# Elasticsearch Index Management - Index Lifecycle Policies

**URL:** <https://discuss.elastic.co/t/elasticsearch-index-management-index-lifecycle-policies/244221>\
**Category:** Kibana\
**Tags:** ilm-index-lifecycle-management\
**Created:** [August 7, 2020, 8:16pm UTC](https://discuss.elastic.co/t/elasticsearch-index-management-index-lifecycle-policies/244221 "2020-08-07T20:16:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![brettlarsonwci](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brettlarsonwci/32/72289_2.png) [@brettlarsonwci](https://discuss.elastic.co/u/brettlarsonwci)\
**Post date:** [August 7, 2020, 8:16pm UTC](https://discuss.elastic.co/t/elasticsearch-index-management-index-lifecycle-policies/244221/1 "2020-08-07T20:16:51Z")

</div>

Hello All -

I am currently trying to set up some lifecycle policy's to clean up indices. In Kibana, I have an index pattern of "logstash-\*". Fluentd is just taking everything matching that pattern and sending it. This creates a new indice each day such as logstash.2020.08.01. I could apply the lifecycle policy directly to the indice, but I would have to go in each day and do that to each subsequent indice that gets automatically created. I assume the correct way to go about this is to create an index template, and apply the lifecycle policy to the template? And then somehow edit my fluentd configuration to direct it to a given index template instead of just a kibana index pattern? Am I on the right track? Also wondering what to put for "Alias" in this scenario, because when I attempt to bind a lifecycle policy to a template, it says with rollover enabled you have to specify alias. Not sure what is appropriate for that.

Thanks so much for your help!

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [August 12, 2020, 4:45pm UTC](https://discuss.elastic.co/t/elasticsearch-index-management-index-lifecycle-policies/244221/2 "2020-08-12T16:45:33Z")

</div>

Sounds like you are trying to set up automatic rollover? Have you tried [https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started-index-lifecycle-management.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started-index-lifecycle-management.html)?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 19, 2020, 5:22am UTC](https://discuss.elastic.co/t/elasticsearch-index-management-index-lifecycle-policies/244221/3 "2020-08-19T05:22:25Z")

</div>

> [@brettlarsonwci](#):
>
> I assume the correct way to go about this is to create an index template, and apply the lifecycle policy to the template

Yep, see [Manage existing indices | Elasticsearch Guide [7.9] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/ilm-with-existing-indices.html)

> [@brettlarsonwci](#):
>
> And then somehow edit my fluentd configuration to direct it to a given index template instead of just a kibana index pattern

Into an index, the template will apply (if you're using a matching name of course).

> [@brettlarsonwci](#):
>
> Am I on the right track?

Definitely 😃

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2020, 5:23am UTC](https://discuss.elastic.co/t/elasticsearch-index-management-index-lifecycle-policies/244221/5 "2020-09-16T05:23:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
