# Force index rollover with a new index name

**URL:** <https://discuss.elastic.co/t/force-index-rollover-with-a-new-index-name/315983>\
**Category:** Logstash\
**Created:** [October 6, 2022, 1:58pm UTC](https://discuss.elastic.co/t/force-index-rollover-with-a-new-index-name/315983 "2022-10-06T13:58:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![frank\_rib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_rib/32/104372_2.png) [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Post date:** [October 6, 2022, 1:58pm UTC](https://discuss.elastic.co/t/force-index-rollover-with-a-new-index-name/315983/1 "2022-10-06T13:58:47Z")

</div>

Hello,  
I was configured filebeat agent to send data directly to elasticsearch from multiples agent. afterwards I added the index to a have a problem with the rollover  
I added the index to the retention policy test0.  
The index settings

> {  
> "ecs-agent-windows": {  
> "settings": {  
> "index": {  
> "lifecycle": {  
> "name": "test0",  
> "rollover\_alias": "ecs-agent-windows1",  
> "indexing\_complete": "true"  
> },  
> "routing": {  
> "allocation": {  
> "include": {  
> "\_tier\_preference": "data\_warm,data\_hot"  
> }  
> }  
> },  
> "number\_of\_shards": "1",  
> "provided\_name": "ecs-agent-windows",  
> "creation\_date": "1663002046263",  
> "priority": "50",  
> "number\_of\_replicas": "0",  
> "uuid": "OgE-V8WVRBqW56Hwwmo5Bg",  
> "version": {  
> "created": "8030299"  
> }  
> }  
> }  
> }  
> }  
> The policy settings  
> {  
> "test0": {  
> "version": 1,  
> "modified\_date": "2022-10-05T17:17:50.872Z",  
> "policy": {  
> "phases": {  
> "warm": {  
> "min\_age": "1s",  
> "actions": {  
> "set\_priority": {  
> "priority": 50  
> }  
> }  
> },  
> "hot": {  
> "min\_age": "0ms",  
> "actions": {  
> "set\_priority": {  
> "priority": 100  
> },  
> "rollover": {  
> "max\_primary\_shard\_size": "50gb",  
> "max\_age": "10m",  
> "max\_docs": 500  
> }  
> }  
> }  
> }  
> },  
> "in\_use\_by": {  
> "indices": [  
> "ecs-agent-windows",  
> "ecs-agent-filebeat-2022.10.05-000002",  
> "ecs-agent-filebeat-2022.10.05-000001",  
> "ecs-agent-filebeat"  
> ],  
> "data\_streams": ,  
> "composable\_templates": [  
> "ecs-agent-windows",  
> "agent-filebeat",  
> "agent-winlogbeat"  
> ]  
> }  
> }  
> }  
> The ILM explain:  
> {  
> "indices": {  
> "ecs-agent-windows": {  
> "index": "ecs-agent-windows",  
> "managed": true,  
> "policy": "test0",  
> "index\_creation\_date\_millis": 1663002046263,  
> "time\_since\_index\_creation": "23.8d",  
> "lifecycle\_date\_millis": 1663002046263,  
> "age": "23.8d",  
> "phase": "warm",  
> "phase\_time\_millis": 1665015792294,  
> "action": "complete",  
> "action\_time\_millis": 1665016742506,  
> "step": "complete",  
> "step\_time\_millis": 1665016742506,  
> "phase\_execution": {  
> "policy": "test0",  
> "phase\_definition": {  
> "min\_age": "1s",  
> "actions": {  
> "set\_priority": {  
> "priority": 50  
> }  
> }  
> },  
> "version": 1,  
> "modified\_date\_in\_millis": 1664990270872  
> }  
> }  
> }  
> }   
> The logs are always added to ecs-agent-windows, even though the index is at the complete phase.  
> Is there any why to force the rollover to resolve this issue from elasticsearch, knowing that I don’t have access to filebeat agent.  
> Best regards,

---

<div class="post-metadata">

**Author:** ![frank\_rib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_rib/32/104372_2.png) [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Post date:** [October 9, 2022, 7:11pm UTC](https://discuss.elastic.co/t/force-index-rollover-with-a-new-index-name/315983/2 "2022-10-09T19:11:38Z")

</div>

Hello,  
Can I have an expert who can help me to solve the issue

Regards,

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 9, 2022, 8:35pm UTC](https://discuss.elastic.co/t/force-index-rollover-with-a-new-index-name/315983/3 "2022-10-09T20:35:05Z")

</div>

Hi @frank_rib

It is unclear what the past state, current state and desired state you want......

Let's start with some basics what version are you on? For all component?

Are you using elastic agent or filebeat?

Are you trying to use Indices or Data Streams? (Do you know the difference? Do you have a preference .. I see mixed references above)

Can you show your filebeat.yml? This is a good place to start.

It is unclear whether you are trying to use a data stream / index.

I see `"ecs-agent-windows"` named as a data stream in the policy but at the top you seem to have it named as an index... that is confusing an probably part of the issues.

So going back ... perhaps explain what you are trying to accomplish at a higher level than just asking how to rollover.

What do you want going forward.

If you are new to Elastic I highly encourage you to use most of the defaults until you get a good understand of all the components and their relationships.

If you just want to force a rollover (which I do not think will work)

See [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-rollover-index.html) (actually works for data streams too)

`POST ecs-agent-windows1/_rollover`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2022, 8:35pm UTC](https://discuss.elastic.co/t/force-index-rollover-with-a-new-index-name/315983/4 "2022-11-06T20:35:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
