# Hot-warm policy

**URL:** <https://discuss.elastic.co/t/hot-warm-policy/259862>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [December 30, 2020, 8:56am UTC](https://discuss.elastic.co/t/hot-warm-policy/259862 "2020-12-30T08:56:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abdelhalim](https://avatars.discourse-cdn.com/v4/letter/a/838e76/32.png) [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Post date:** [December 30, 2020, 8:56am UTC](https://discuss.elastic.co/t/hot-warm-policy/259862/1 "2020-12-30T08:56:07Z")

</div>

Hello,

I would like to create a `Hot-warm` policy , and the index should rollover when the index is 20Gb of size or `max_age` equal to 30days **BUT** , if the size condition occur before the age condition, the index should rollover but the data have to stay in the hot node till the `max_age` condition occur. and then the data should be in warm data for 5 months and then deleted.

**Example** : if after 15days the index is `20gb`, the index rollover but don't leave the hot data node till it's age is 30 days, so should stay other 15 days in the hot data before if goes into the warm data (Hope I explain it well 😅)

SO I created this policy

```auto
PUT _ilm/policy/hot-warm-cold-delete-6months-policy
{
  "policy": {
    "phases": {
      "hot": {
        "actions": {
          "rollover": {
            "max_size":"20gb",
            "max_age":"30d"
          },
          "set_priority": {
            "priority": 50
          }
        }
      },
      "warm": {
        "min_age": "30d",
        "actions": {
          "forcemerge": {
            "max_num_segments": 1
          },
          "shrink": {
            "number_of_shards": 1
          },
          "allocate": {
            "require": {
              "data": "warm"
            }
          },
          "set_priority": {
            "priority": 25
          }
        }
      },
      "delete": {
        "min_age": "150d",
        "actions": {
          "delete": {}
        }
      }
    }
  }
}

```

but if I understand well, this means that the index will be sent to the warm data after 30 days of the rollover and it doesn't work as I want exactly

Could you tell me please if what I am trying to do is possible with ILM ?

Thanks for your help 🙂

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [December 30, 2020, 1:40pm UTC](https://discuss.elastic.co/t/hot-warm-policy/259862/2 "2020-12-30T13:40:35Z")

</div>

I haven't used it, but I think this is "lifecycle.parse\_origination\_date"

---

<div class="post-metadata">

**Author:** ![dakrone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dakrone/32/23351_2.png) [@dakrone](https://discuss.elastic.co/u/dakrone)\
**Post date:** [January 4, 2021, 3:48pm UTC](https://discuss.elastic.co/t/hot-warm-policy/259862/3 "2021-01-04T15:48:19Z")

</div>

It is, as mentioned by Len, you can do this with the `parse_origination_date` setting, check out this blog for an example:

> **[Control the phase transition timings in ILM using the origination date](https://www.elastic.co/blog/control-ilm-phase-transition-timings-using-origination-date)**
>
> As data transitions from different systems into Elasticsearch, the origination date index settings provide a way to inform the index lifecycle management module of the age of the data and use it to calculate the phase transition timings.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2021, 3:49pm UTC](https://discuss.elastic.co/t/hot-warm-policy/259862/4 "2021-02-01T15:49:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
