# Help With ILM

**URL:** <https://discuss.elastic.co/t/help-with-ilm/249177>\
**Category:** Kibana\
**Tags:** ilm-index-lifecycle-management\
**Created:** [September 18, 2020, 9:11pm UTC](https://discuss.elastic.co/t/help-with-ilm/249177 "2020-09-18T21:11:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bruceclegg](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Post date:** [September 18, 2020, 9:11pm UTC](https://discuss.elastic.co/t/help-with-ilm/249177/1 "2020-09-18T21:11:59Z")

</div>

I still consider myself very much a neophyte with ELK.

A few weeks ago I set up Lifecycle Policies for Indices in Kibana. I used the old index names the developers have hard coded into their programs.

But when it came time for the rollover I checked and found the rollover had failed in the check-rollover-ready step. I got the error message: **illegal\_argument\_exception: index name [aapc.log-test] does not match pattern '^.\*-\d+$'**

I did some googling and learned that I should have named the indexes with a number at the end. So instead of aapc.log-test, I should have named it aapc.log-test-000001 - and set the alias to be aapc.log-test.

My question is: What is the best way to get there from here?

I understand you can't rename indexes. The easiest solution seems to be to delete the indexes and build new ones with new names and better aliases. But I'd rather not delete if I don't have to. Is there a better answer?

Thanks

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [September 18, 2020, 10:00pm UTC](https://discuss.elastic.co/t/help-with-ilm/249177/2 "2020-09-18T22:00:21Z")

</div>

There are several options, you could do the following:

- Delete the index and build new ones with the correct name format.
- Use the reindex api to a new index with the proper name
- Use the clone api to "rename" the index (its a very fast process)
- Take a snapshot and restore it with the proper name, however there are a couple of options to check to really rename the index and avoid future issues
- Delete or reindex the current index infavor of DataStream that handles all the naming for you. Considering that you are ingesting logs, this could be your best option.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 22, 2020, 10:28pm UTC](https://discuss.elastic.co/t/help-with-ilm/249177/3 "2020-09-22T22:28:50Z")

</div>

Can you share your policy?

---

<div class="post-metadata">

**Author:** ![Bruceclegg](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Post date:** [September 25, 2020, 4:48pm UTC](https://discuss.elastic.co/t/help-with-ilm/249177/4 "2020-09-25T16:48:51Z")

</div>

Sorry for delay - was out the last few days.

{  
"Index\_lifecycle" : {  
"version" : 1,  
"modified\_date" : "2020-09-02T18:42:20.699Z",  
"policy" : {  
"phases" : {  
"hot" : {  
"min\_age" : "0ms",  
"actions" : {  
"rollover" : {  
"max\_size" : "50gb",  
"max\_age" : "30d"  
},  
"set\_priority" : {  
"priority" : 100  
}  
}  
},  
"delete" : {  
"min\_age" : "60d",  
"actions" : {  
"delete" : { }  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Bruceclegg](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Post date:** [October 8, 2020, 9:55pm UTC](https://discuss.elastic.co/t/help-with-ilm/249177/5 "2020-10-08T21:55:49Z")

</div>

There is much I don't know about this yet.

First I tried re-index

```
 I created an empty index
        PUT /aapc.log-test-00001

```

Then I attempted the reindex  
POST \_reindex  
{  
"source": {  
"index": "aapc.log-test"  
},  
"dest": {  
"index": "aapc.log-test-00001"  
}  
}

and got mapper\_parsing\_exceptions

I read on this a bit and it seemed cloning might be the better solution as it would build the new index with the same properties as the source.

But - reading about cloning - it tells me the index must be 'green' - mine are yellow because of the illegal\_argument\_exception with the index name issue with ILM. Is this really going to be a problem for cloning? It also says I've got to mark the index as read-only. I don't want to have to do that either, unless I don't have to.

I'm going to go back to seeing if I can create the new index with the same mappings as the source. I will post here with my results.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2020, 9:55pm UTC](https://discuss.elastic.co/t/help-with-ilm/249177/6 "2020-11-05T21:55:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
