# ES custom ILM policy with cumulative index or disk size

**URL:** <https://discuss.elastic.co/t/es-custom-ilm-policy-with-cumulative-index-or-disk-size/326135>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [February 22, 2023, 7:48am UTC](https://discuss.elastic.co/t/es-custom-ilm-policy-with-cumulative-index-or-disk-size/326135 "2023-02-22T07:48:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![blueren](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@blueren](https://discuss.elastic.co/u/blueren)\
**Post date:** [February 22, 2023, 7:48am UTC](https://discuss.elastic.co/t/es-custom-ilm-policy-with-cumulative-index-or-disk-size/326135/1 "2023-02-22T07:48:56Z")

</div>

We're trying to implement an ILM policy for moving indices between hot -\> warm -\> cold in out on-premise server.

What we have is this:

1. SSD for storing hot indices
2. HDD for storing warm indices \> 7d
3. NAS for storing cold indices \> 30d

Considering that we will not be able to increase the size of the disks on demand, we want to make sure we get the ILM policies to self police in such a way that -

**HOT TIER:**

1. Hot index moves to warm if it's age is \> 7d.
2. Oldest hot index moves to warm, if the total cumulative size of all hot indices is \> 10TB

**WARM TIER**

1. Warm index moves to cold if it's age is \> 30d
2. Oldest warm index moves to cold, if the total cumulative size of all warm indices is \> 50TB

We are very specific of point 2 in both the cases in order to manage the SSD and HDD better since it cannot be expanded on a whim.

Is it possible to implement an ILM policy with the above parameters and conditions? If so, where would I begin?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 22, 2023, 8:13am UTC](https://discuss.elastic.co/t/es-custom-ilm-policy-with-cumulative-index-or-disk-size/326135/2 "2023-02-22T08:13:29Z")

</div>

You can't do it on cumulative, no. Policies only apply to indices (and their shards), not to tier usage beyond time-based limits.

---

<div class="post-metadata">

**Author:** ![blueren](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@blueren](https://discuss.elastic.co/u/blueren)\
**Post date:** [February 22, 2023, 10:26am UTC](https://discuss.elastic.co/t/es-custom-ilm-policy-with-cumulative-index-or-disk-size/326135/3 "2023-02-22T10:26:22Z")

</div>

Thanks for the quick response. So is there no other way to self police the storage / migration? Does this solely fall upon the infra management?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 22, 2023, 9:25pm UTC](https://discuss.elastic.co/t/es-custom-ilm-policy-with-cumulative-index-or-disk-size/326135/4 "2023-02-22T21:25:47Z")

</div>

To do what you want to do, yes that is correct.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2023, 9:25pm UTC](https://discuss.elastic.co/t/es-custom-ilm-policy-with-cumulative-index-or-disk-size/326135/5 "2023-03-22T21:25:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
