we have 11 index out of these we have one index called log-wlb-sysmon.It created its first index on 2021.04.06(log-wlb-sysmon-2021.04.06-000001) , we are using ILM policy for all the indexes
It created the another index on 19th April (log-wlb-sysmon-2021.04.19-000002) because we have set "max_age": "30d", "max_size": "50gb"
, after some period of time we faced some mapping problem in this index so we decided to delete our old index(log-wlb-sysmon-2021.04.19-000002) and recreate this index so we did this
PUT log-wlb-sysmon-2021.04.26-000002
{
"aliases": {
"log-wlb-sysmon": {
"is_write_index": true
}
}
}
from then it was working fine both the indices(log-wlb-sysmon-2021.04.06-000001 and (log-wlb-sysmon-2021.04.26-000002)
Now we've notice that it created index log-wlb-sysmon-2021.04.26-000003 on 7th april , it should create index like log-wlb-sysmon-2021.05.07-000003
[2021-05-07T16:30:36,725][INFO ][o.e.c.m.MetadataCreateIndexService] [em2] [log-wlb-sysmon-2021.04.26-000003] creating index, cause [rollover_index], templates [winlogbeat_sysmon], shards [1]/[1]
[2021-05-07T16:30:36,767][INFO ][o.e.x.i.IndexLifecycleTransition] [em2] moving index [log-wlb-sysmon-2021.04.26-000003] from [null] to [{"phase":"new","action":"complete","name":"complete"}] in policy [winlogbeat_sysmon_policy]
[2021-05-07T16:30:36,845][INFO ][o.e.x.i.IndexLifecycleTransition] [em2] moving index [log-wlb-sysmon-2021.04.26-000002] from [{"phase":"hot","action":"rollover","name":"attempt-rollover"}] to [{"phase":"hot","action":"rollover","name":"wait-for-active-shards"}] in policy [winlogbeat_sysmon_policy]
[2021-05-07T16:30:36,880][INFO ][o.e.c.m.MetadataMappingService] [em2] [log-wlb-sysmon-2021.04.26-000003/QSzhCbMPRQ2Yynils14EFA] update_mapping [_doc]
[2021-05-07T16:30:36,920][INFO ][o.e.x.i.IndexLifecycleTransition] [em2] moving index [log-wlb-sysmon-2021.04.26-000003] from [{"phase":"new","action":"complete","name":"complete"}] to [{"phase":"hot","action":"set_priority","name":"set_priority"}] in policy [winlogbeat_sysmon_policy]
[2021-05-07T16:30:36,989][INFO ][o.e.c.m.MetadataMappingService] [em2] [log-wlb-sysmon-2021.04.26-000003/QSzhCbMPRQ2Yynils14EFA] update_mapping [_doc]
[2021-05-07T16:30:36,991][INFO ][o.e.c.m.MetadataMappingService] [em2] [log-wlb-sysmon-2021.04.26-000003/QSzhCbMPRQ2Yynils14EFA] update_mapping [_doc]
[2021-05-07T16:30:37,032][INFO ][o.e.x.i.IndexLifecycleTransition] [em2] moving index [log-wlb-sysmon-2021.04.26-000002] from [{"phase":"hot","action":"rollover","name":"wait-for-active-shards"}] to [{"phase":"hot","action":"rollover","name":"update-rollover-lifecycle-date"}] in policy [winlogbeat_sysmon_policy]
[2021-05-07T16:30:37,033][INFO ][o.e.x.i.IndexLifecycleTransition] [em2] moving index [log-wlb-sysmon-2021.04.26-000002] from [{"phase":"hot","action":"rollover","name":"update-rollover-lifecycle-date"}] to [{"phase":"hot","action":"rollover","name":"set-indexing-complete"}] in policy [winlogbeat_sysmon_policy]
[2021-05-07T16:30:37,100][INFO ][o.e.c.m.MetadataMappingService] [em2] [log-wlb-sysmon-2021.04.26-000003/QSzhCbMPRQ2Yynils14EFA] update_mapping [_doc]
log-wlb-sysmon index detail
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
green open log-wlb-sysmon-2021.04.26-000002 p5ROhVjwT0Gpl3pgwu2bRA 1 1 84829663 79510 100gb 50gb
green open log-wlb-sysmon-2021.04.06-000001 IAHprh30T6-rh2hxB67TLA 1 1 84049138 52926 100gb 50gb
green open log-wlb-sysmon-2021.04.26-000003 QSzhCbMPRQ2Yynils14EFA 1 1 39651126 67857 46.6gb 23.3gb
logstash pipeline file for this index
elasticsearch {
hosts => ["https://xx.xx.xx.xx:9200","https://xx.xx.xx.xx:9200"]
cacert => '/etc/logstash/certs/ca/ca.crt'
user => "logstash_user"
password => "password@xxx"
document_id => "%{[@metadata][log_hash]}"
manage_template => false
ilm_rollover_alias => "log-wlb-sysmon"
ilm_pattern => "{now/d}-000001"
ilm_enabled => "true"
ilm_policy => "winlogbeat_sysmon_policy"