# How to change ILM policy?

**URL:** <https://discuss.elastic.co/t/how-to-change-ilm-policy/381161>\
**Category:** Elasticsearch\
**Created:** [August 20, 2025, 10:53am UTC](https://discuss.elastic.co/t/how-to-change-ilm-policy/381161 "2025-08-20T10:53:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![MagnusTHN](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@MagnusTHN](https://discuss.elastic.co/u/MagnusTHN)\
**Post date:** [August 20, 2025, 10:53am UTC](https://discuss.elastic.co/t/how-to-change-ilm-policy/381161/1 "2025-08-20T10:53:13Z")

</div>

Hi everyone,

I’m using Elasticsearch (8.15.1) for logging in my server environment, and Fleet to distribute agents across the servers.  
The indices created are currently using the `logs` index lifecycle policy, which according to Elasticsearch is now deprecated.

What’s the recommended way to change the ILM policy for indices created through Fleet and Elastic Agent?

From what I’ve seen, there are basically two options:

1. Create an index template with a higher priority to override the existing ILM setting.

2. “Fork” the integration package, meaning:

Are there any other approaches I should consider?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 20, 2025, 12:26pm UTC](https://discuss.elastic.co/t/how-to-change-ilm-policy/381161/2 "2025-08-20T12:26:52Z")

</div>

Can you upgrade to 8.19.2? This is way more easier to do on later versions where you just need to add the custom ILM policy on the `@custom` template.

If you cannot upgrade now, you need to follow this specific [documentation](https://www.elastic.co/guide/en/fleet/8.15/data-streams-ilm-tutorial.html) for 8.15.

You would need to clone the index template for **every dataset** in **every integration** that you want to change.

On later versions this step is not required as the default templates already use a `@custom` component template that will be created on the first time you try to edit it.

---

<div class="post-metadata">

**Author:** ![MagnusTHN](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@MagnusTHN](https://discuss.elastic.co/u/MagnusTHN)\
**Post date:** [September 3, 2025, 11:48am UTC](https://discuss.elastic.co/t/how-to-change-ilm-policy/381161/3 "2025-09-03T11:48:48Z")

</div>

Hi, and thank you for your reply.

Elasticsearch version is now 8.19.3

Just to clarify, is it enough if I only update the @custom component templates?  
For example:  
I have an ILM policy called "ilm-logs-firewall", and when I run `GET _component_template` it shows:

```json
{
  "name": "logs-fortinet_fortigate.log@custom",
  "component_template": {
    "template": {
      "settings": {}
    },
    "_meta": {
      "package": {
        "name": "fortinet_fortigate"
      },
      "managed_by": "fleet",
      "managed": true
    }
  }
}

```

So it should be enough if I just add:

```json
PUT _component_template/logs-fortinet_fortigate.log@custom
{
  "template": {
    "settings": {
      "index.lifecycle.name": "ilm-logs-firewall"
    }
  }
}

```

Or have I misunderstood?

Best regards,  
Magnus

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 3, 2025, 12:15pm UTC](https://discuss.elastic.co/t/how-to-change-ilm-policy/381161/4 "2025-09-03T12:15:07Z")

</div>

Yes, just adding the ILM setting on the `@custom` template is enough.

You will need to manually rollover the datastream or wait for it to rollover automatically so new indices can use this policy.
