# HELP \[illegal\_argument\_exception: index.lifecycle.rollover\_alias \[sonicwall-\*\] does not point to index \[sonicwall-2020.09.28-000001\]\]

**URL:** <https://discuss.elastic.co/t/help-illegal-argument-exception-index-lifecycle-rollover-alias-sonicwall-does-not-point-to-index-sonicwall-2020-09-28-000001/250281>\
**Category:** Kibana\
**Tags:** ilm-index-lifecycle-management\
**Created:** [September 29, 2020, 3:03am UTC](https://discuss.elastic.co/t/help-illegal-argument-exception-index-lifecycle-rollover-alias-sonicwall-does-not-point-to-index-sonicwall-2020-09-28-000001/250281 "2020-09-29T03:03:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akbar\_Maulana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akbar_maulana/32/76351_2.png) [@Akbar\_Maulana](https://discuss.elastic.co/u/Akbar_Maulana)\
**Post date:** [September 29, 2020, 3:03am UTC](https://discuss.elastic.co/t/help-illegal-argument-exception-index-lifecycle-rollover-alias-sonicwall-does-not-point-to-index-sonicwall-2020-09-28-000001/250281/1 "2020-09-29T03:03:16Z")

</div>

I use this configuration for my indices but always returned with this error

PUT \_template/sonicwall?include\_type\_name  
{  
"version": 60001,  
"order": 0,  
"index\_patterns": [  
"sonicwall-_"  
],  
"settings": {  
"index": {  
"lifecycle": {  
"name": "logstash-policy",  
"rollover\_alias": "sonicwall-_"  
},  
"max\_result\_window": "100000",  
"refresh\_interval": "5s",  
"number\_of\_shards": "1",  
"number\_of\_replicas": "0"  
}  
},  
"mappings": {  
"\_doc": {  
"\_source": {  
"excludes": ,  
"includes": ,  
"enabled": true  
},  
"\_routing": {  
"required": false  
},  
"dynamic": true,  
"numeric\_detection": false,  
"date\_detection": true,  
"dynamic\_date\_formats": [  
"strict\_date\_optional\_time",  
"yyyy/MM/dd HH:mm:ss Z||yyyy/MM/dd Z"  
],  
"dynamic\_templates": [  
{  
"message\_field": {  
"path\_match": "message",  
"mapping": {  
"norms": false,  
"type": "text"  
},  
"match\_mapping\_type": "string"  
}  
},  
{  
"string\_fields": {  
"mapping": {  
"norms": false,  
"type": "text",  
"fields": {  
"keyword": {  
"ignore\_above": 256,  
"type": "keyword"  
}  
}  
},  
"match\_mapping\_type": "string",  
"match": "\*"  
}  
}  
],  
"properties": {  
"@timestamp": {  
"type": "date"  
},  
"@version": {  
"type": "keyword"  
},  
"geoip": {  
"dynamic": true,  
"type": "object",  
"properties": {  
"ip": {  
"type": "ip"  
},  
"latitude": {  
"type": "half\_float"  
},  
"location": {  
"type": "geo\_point"  
},  
"longitude": {  
"type": "half\_float"  
}  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 29, 2020, 3:10am UTC](https://discuss.elastic.co/t/help-illegal-argument-exception-index-lifecycle-rollover-alias-sonicwall-does-not-point-to-index-sonicwall-2020-09-28-000001/250281/2 "2020-09-29T03:10:12Z")

</div>

Welcome to our community! 😃

Check out my answer here [ILM Policy - Help!\>!\>!\>](https://discuss.elastic.co/t/ilm-policy-help/250217/2), it is the same issue.

---

<div class="post-metadata">

**Author:** ![Akbar\_Maulana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akbar_maulana/32/76351_2.png) [@Akbar\_Maulana](https://discuss.elastic.co/u/Akbar_Maulana)\
**Post date:** [October 5, 2020, 2:18am UTC](https://discuss.elastic.co/t/help-illegal-argument-exception-index-lifecycle-rollover-alias-sonicwall-does-not-point-to-index-sonicwall-2020-09-28-000001/250281/3 "2020-10-05T02:18:55Z")

</div>

I tried, but it's still the same

---

<div class="post-metadata">

**Author:** ![Akbar\_Maulana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akbar_maulana/32/76351_2.png) [@Akbar\_Maulana](https://discuss.elastic.co/u/Akbar_Maulana)\
**Post date:** [October 5, 2020, 2:41am UTC](https://discuss.elastic.co/t/help-illegal-argument-exception-index-lifecycle-rollover-alias-sonicwall-does-not-point-to-index-sonicwall-2020-09-28-000001/250281/4 "2020-10-05T02:41:48Z")

</div>

I use this request from Web UI

```auto
PUT _template/sonicwall?include_type_name
{
  "version": 60001,
  "order": 0,
  "index_patterns": [
    "sonicwall-*"
  ],
  "settings": {
    "index": {
      "lifecycle": {
        "name": "logstash-policy",
        "rollover_alias": "sonicwall-*"
      },
      "max_result_window": "100000",
      "refresh_interval": "5s",
      "number_of_shards": "1",
      "number_of_replicas": "0"
    }
  },
  "mappings": {
    "_doc": {
      "_source": {
        "excludes": [],
        "includes": [],
        "enabled": true
      },
      "_routing": {
        "required": false
      },
      "dynamic": true,
      "numeric_detection": false,
      "date_detection": true,
      "dynamic_date_formats": [
        "strict_date_optional_time",
        "yyyy/MM/dd HH:mm:ss Z||yyyy/MM/dd Z"
      ],
      "dynamic_templates": [
        {
          "message_field": {
            "path_match": "message",
            "mapping": {
              "norms": false,
              "type": "text"
            },
            "match_mapping_type": "string"
          }
        },
        {
          "string_fields": {
            "mapping": {
              "norms": false,
              "type": "text",
              "fields": {
                "keyword": {
                  "ignore_above": 256,
                  "type": "keyword"
                }
              }
            },
            "match_mapping_type": "string",
            "match": "*"
          }
        }
      ],
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "@version": {
          "type": "keyword"
        },
        "geoip": {
          "dynamic": true,
          "type": "object",
          "properties": {
            "ip": {
              "type": "ip"
            },
            "latitude": {
              "type": "half_float"
            },
            "location": {
              "type": "geo_point"
            },
            "longitude": {
              "type": "half_float"
            }
          }
        }
      }
    }
  }
}

```

And use this output in logstash conf.d

```auto
Else if [type] == "Sonicwall"{
    elasticsearch {
      hosts => ["xxxxx"]
      user => "xxx"
      password => "xxx"
      #index => "sonicwall-index"
      manage_template => true
      template_name => "sonicwall"
      index => "sonicwall-%{+YYYY.MM.dd}"
      #ilm_enabled => true
      #ilm_rollover_alias => "sonicwall"
      #ilm_pattern => "{now/d}-000001"
      #ilm_policy => "logstash-policy"
      ssl => true
      cacert => "/etc/logstash/certs/ca.crt"

```

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [October 5, 2020, 4:00am UTC](https://discuss.elastic.co/t/help-illegal-argument-exception-index-lifecycle-rollover-alias-sonicwall-does-not-point-to-index-sonicwall-2020-09-28-000001/250281/5 "2020-10-05T04:00:04Z")

</div>

In your index template, it shows below which seems incorrect

> [@Akbar\_Maulana](#):
>
> ` "rollover_alias": "sonicwall-*"`

rollover\_alias should be example `sonicwall` instead of having a `-*` inside

Also your `logstash conf.d` `index =>` should point to your `rollover_alias` instead of `"sonicwall-%{+YYYY.MM.dd}"`

If you wanted to add date to your index, you can take a look at this [post](https://discuss.elastic.co/t/index-lifecycle-rollover-alias-does-not-point-to-index/192525) or read up on [date math](https://www.elastic.co/guide/en/elasticsearch/reference/7.x/indices-rollover-index.html#_using_date_math_with_the_rollover_api)

This [document](https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started-index-lifecycle-management.html#manage-time-series-data-without-data-streams) helps me alot when I'm configuring ILM

Hope this can help you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2020, 4:00am UTC](https://discuss.elastic.co/t/help-illegal-argument-exception-index-lifecycle-rollover-alias-sonicwall-does-not-point-to-index-sonicwall-2020-09-28-000001/250281/6 "2020-11-02T04:00:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
