# Fleet managed Lifecycle Policies

**URL:** <https://discuss.elastic.co/t/fleet-managed-lifecycle-policies/310505>\
**Category:** Elastic Agent\
**Tags:** ilm-index-lifecycle-management\
**Created:** [July 25, 2022, 7:05am UTC](https://discuss.elastic.co/t/fleet-managed-lifecycle-policies/310505 "2022-07-25T07:05:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![hermlam](https://avatars.discourse-cdn.com/v4/letter/h/8797f3/32.png) [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Post date:** [July 25, 2022, 7:05am UTC](https://discuss.elastic.co/t/fleet-managed-lifecycle-policies/310505/1 "2022-07-25T07:05:46Z")

</div>

Hi,  
Lifecycle policies for logs (name: Logs) are managed by Fleet. It is recommended not too edit this policy. But data in the logs will stay forever (see screenshot) and not deleted after x days, as usual.  
So eventually every logs will grow too big.  
What to do?  
Thanks,  
Herman

 ![Screenshot 2022-07-25 090048](https://us1.discourse-cdn.com/elastic/original/3X/a/5/a50c05e79524fbeedbb7e49f2f38c9c1bad86cba.jpeg)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 26, 2022, 3:58am UTC](https://discuss.elastic.co/t/fleet-managed-lifecycle-policies/310505/2 "2022-07-26T03:58:57Z")

</div>

I think if you scroll down it will show a delete action?

---

<div class="post-metadata">

**Author:** ![hermlam](https://avatars.discourse-cdn.com/v4/letter/h/8797f3/32.png) [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Post date:** [July 26, 2022, 5:28am UTC](https://discuss.elastic.co/t/fleet-managed-lifecycle-policies/310505/3 "2022-07-26T05:28:20Z")

</div>

Hi Mark,  
Thanks for your answer.  
Yes, normally there is a delete action, but only after changing the toggle in the hot phase section. And changing the toggle or the delete section mean a change and that's not recommended for this (fleet managed) policy, see in top of the screenshot.  
Herman

---

<div class="post-metadata">

**Author:** ![DougR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dougr/32/48095_2.png) [@DougR](https://discuss.elastic.co/u/DougR)\
**Post date:** [August 10, 2022, 9:24pm UTC](https://discuss.elastic.co/t/fleet-managed-lifecycle-policies/310505/4 "2022-08-10T21:24:57Z")

</div>

I'm dealing with this issue for the first time as well, as I'm in the process of migrating to fleet. I've created a new policy, but how do I apply the policy to my `logs-*` data streams?

Thx.

---

<div class="post-metadata">

**Author:** ![hermlam](https://avatars.discourse-cdn.com/v4/letter/h/8797f3/32.png) [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Post date:** [August 11, 2022, 5:08am UTC](https://discuss.elastic.co/t/fleet-managed-lifecycle-policies/310505/5 "2022-08-11T05:08:46Z")

</div>

Hi Doug,  
Yes, for logs that's different, I don't know why.  
You can find it easy:  
Stack Management-\>Index Management-\>Data Streams and select one of ther logs-\*. In the right corner you'll see the policy.  
Herman

---

<div class="post-metadata">

**Author:** ![DougR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dougr/32/48095_2.png) [@DougR](https://discuss.elastic.co/u/DougR)\
**Post date:** [August 12, 2022, 5:30pm UTC](https://discuss.elastic.co/t/fleet-managed-lifecycle-policies/310505/6 "2022-08-12T17:30:26Z")

</div>

I found instructions for applying a policy to a specific data stream here. It's a pain, but it works well. One thing I did not do was create an individual component template for each data stream (step 2), I created generic `logs-settings-default@custom` and `metrics-settings-default@custom` component templates and applied them with a new index template (step 3).

I made certain to remove `fleet_managed: true` from everything, so Fleet shouldn't zap it. There's no reason it shouldn't work, but we'll see the first time I have to upgrade the agent. 🤣

The one thing I'll need to be careful of when agents update is that where the new template specifies a pipeline, the pipeline is versioned, so I'll probably need to go through and update pipeline versions in the templates I've updated.

> **[Data streams | Fleet and Elastic Agent Guide \[8.3\] | Elastic](https://www.elastic.co/guide/en/fleet/current/data-streams.html#data-streams-ilm-tutorial)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 9, 2022, 5:31pm UTC](https://discuss.elastic.co/t/fleet-managed-lifecycle-policies/310505/7 "2022-09-09T17:31:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
