# Examples for setting up Beats (modules) \> Logstash \> ES with ILM?

**URL:** <https://discuss.elastic.co/t/examples-for-setting-up-beats-modules-logstash-es-with-ilm/182045>\
**Category:** Logstash\
**Tags:** ilm-index-lifecycle-management\
**Created:** [May 21, 2019, 3:17pm UTC](https://discuss.elastic.co/t/examples-for-setting-up-beats-modules-logstash-es-with-ilm/182045 "2019-05-21T15:17:04Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![pdizz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pdizz/32/45941_2.png) [@pdizz](https://discuss.elastic.co/u/pdizz)\
**Post date:** [May 21, 2019, 3:17pm UTC](https://discuss.elastic.co/t/examples-for-setting-up-beats-modules-logstash-es-with-ilm/182045/1 "2019-05-21T15:17:04Z")

</div>

Are there any basic configuration examples showing how to set up a Beats (with modules and dashboards) \> Logstash \> ES pipeline using Index Lifecycle Management? Currently I'm familiar with the "classic" setup with Metricbeat and Filebeat pushing logs to logstash. Logstash is configured to create daily indices with `%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}` for the name.

To set this up to use ILM, I need to run the beats setup commands with ilm enabled to create the templates, which creates the policy and index template (something like `filebeat-7.0.1-2019-05-06-000001`) That is the "real" index, but logstash should just be configured to write to the alias `filebeat-7.0.1`?

Or is logstash supposed to be configured to use ILM and I need to set up the template and alias myself? Should it still separate indices per beat or just use one `logstash` index? Would that break the built-in dashboards? If anyone has a basic working example for a setup like this I would really appreciate it!

---

<div class="post-metadata">

**Author:** ![drod](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drod/32/47881_2.png) [@drod](https://discuss.elastic.co/u/drod)\
**Post date:** [June 11, 2019, 3:39pm UTC](https://discuss.elastic.co/t/examples-for-setting-up-beats-modules-logstash-es-with-ilm/182045/2 "2019-06-11T15:39:39Z")

</div>

I have the same question. I have everything working but ILM is having issues. ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4c31ede68f2de92dd760172ede4f1ba814dd6de8.png)

---

<div class="post-metadata">

**Author:** ![Scott\_McCollough](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scott_mccollough/32/47884_2.png) [@Scott\_McCollough](https://discuss.elastic.co/u/Scott_McCollough)\
**Post date:** [June 11, 2019, 4:25pm UTC](https://discuss.elastic.co/t/examples-for-setting-up-beats-modules-logstash-es-with-ilm/182045/3 "2019-06-11T16:25:14Z")

</div>

Has anyone figured this out yet? I'm facing the same issue.

---

<div class="post-metadata">

**Author:** ![pdizz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pdizz/32/45941_2.png) [@pdizz](https://discuss.elastic.co/u/pdizz)\
**Post date:** [June 11, 2019, 4:45pm UTC](https://discuss.elastic.co/t/examples-for-setting-up-beats-modules-logstash-es-with-ilm/182045/4 "2019-06-11T16:45:59Z")

</div>

Do you have logstash configured for daily indexes? Something like `index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"`?

When you set up ILM it creates an alias like `filebeat-7.0.1` and ILM handles rolling over and creating real indexes. So if you configure logstash to just push to the alias `index => "%{[@metadata][beat]}-%{[@metadata][version]}"` it should get rid of those errors.

The problem I ran in to was it all seems to work as long as you never touch it again. If you ever delete indexes manually, I still havent figured out how to configure it again to restore it to a working state.

---

<div class="post-metadata">

**Author:** ![drod](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drod/32/47881_2.png) [@drod](https://discuss.elastic.co/u/drod)\
**Post date:** [June 11, 2019, 5:01pm UTC](https://discuss.elastic.co/t/examples-for-setting-up-beats-modules-logstash-es-with-ilm/182045/5 "2019-06-11T17:01:39Z")

</div>

yup I have logstash creating daily indexes. Alright so I should make that change. Now I am wondering if this will be broken for me now though because I just reindexed and deleted an index.

---

<div class="post-metadata">

**Author:** ![Scott\_McCollough](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scott_mccollough/32/47884_2.png) [@Scott\_McCollough](https://discuss.elastic.co/u/Scott_McCollough)\
**Post date:** [June 11, 2019, 5:02pm UTC](https://discuss.elastic.co/t/examples-for-setting-up-beats-modules-logstash-es-with-ilm/182045/6 "2019-06-11T17:02:03Z")

</div>

Now it's creating the index but no ILM policy or alias. Let me start from scratch again.

---

<div class="post-metadata">

**Author:** ![Scott\_McCollough](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scott_mccollough/32/47884_2.png) [@Scott\_McCollough](https://discuss.elastic.co/u/Scott_McCollough)\
**Post date:** [June 11, 2019, 5:45pm UTC](https://discuss.elastic.co/t/examples-for-setting-up-beats-modules-logstash-es-with-ilm/182045/7 "2019-06-11T17:45:46Z")

</div>

I started from scratch completely and es is not creating ilm at all using `index => "%{[@metadata][beat]}-%{[@metadata][version]}"`

---

<div class="post-metadata">

**Author:** ![pdizz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pdizz/32/45941_2.png) [@pdizz](https://discuss.elastic.co/u/pdizz)\
**Post date:** [June 11, 2019, 6:01pm UTC](https://discuss.elastic.co/t/examples-for-setting-up-beats-modules-logstash-es-with-ilm/182045/8 "2019-06-11T18:01:18Z")

</div>

i think ILM configuration is created when you run the beats setup commands like `filebeat setup --template -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=["localhost:9200"]'`.

I would stop the logstash service before cleaning up indexes so it doesnt create a new one before you have a chance to run setup

---

<div class="post-metadata">

**Author:** ![Scott\_McCollough](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scott_mccollough/32/47884_2.png) [@Scott\_McCollough](https://discuss.elastic.co/u/Scott_McCollough)\
**Post date:** [June 11, 2019, 6:04pm UTC](https://discuss.elastic.co/t/examples-for-setting-up-beats-modules-logstash-es-with-ilm/182045/9 "2019-06-11T18:04:04Z")

</div>

Thanks for the help Pete. This is driving me nuts. The documentation states this should all be automagic but it's just not quite meshing together correctly. Luckily I have the time to invest right now.

---

<div class="post-metadata">

**Author:** ![Scott\_McCollough](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scott_mccollough/32/47884_2.png) [@Scott\_McCollough](https://discuss.elastic.co/u/Scott_McCollough)\
**Post date:** [June 11, 2019, 7:43pm UTC](https://discuss.elastic.co/t/examples-for-setting-up-beats-modules-logstash-es-with-ilm/182045/10 "2019-06-11T19:43:00Z")

</div>

That seems to be working, thank you. The initial index is still created with a date stamp in the name, but it appears to be working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2019, 7:43pm UTC](https://discuss.elastic.co/t/examples-for-setting-up-beats-modules-logstash-es-with-ilm/182045/11 "2019-07-09T19:43:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
