# How can i create logstash index every 4 hours except 1 hour

**URL:** <https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928>\
**Category:** Logstash\
**Created:** [April 14, 2020, 1:48pm UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928 "2020-04-14T13:48:38Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dragon9](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@Dragon9](https://discuss.elastic.co/u/Dragon9)\
**Post date:** [April 14, 2020, 1:48pm UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/1 "2020-04-14T13:48:38Z")

</div>

like

```auto
  output{
    elasticsearch {
        index => "logstash-%{+YYYY.MM.dd.hh}"
     }  
}

```

for example:-  
logstash-2020.04.14.07  
logstash-2020.04.14.11

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 14, 2020, 9:07pm UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/2 "2020-04-14T21:07:29Z")

</div>

Can I ask why you want them hourly?

---

<div class="post-metadata">

**Author:** ![Dragon9](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@Dragon9](https://discuss.elastic.co/u/Dragon9)\
**Post date:** [April 15, 2020, 8:33am UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/3 "2020-04-15T08:33:55Z")

</div>

my requirement is that i want my purging hourly.  
but when i set logstash index creation to hourly then elasticsearch shards failed  
because of bulk of indexes. So if i set logstash index creation in every 4-6 hours  
i think elasticsearch have no issue.  
this is due to in a day only 4-6 indexes create for a application if i set index creation to 4-6 hours

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 15, 2020, 8:37am UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/4 "2020-04-15T08:37:12Z")

</div>

You should just use ILM to manage this for you, it'd be a lot easier.

---

<div class="post-metadata">

**Author:** ![Dragon9](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@Dragon9](https://discuss.elastic.co/u/Dragon9)\
**Post date:** [April 15, 2020, 8:47am UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/5 "2020-04-15T08:47:41Z")

</div>

i am using curator for purging

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 15, 2020, 9:16am UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/6 "2020-04-15T09:16:12Z")

</div>

Yeah I appreciate, ILM would remove a lot of the hassle here though.

However, does your example config not work?

---

<div class="post-metadata">

**Author:** ![Dragon9](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@Dragon9](https://discuss.elastic.co/u/Dragon9)\
**Post date:** [April 15, 2020, 9:19am UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/7 "2020-04-15T09:19:15Z")

</div>

i think if i store date\_time in variable in logstash and use it in if condition for my  
but i want a standard solution from you

---

<div class="post-metadata">

**Author:** ![Dragon9](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@Dragon9](https://discuss.elastic.co/u/Dragon9)\
**Post date:** [April 15, 2020, 12:29pm UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/8 "2020-04-15T12:29:45Z")

</div>

@warkolm how to do that ,plz help

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 15, 2020, 2:14pm UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/9 "2020-04-15T14:14:05Z")

</div>

@Dragon9 with respect, that's what @warkolm was trying to tell you. ILM _is_ our "standard solution" for this use case—and Logstash works in conjunction with ILM.

ILM = Index Lifecycle Management.

To be completely transparent, Logstash does not create indices. It only tells Elasticsearch that document _d_ belongs in index _i._ Elasticsearch creates index _i_ if it does not exist.

So with ILM set up, then you can set up a rollover period of any time interval you like. When the index meets one of three possible conditions (max age, document count, or size), it will be rolled over. If you create the initial index with a datestamp in it (using date math), you will also have record of when the index was created in the index name itself—and all subsequent rolled-over indices will automatically have the date stamp in the same format.

I suggest reading up on ILM [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-management.html) before trying to shoehorn Logstash and Curator to fit this use case when ILM is both a better fit, and built-in to the Elastic Stack (and I say that as the creator and maintainer of Curator).

---

<div class="post-metadata">

**Author:** ![Dragon9](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@Dragon9](https://discuss.elastic.co/u/Dragon9)\
**Post date:** [April 16, 2020, 11:24am UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/10 "2020-04-16T11:24:34Z")

</div>

@theuntergeek  
when i use curator for alias and rollover.  
my old index is logstash-2020.04.16-1 and  
new index like logstash-2020.04.16-000002  
but in new index data is not writing .how to solve this

my configuration is

```auto
     1:
        action: alias
        description: >-
         Alias indices from last week, with a prefix of kibana_sample_data_ecommerce to 'kibana_alias-000001',
         remove indices from the previous week.
        options:
          name: logst
          warn_if_no_indices: False
          disable_action: False
        add:
          filters:
          - filtertype: pattern
            kind: prefix
            value: logstash-  
     2:
        action: rollover
        description: >-
         Rollover the index associated with alias 'aliasname', which should be in the
         format of prefix-000001 (or similar), or prefix-YYYY.MM.DD-1.
        options:
          disable_action: False
          name: logst
          conditions:
            max_age: 10s

```

---

<div class="post-metadata">

**Author:** ![Dragon9](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@Dragon9](https://discuss.elastic.co/u/Dragon9)\
**Post date:** [April 16, 2020, 3:36pm UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/11 "2020-04-16T15:36:44Z")

</div>

with this i also have two questions:  
1.is rollover policy and index template is mandatory.  
2.how to configure logstash output for push data automatically in rollover index

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 17, 2020, 1:23am UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/12 "2020-04-17T01:23:37Z")

</div>

1. Only if you had one before
2. Set `index => "alias_name"` in your Logstash elasticsearch output block to always write to the alias.

---

<div class="post-metadata">

**Author:** ![Dragon9](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@Dragon9](https://discuss.elastic.co/u/Dragon9)\
**Post date:** [April 17, 2020, 8:16am UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/13 "2020-04-17T08:16:50Z")

</div>

> [@theuntergeek](#):
>
> index =\> "alias\_name"

when i do this logstash throw error

```auto
[2020-04-17T08:11:17,864][ERROR][logstash.outputs.elasticsearch] Encountered a retryable error. Will Retry with exponential backoff {:code=>400, :url=>"http://10.109.226.97:9200/_bulk"}
[2020-04-17T08:11:18,122][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600}
[2020-04-17T08:11:19,999][ERROR][logstash.outputs.elasticsearch] Encountered a retryable error. Will Retry with exponential backoff {:code=>400, :url=>"http://10.109.226.97:9200/_bulk"}
[2020-04-17T08:11:24,012][ERROR][logstash.outputs.elasticsearch] Encountered a retryable error. Will Retry with exponential backoff {:code=>400, :url=>"http://10.109.226.97:9200/_bulk"}
[2020-04-17T08:11:32,051][ERROR][logstash.outputs.elasticsearch] Encountered a retryable error. Will Retry with exponential backoff {:code=>400, :url=>"http://10.109.226.97:9200/_bulk"}
[2020-04-17T08:11:48,064][ERROR][logstash.outputs.elasticsearch] Encountered a retryable error. Will Retry with exponential backoff {:code=>400, :url=>"http://10.109.226.97:9200/_bulk"}
[2020-04-17T08:12:20,098][ERROR][logstash.outputs.elasticsearch] Encountered a retryable error. Will Retry with exponential backoff {:code=>400, :url=>"http://10.109.226.97:9200/_bulk"}
[2020-04-17T08:13:24,108][ERROR][logstash.outputs.elasticsearch] Encountered a retryable error. Will Retry with exponential backoff {:code=>400, :url=>"http://10.109.226.97:9200/_bulk"}

```

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 17, 2020, 4:25pm UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/14 "2020-04-17T16:25:47Z")

</div>

This implies there's perhaps something else in your Elasticsearch output block.

Please share that portion of your Logstash output configuration, taking care to obfuscate/redact/remove username, password, and hosts (if they're not local).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2020, 4:25pm UTC](https://discuss.elastic.co/t/how-can-i-create-logstash-index-every-4-hours-except-1-hour/227928/15 "2020-05-15T16:25:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
