# Hot/Warm/Cold phases being ignored. Data goes directly to Cold

**URL:** <https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management, datastreams, streams\
**Created:** [August 25, 2026, 11:37am UTC](https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910 "2026-08-25T11:37:04Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alberto\_Martinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alberto_martinez/32/148116_2.png) [@Alberto\_Martinez](https://discuss.elastic.co/u/Alberto_Martinez)\
**Post date:** [August 25, 2026, 11:37am UTC](https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910/1 "2026-08-25T11:37:04Z")

</div>

Hello,

As the title says, all my streams share a common ILM policy but somehow it is ignored.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/a/ea849364c753117ac7fef615bc3267759e2b33dd.png)

All nodes are capable of hot/warm/cold. It is a recent setup and we don't have separate roles yet.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c5b9aeff5446ab928b1892d54513f4444100832f.png)

Any pointer to what could be happening here?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 25, 2026, 12:53pm UTC](https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910/2 "2026-08-25T12:53:02Z")

</div>

> [@Alberto\_Martinez](#):
>
> Any pointer to what could be happening here?

You need to share your policy, it is impossible to troubleshoot without seeing it.

Share a screenshot of the policy in Kibana and the raw json as well.

---

<div class="post-metadata">

**Author:** ![Alberto\_Martinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alberto_martinez/32/148116_2.png) [@Alberto\_Martinez](https://discuss.elastic.co/u/Alberto_Martinez)\
**Post date:** [September 4, 2026, 10:31am UTC](https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910/3 "2026-09-04T10:31:26Z")

</div>

```json
PUT _ilm/policy/deusto-ilm-policy
{
  "policy": {
    "phases": {
      "hot": {
        "min_age": "0ms",
        "actions": {
          "set_priority": {
            "priority": 100
          }
        }
      },
      "warm": {
        "min_age": "1d",
        "actions": {
          "set_priority": {
            "priority": 50
          }
        }
      },
      "cold": {
        "min_age": "2d",
        "actions": {
          "readonly": {},
          "set_priority": {
            "priority": 0
          }
        }
      },
      "delete": {
        "min_age": "60d",
        "actions": {
          "delete": {
            "delete_searchable_snapshot": true
          }
        }
      }
    }
  }
}

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a4d168c4f9be63c7df86d0984390da50ff490448.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 4, 2026, 3:38pm UTC](https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910/4 "2026-09-04T15:38:59Z")

</div>

> [@Alberto\_Martinez](#):
>
> As the title says, all my streams share a common ILM policy but somehow it is ignored.

From what you shared, I'm not sure there is any issue.

Your lifecycle policy does not have a rollover, it has a warm phase tha will trigger after one day of the creation of the index, and a cold phase that will trigger after two days of the creation of the index.

If any index is older than 2 days they will be in cold.

It is also not clear if you are using normal indices or data streams, can you share the result of running `GET _cat/indices` in Kibana Dev Tools?

> [@Alberto\_Martinez](#):
>
> All nodes are capable of hot/warm/cold. It is a recent setup and we don't have separate roles yet.

I'm not sure how the Streams app works, so I'm not sure if this could lead to any issues, but if all indices have the same role, it does not make any sense to have ILM with data tiering, you should have dedicated warm and cold indices for this to make sense.

---

<div class="post-metadata">

**Author:** ![Alberto\_Martinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alberto_martinez/32/148116_2.png) [@Alberto\_Martinez](https://discuss.elastic.co/u/Alberto_Martinez)\
**Post date:** [September 4, 2026, 4:02pm UTC](https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910/5 "2026-09-04T16:02:53Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/d/4dac5b3cacaee9536fbb3713ce39c2528b1dc09b.png)

I see what may be happening. The datastreams are not rolling daily into different indexes and thus not following the ILM as I expect. Is that so?

How I make the datastreams behave like I expect?

Thank you very much!

PS:

> if all indices have the same role, it does not make any sense to have ILM with data tiering, you should have dedicated warm and cold indices for this to make sense.

I believe, but I could be wrong, that a cold index consumes less resources than a hot index. The ILM policy right now is just for that, though maybe in the future we should dedicate nodes to cold data retention.

---

<div class="post-metadata">

**Author:** ![Dor\_Levi1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dor_levi1/32/148213_2.png) [@Dor\_Levi1](https://discuss.elastic.co/u/Dor_Levi1)\
**Post date:** [September 12, 2026, 5:12am UTC](https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910/6 "2026-09-12T05:12:49Z")

</div>

Leandro has it: your policy has no `rollover` action, so ILM is never asked to start a new backing index, and the phase ages are measured from index creation. That is why an index more than two days old is already in cold.

There is a second thing worth checking. The cold phase's `readonly` action will not act on a data stream's write index; it waits at that step instead. So if the write index itself has reached cold, it can sit there without progressing. `GET <data-stream>/_ilm/explain` will tell you: look at `phase`, `action`, `step`, and at `lifecycle_date_millis` next to `index_creation_date_millis`, which is the timestamp the phase ages are counted from.

Adding rollover to hot is the fix going forward. As a replacement hot section, keeping your other phases as they are:

```auto
"hot": {
  "min_age": "0ms",
  "actions": {
    "rollover": { "max_age": "1d", "max_primary_shard_size": "50gb" },
    "set_priority": { "priority": 100 }
  }
}

```

Two things that policy edit alone will not do. Check that the index template matching these streams actually applies this policy, since only new backing indices pick it up. And an index already in cold does not go back to hot because the policy gained a hot action, so you will probably need one manual `POST <data-stream>/_rollover` to get a fresh write index that starts in hot. Worth looking at the explain output for the current write index before you do that.

On expectations once it is rolling: `max_age: 1d` is approximately daily rather than midnight aligned, since ILM checks on a poll interval, and warm at `1d`, cold at `2d` and delete at `60d` are then counted from each rollover. ILM also skips rolling an empty index by default, so you do not need `min_docs`. I would leave `min_primary_shard_size` out unless small indices actually become a problem, because a minimum size condition can hold rollover past `max_age` and that is the opposite of what you are after.

On cold being lighter than hot, which is the other half of what Leandro raised: this policy does not make a cold index smaller, and in your topology it does not put it on different hardware either. ILM injects a migrate action into warm and cold that sets `index.routing.allocation.include._tier_preference`, with cold resolving to `data_cold,data_warm,data_hot`. Your nodes carry all of those roles, and the generic `data` role as well, which takes precedence over the specialised ones. So the preference resolves to the same nodes whatever the phase says. Separate warm and cold nodes are what makes tiering mean something, which is the point he was making.

Disclosure: I'm a co-founder of log10x, which builds tooling to reduce data before it is indexed in Elasticsearch.

Dor

---

<div class="post-metadata">

**Author:** ![Alberto\_Martinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alberto_martinez/32/148116_2.png) [@Alberto\_Martinez](https://discuss.elastic.co/u/Alberto_Martinez)\
**Post date:** [September 15, 2026, 11:50am UTC](https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910/7 "2026-09-15T11:50:58Z")

</div>

Thank you very much for your detailed answer!

I was under the impression that the ILM alone would make the data stream roll over a new index when a new phase started. Instead, the rollover conditions allow finer control as I understand it.

If the warm and cold phases only affect the index priority, then the texts "The warm tier is optimized for search performance over indexing performance." and "The cold tier is optimized for cost savings over search performance." would be some BS. I don't expect the indices to be smaller in disk size, unless using the Replicas, Shrink, Force Merge or Downsample options, but I thought that phasing those indices into warm or cold would mean less RAM usage for keeping them open.

Again, thank you very much. I hope your answers help other too!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 15, 2026, 12:41pm UTC](https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910/8 "2026-09-15T12:41:27Z")

</div>

> [@Alberto\_Martinez](#):
>
> If the warm and cold phases only affect the index priority, then the texts "The warm tier is optimized for search performance over indexing performance." and "The cold tier is optimized for cost savings over search performance." would be some BS. I don't expect the indices to be smaller in disk size, unless using the Replicas, Shrink, Force Merge or Downsample options, but I thought that phasing those indices into warm or cold would mean less RAM usage for keeping them open.

Both descriptions for the warm and cold tier are correct, but it is expected that both warm and cold tiers have different hardware profiles from the hot tier.

If your nodes have all tiers then you do not have real data tiering and this will make no difference.
