# ELK rollover renamed indexes

**URL:** <https://discuss.elastic.co/t/elk-rollover-renamed-indexes/269426>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [April 7, 2021, 8:53am UTC](https://discuss.elastic.co/t/elk-rollover-renamed-indexes/269426 "2021-04-07T08:53:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![arvanMalian](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@arvanMalian](https://discuss.elastic.co/u/arvanMalian)\
**Post date:** [April 7, 2021, 8:53am UTC](https://discuss.elastic.co/t/elk-rollover-renamed-indexes/269426/1 "2021-04-07T08:53:25Z")

</div>

Hi, I'm using ELK stack version 7.10.1 ( elasticsearch, kibana, filebeat )  
My goal is to apply lifecycle policy to my indexes with ILM. I remaned indexes, it's something like this:  
filebeat-7.10.1-2021.04.06-000001 ( generated by default with ILM)  
apache-2021.04.06-000001  
audit-2021.04.06-000001  
system-2021.04.06-000001  
Fistly I'm trying to configure rollover for apache logs (apache module is enabled).

I created Policy, template and first index with is\_write\_index option:  
#create ilm policy  
PUT /\_ilm/policy/apache\_policy\_test  
{  
"policy": {  
"phases": {  
"hot": {  
"actions": {  
"rollover": {  
"max\_size": "2mB",  
"max\_docs": 100,  
"max\_age": "1d"  
}  
}  
},  
"delete": {  
"min\_age": "3m",  
"actions": {  
"delete": {}  
}  
}  
}  
}  
}

# create template

PUT \_template/apache\_template\_test  
{  
"index\_patterns": ["apache-\*"],  
"settings": {  
"number\_of\_shards": 1,  
"number\_of\_replicas": 1,  
"index.lifecycle.name": "apache\_policy\_test",  
"index.lifecycle.rollover\_alias": "apache\_rollover\_alias\_test"  
}  
}

################# filebeat config  
logging.level: info  
logging.to\_files: true  
logging.files:  
path: /var/log/filebeat  
name: filebeat.log  
keepfiles: 7  
permissions: 0644

filebeat.inputs:

- type: log  
enabled: true  
paths:
  - /var/log/\*.log

- type: filestream  
enabled: false  
paths:
  - /var/log/\*.log

filebeat.config.modules:  
path: ${path.config}/modules.d/\*.yml  
reload.enabled: false

setup.template.settings:  
index.number\_of\_shards: 1

setup.kibana:  
host: "192.168.1.156:5601"

output.elasticsearch:  
hosts: ["192.168.1.156:9200"]  
indices:  
- index: "apache-%{+yyyy.MM.dd}-000001"  
when.equals:  
event.module: "apache"

processors:

- add\_host\_metadata:  
when.not.contains.tags: forwarded
- add\_cloud\_metadata: ~
- add\_docker\_metadata: ~
- add\_kubernetes\_metadata: ~  
################# END

Apache index has ' Aliases none ', so no rollover  
error message:  
"illegal\_argument\_exception: index.lifecycle.rollover\_alias [apache\_rollover\_alias\_test] does not point to index [apache-2021.04.06-000001] "  
I retried differently by creating the first index. The rollover works but the next index apache-2021.04.06-000002 doesn't updated (doc count is always 0)

# create first index with aliases

PUT /apache-2021.04.06-000001  
{  
"aliases": {  
"apache\_rollover\_alias\_test": {  
"is\_write\_index": true  
}  
}  
}

# get index informations

GET apache-2021.04.06-000001/\_ilm/explain

# retry the policy

POST apache-2021.04.06-000001/\_ilm/retry

Finally nothing works.  
what is wrong? have I forgotten something?  
Thanks you !

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 8, 2021, 1:59am UTC](https://discuss.elastic.co/t/elk-rollover-renamed-indexes/269426/2 "2021-04-08T01:59:13Z")

</div>

Welcome to our community! 😃

If you created the `apache-2021.04.06-000001` index with the `apache_rollover_alias_test` alias, what was the output from `GET apache-2021.04.06-000001/_ilm/explain`?  
You shouldn't need to run a retry on the policy though, if you just created it then it's unlikely to fill your rollover criteria.

---

<div class="post-metadata">

**Author:** ![arvanMalian](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@arvanMalian](https://discuss.elastic.co/u/arvanMalian)\
**Post date:** [April 8, 2021, 9:19am UTC](https://discuss.elastic.co/t/elk-rollover-renamed-indexes/269426/3 "2021-04-08T09:19:26Z")

</div>

Hi @warkolm ,  
I used GET just to check the created index (it's not really useful)  
Why retry policy? Maybe it's useless or that's not the way to do it.  
I also tried whitout retry policy.  
The next index ( number 2) is not updated (but has a rollover alias) and the first index has no more aliase (Alias None), so I got the error ( rollover\_alias does not point to index )  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2021, 9:19am UTC](https://discuss.elastic.co/t/elk-rollover-renamed-indexes/269426/4 "2021-05-06T09:19:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
