# Fortinet FortiGate Firewall Logs Integration apply ILM 1 day

**URL:** <https://discuss.elastic.co/t/fortinet-fortigate-firewall-logs-integration-apply-ilm-1-day/371724>\
**Category:** Elastic Agent\
**Created:** [December 9, 2024, 7:19pm UTC](https://discuss.elastic.co/t/fortinet-fortigate-firewall-logs-integration-apply-ilm-1-day/371724 "2024-12-09T19:19:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![juancamiloll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juancamiloll/32/110326_2.png) [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Post date:** [December 9, 2024, 7:19pm UTC](https://discuss.elastic.co/t/fortinet-fortigate-firewall-logs-integration-apply-ilm-1-day/371724/1 "2024-12-09T19:19:46Z")

</div>

Hello  
I have installed the “Fortinet FortiGate Firewall Logs” integration.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/3/93da3765b33e094a387e95de2a20b43e8c8e7c0e.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/d/dda167a1e4a20f454c3cc9b82307af467c3d9b8e.png)

I did the respective configuration

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/c/5c1117facf8df05a75ae84fc3e76f2693bfd7b28.png)

The datastream was created and I am receiving logs normally.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/3/7305f6631bf6816b4e75880f802a383be9b8fa90.png)

My problem is that it took a policy called “logs” and I need to apply an index life cycle of 1 day and for obvious reasons I cannot modify the “logs” policy because it would affect the other datastreams, I need to apply a policy only for Fortinet.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/2/32eb18919511b263f71cbc43b0c65cd6d36d36f6.png)

If the ILM policy is associated to the index template, then I go to the fortinet index template but I have no idea what to modify to apply the ILM I created manually called “Fortinet-policy” which removes the index in 1 day.

I also see that there are some “component templates” and not knowing what they do or what they are for I am worried about moving something that generates problems to the ingest that at the moment works fine.

Thank you for your help

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/e/ee49a8384c4d36aa0b0b52b7205d75d773965969.png)

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [December 9, 2024, 9:13pm UTC](https://discuss.elastic.co/t/fortinet-fortigate-firewall-logs-integration-apply-ilm-1-day/371724/2 "2024-12-09T21:13:37Z")

</div>

The workflow for customizing the ILM policy of an existing integration is available here: [Tutorial: Customize data retention policies | Fleet and Elastic Agent Guide [8.16] | Elastic](https://www.elastic.co/guide/en/fleet/current/data-streams-ilm-tutorial.html)
