# How can I create a APM Template with timestamps and the 0000n (for ILM)

**URL:** <https://discuss.elastic.co/t/how-can-i-create-a-apm-template-with-timestamps-and-the-0000n-for-ilm/302338>\
**Category:** APM\
**Tags:** server\
**Created:** [April 13, 2022, 1:11pm UTC](https://discuss.elastic.co/t/how-can-i-create-a-apm-template-with-timestamps-and-the-0000n-for-ilm/302338 "2022-04-13T13:11:24Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![jehanjazz-1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jehanjazz-1/32/104351_2.png) [@jehanjazz-1](https://discuss.elastic.co/u/jehanjazz-1)\
**Post date:** [April 13, 2022, 1:11pm UTC](https://discuss.elastic.co/t/how-can-i-create-a-apm-template-with-timestamps-and-the-0000n-for-ilm/302338/1 "2022-04-13T13:11:24Z")

</div>

Hello to the community,  
I am trying to setup APM with an ILM that I configured manually. If I use the default index available in the output.Elasticsearch, I get indexes similar to "apm-7.16.3-error-000001". I now need to add a timestamp to my indexes so that I can know at which date they were created without having to go thru the details of each index individually.

I have referred to the the below docs and pages and tried to get to the mentioned config :

- [How to set ElasticSearch Apm Server indexing template as YYYY.mm?](https://discuss.elastic.co/t/how-to-set-elasticsearch-apm-server-indexing-template-as-yyyy-mm/177811)
- [Configure Index lifecycle management (ILM) | APM Server Reference [7.15] | Elastic](https://www.elastic.co/guide/en/apm/server/current/ilm-reference.html#ilm-enabled-config)
- [Configure Index lifecycle management (ILM) | APM Server Reference [7.15] | Elastic](https://www.elastic.co/guide/en/apm/server/current/ilm-reference.html#ilm-config-scenarios)

```auto
apm-server:
  host: "0.0.0.0:8200"
  rum.enabled: "true"
  ilm:
    enabled: "true"
    setup:
      enabled: "true"
      overwrite: "true"
      require_policy: "false"
      mapping:
        - event_type: "error"
          policy_name: "My-kibana-ILM-1"
          index_suffix: ""
        - event_type: "span"
          policy_name: "My-kibana-ILM-1"
          index_suffix: ""
        - event_type: "transaction"
          policy_name: "My-kibana-ILM-1"
          index_suffix: ""
        - event_type: "metric"
          policy_name: "My-kibana-ILM-1"
          index_suffix: ""
setup:
  template:
    enabled: "true"
    overwrite: "true"
    name: "apm-%{[observer.version]}"
    pattern: "apm-%{[observer.version]}*"
output:
  elasticsearch:
    enabled: "true"
    protocol: "http"
    hosts: ["loggingcluster-master:9200"]
    index: "apm-%{[observer.version]}-%{[processor.event]}-%{+yyyy.MM.dd}"
    indices:
     - index: "apm-%{[observer.version]}-sourcemap-%{+yyyy.MM.dd}"
       when.contains:
         processor.event: "sourcemap"
     - index: "apm-%{[observer.version]}-error-%{+yyyy.MM.dd}"
       when.contains:
         processor.event: "error"
     - index: "apm-%{[observer.version]}-transaction-%{+yyyy.MM.dd}"
       when.contains:
         processor.event: "transaction"
     - index: "apm-%{[observer.version]}-span-%{+yyyy.MM.dd}"
       when.contains:
         processor.event: "span"
     - index: "apm-%{[observer.version]}-metric-%{+yyyy.MM.dd}"
       when.contains:
         processor.event: "metric"
     - index: "apm-%{[observer.version]}-onboarding-%{+yyyy.MM.dd}"
       when.contains:
         processor.event: "onboarding"

```

I need my indexes to be created in this format : "apm-7.16.3-error-2022-04-13-000001" (need the date to change dynamically based on each day)

Currently with the above config, I am only able to achieve this :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/f/cf867010e390ed8985aff869eba2cc4ca62aea6a.png)

I was able to configure my logstash (for reference, not to be confused with the APM settings)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/3/a35b0a5feea97e1f6e8b63464ff0a11d3f3e725f.png)

Currently working on **apm-server : version: 7.16.3**

---

<div class="post-metadata">

**Author:** ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)\
**Post date:** [April 20, 2022, 10:03am UTC](https://discuss.elastic.co/t/how-can-i-create-a-apm-template-with-timestamps-and-the-0000n-for-ilm/302338/2 "2022-04-20T10:03:29Z")

</div>

Hi @jehanjazz-1 ,

If the date suffix is the only part you want to change, you could still use the default ILM policy and only configure the `index_suffix`; something similar to

```auto
apm-server:
  ilm:
    enabled: "true"
    setup:
      enabled: true
      mapping:
        - event_type: "error"
          policy_name: "apm-rollover-30-days"
          index_suffix: "%{+yyyy-MM-dd}"
        - event_type: "span"
          policy_name: "apm-rollover-30-days"
          index_suffix: "%{+yyyy-MM-dd}"
...

```

would lead to indices such as `apm-7.16.3-error-2022-04-20-000001` and `apm-7.16.3-span-2022-04-20-000001` .

---

<div class="post-metadata">

**Author:** ![jehanjazz-1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jehanjazz-1/32/104351_2.png) [@jehanjazz-1](https://discuss.elastic.co/u/jehanjazz-1)\
**Post date:** [April 20, 2022, 11:52am UTC](https://discuss.elastic.co/t/how-can-i-create-a-apm-template-with-timestamps-and-the-0000n-for-ilm/302338/3 "2022-04-20T11:52:47Z")

</div>

Hello,

Thank you for the suggestion. I will try to apply this in my config and let you know if all goes well.

Cheers !!

---

<div class="post-metadata">

**Author:** ![jehanjazz-1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jehanjazz-1/32/104351_2.png) [@jehanjazz-1](https://discuss.elastic.co/u/jehanjazz-1)\
**Post date:** [April 23, 2022, 10:54am UTC](https://discuss.elastic.co/t/how-can-i-create-a-apm-template-with-timestamps-and-the-0000n-for-ilm/302338/4 "2022-04-23T10:54:30Z")

</div>

Hello @simitt

I tried the configuration, the Indices created were as per the way I needed them to be

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/1/713c3dc57d5a01f648e0cb226246c297300d96d0.png)

Although now the Index template itself has a Date tag in it :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/1/f1da3aefd0eebacbefaec92de95df9a61968c2e9.png)

Is there any way to get the index template without the Date Tag? but get the indexes created with the Date and 0000n format?  
Eg.  
Index Template :  
Name : apm-7.16.3-error  
Pattern : apm-7.16.3-error\*

Indices created by the above template :  
Index name : apm-7.16.3-error-2022-04-23-000001  
ILM : Same from my first config file.

For reference to get the output shown in the images I used this config :

```auto
apm-server:
  host: "0.0.0.0:8200"
  rum.enabled: "true"
  ilm:
    enabled: "true"
    setup:
      enabled: "true"
      overwrite: "true"
      require_policy: "false"
      mapping:
        - event_type: "error"
          policy_name: "My-kibana-logs-1"
          index_suffix: "%{+yyyy-MM-dd}"
        - event_type: "span"
          policy_name: "My-kibana-logs-1"
          index_suffix: "%{+yyyy-MM-dd}"
        - event_type: "transaction"
          policy_name: "My-kibana-logs-1"
          index_suffix: "%{+yyyy-MM-dd}"
        - event_type: "metric"
          policy_name: "My-kibana-logs-1"
          index_suffix: "%{+yyyy-MM-dd}"
queue: {}
output:
  elasticsearch:
    protocol: "http"
    hosts: ["loggingcluster-master:9200"]

```

---

<div class="post-metadata">

**Author:** ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)\
**Post date:** [April 26, 2022, 12:49pm UTC](https://discuss.elastic.co/t/how-can-i-create-a-apm-template-with-timestamps-and-the-0000n-for-ilm/302338/5 "2022-04-26T12:49:05Z")

</div>

No that is not possible, the `index_suffix` is also included into the template. Could you share your concerns and use cases for not including it?

---

<div class="post-metadata">

**Author:** ![jehanjazz-1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jehanjazz-1/32/104351_2.png) [@jehanjazz-1](https://discuss.elastic.co/u/jehanjazz-1)\
**Post date:** [April 26, 2022, 3:41pm UTC](https://discuss.elastic.co/t/how-can-i-create-a-apm-template-with-timestamps-and-the-0000n-for-ilm/302338/6 "2022-04-26T15:41:46Z")

</div>

Hello,

I want to create or setup the APM similar to my logstash setup.

Under Logstash the Index Template created is as such :  
Name : logstash  
Pattern : logstash\*  
Indices created : logstash-2022.04.18-000006

```auto
output {
          elasticsearch {
            hosts => ["http://loggingcluster-master:9200"]
            index => "logstash-%{+yyyy.MM.dd}"
          ilm_pattern => "{now/d}-000001"
          ilm_policy => "My-kibana-logs" 
          }
        }

```

Similar to the above setup and output I wanted to setup APM as well, so that I can manage the APM indices based on the date and time stamp, and incase any manual action is needed, searching via date in the UI becomes much simpler than searching via Created timestamp.

I understand that my question or expectation maybe incorrect, and if so I'll setup APM without the DD-MM-YYYY in the index then.

---

<div class="post-metadata">

**Author:** ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)\
**Post date:** [April 27, 2022, 9:32am UTC](https://discuss.elastic.co/t/how-can-i-create-a-apm-template-with-timestamps-and-the-0000n-for-ilm/302338/7 "2022-04-27T09:32:00Z")

</div>

As showed above, you can use the `index_suffix` to configure a date if prefered, but it will also be part of the template. Generally for the ILM configuration and rollover the date part is not necessary though.

---

<div class="post-metadata">

**Author:** ![jehanjazz-1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jehanjazz-1/32/104351_2.png) [@jehanjazz-1](https://discuss.elastic.co/u/jehanjazz-1)\
**Post date:** [April 27, 2022, 10:56am UTC](https://discuss.elastic.co/t/how-can-i-create-a-apm-template-with-timestamps-and-the-0000n-for-ilm/302338/8 "2022-04-27T10:56:34Z")

</div>

Thank you for your inputs.

I'll configure the index without the Date suffix as of now then, since the ILM works even without them.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2022, 6:56am UTC](https://discuss.elastic.co/t/how-can-i-create-a-apm-template-with-timestamps-and-the-0000n-for-ilm/302338/9 "2022-05-18T06:56:59Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
