# How can I name Curator rollover new Index like date prefix-YYYY.MM.DD-1?

**URL:** <https://discuss.elastic.co/t/how-can-i-name-curator-rollover-new-index-like-date-prefix-yyyy-mm-dd-1/128542>\
**Category:** Elasticsearch\
**Created:** [April 18, 2018, 1:20pm UTC](https://discuss.elastic.co/t/how-can-i-name-curator-rollover-new-index-like-date-prefix-yyyy-mm-dd-1/128542 "2018-04-18T13:20:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jugaji](https://avatars.discourse-cdn.com/v4/letter/j/258eb7/32.png) [@jugaji](https://discuss.elastic.co/u/jugaji)\
**Post date:** [April 18, 2018, 1:20pm UTC](https://discuss.elastic.co/t/how-can-i-name-curator-rollover-new-index-like-date-prefix-yyyy-mm-dd-1/128542/1 "2018-04-18T13:20:01Z")

</div>

Hi!!  
I want curator rollover by date (prefix-YYYY.MM.DD-1) like description at:  
[https://www.elastic.co/guide/en/elasticsearch/client/curator/current/rollover.html](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/rollover.html)

My configuration is:

- Create index:

```auto
PUT /logsservices-2018.04.17-1

```

- Create Alias:

```auto
POST /_aliases
{
  "actions" : [
    { "add" : { "indices" : ["logsservices-2018.04.17-1"], "alias" : "logsservices" } }
  ]
}

```

- Config action:

```auto
actions:
  1:
    action: rollover
    description: >-
      Rollover the index associated with alias 'aliasname', which should be in the
      form of prefix-000001 (or similar), or prefix-YYYY.MM.DD-1.
    options:
      name: logsservices
      conditions:
      max_age: 1d
      max_docs: 1000000
      extra_settings:
        index.number_of_shards: 5
        index.number_of_replicas: 1

```

However, at next day I get this on log:  
//2018-04-18 12:00:17,880 DEBUG elasticsearch log\_request\_success:86 \< {"old\_index":"logsservices-2018.04.17-1","new\_index":"logsservices-2018.04.17-000002","rolled\_over":true,"dry\_run":false,"acknowledged":true,"shards\_acknowledged":true,"conditions":{"[max\_docs: 1000000]":false,"[max\_age: 1d]":true}}

and created a new index with name "logsservices-2018.04.17-000002" instead of "logsservices-2018.04.18-1"

what am I making wrong? How is the correct configuration?

Thanks!!!

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 18, 2018, 2:13pm UTC](https://discuss.elastic.co/t/how-can-i-name-curator-rollover-new-index-like-date-prefix-yyyy-mm-dd-1/128542/2 "2018-04-18T14:13:32Z")

</div>

I took the liberty of editing your post to make it legible. Please use the code tags or triple back-ticks to encapsulate preformatted text in the future.

First, you can create the index and the alias in one shot:

```auto
PUT /logservices-2018.04.17-1
{
  "aliases": {
    "logservices": {}
  }
}

```

Second, there is an [undocumented feature](https://github.com/elastic/curator/issues/1197) for the rollover action that lets you name a new index:

```auto
  options:
    ...
    new_index: '<logservices-{now/d}-1}>'

```

If you need something other than the current year-month-day, look at the [date math docs](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/common-options.html#date-math) and follow the conventions there.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 18, 2018, 2:20pm UTC](https://discuss.elastic.co/t/how-can-i-name-curator-rollover-new-index-like-date-prefix-yyyy-mm-dd-1/128542/3 "2018-04-18T14:20:06Z")

</div>

On a separate note, why even both with dated indices if you're using rollover? You can still use Curator's other age filter options (i.e. field stats) to calculate the index age without needing the index to have a timestamp in the index name. You're generally better off letting the index grow to 5+ GB per shard before rolling over anyway, as smaller than that is just wasted resources.

I heavily advocate just naming the indices `logservices-000001` and rolling over to just the next number.

---

<div class="post-metadata">

**Author:** ![jugaji](https://avatars.discourse-cdn.com/v4/letter/j/258eb7/32.png) [@jugaji](https://discuss.elastic.co/u/jugaji)\
**Post date:** [April 18, 2018, 3:58pm UTC](https://discuss.elastic.co/t/how-can-i-name-curator-rollover-new-index-like-date-prefix-yyyy-mm-dd-1/128542/4 "2018-04-18T15:58:14Z")

</div>

Great!! I like this solution but I have a question.

I'm thinking use delete\_indices action for delete older logs and the Elasticsearch version is 6.2. Should I use field\_caps or field\_stats on filter age to get field @timestamp?

Thanks!!!

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 18, 2018, 4:21pm UTC](https://discuss.elastic.co/t/how-can-i-name-curator-rollover-new-index-like-date-prefix-yyyy-mm-dd-1/128542/5 "2018-04-18T16:21:31Z")

</div>

Curator still calls it `field_stats`, but it's actually just doing a [query and `min` or `max` aggregations](https://github.com/elastic/curator/blob/v5.5.1/curator/indexlist.py#L307-L314) now. Just use that with Curator.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 16, 2018, 4:21pm UTC](https://discuss.elastic.co/t/how-can-i-name-curator-rollover-new-index-like-date-prefix-yyyy-mm-dd-1/128542/6 "2018-05-16T16:21:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
