# How to change the policy of an existing datastream

**URL:** <https://discuss.elastic.co/t/how-to-change-the-policy-of-an-existing-datastream/373811>\
**Category:** Kibana\
**Created:** [January 29, 2025, 11:00am UTC](https://discuss.elastic.co/t/how-to-change-the-policy-of-an-existing-datastream/373811 "2025-01-29T11:00:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ataylor](https://avatars.discourse-cdn.com/v4/letter/a/e495f1/32.png) [@ataylor](https://discuss.elastic.co/u/ataylor)\
**Post date:** [January 29, 2025, 11:00am UTC](https://discuss.elastic.co/t/how-to-change-the-policy-of-an-existing-datastream/373811/1 "2025-01-29T11:00:10Z")

</div>

Hey all,

so current situation is that we set up logging for openshift into elastic, and it has taken the standard Logs index lifecycle policy, However this has a silly retention period, and i need to change this.

I have created an appropriate policy for what we need, but cannot for the life of me work out how to change the policy that is applied to the datastream.

Can anyone offer a step by step solution. (Ideally without any data loss)

TIA

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [January 29, 2025, 2:12pm UTC](https://discuss.elastic.co/t/how-to-change-the-policy-of-an-existing-datastream/373811/2 "2025-01-29T14:12:28Z")

</div>

Hello,

Could you please share the current default policy used & the datastream policy created by you in order to understand how this can be updated.

Thanks!!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 29, 2025, 2:52pm UTC](https://discuss.elastic.co/t/how-to-change-the-policy-of-an-existing-datastream/373811/3 "2025-01-29T14:52:29Z")

</div>

Hi @ataylor Welcome to the community

Perhaps take a look at this

> **[Tutorials: Customize data retention policies | Fleet and Elastic Agent Guide...](https://www.elastic.co/guide/en/fleet/current/data-streams-ilm-tutorial.html)**

I think I provided some instructions here as well

> [@\[BIG-IP ASM\] Could not index event to Elasticsearch](https://discuss.elastic.co/t/big-ip-asm-could-not-index-event-to-elasticsearch/373465/8):
>
> See here how to customize ILM for a data stream... Basically Clone the existing Policy and Edit to your liking and give it a name... like logs-custom Add a custom template you can do through the UI or this is the whole request in Kibana - Dev Tools PUT \_component\_template/logs@custom { "template": { "settings": { "index": { "lifecycle": { "name": "logs-custom" } } } } } If you are going to use agents... you must use data streams If you wan…

---

<div class="post-metadata">

**Author:** ![ataylor](https://avatars.discourse-cdn.com/v4/letter/a/e495f1/32.png) [@ataylor](https://discuss.elastic.co/u/ataylor)\
**Post date:** [February 4, 2025, 3:07pm UTC](https://discuss.elastic.co/t/how-to-change-the-policy-of-an-existing-datastream/373811/4 "2025-02-04T15:07:55Z")

</div>

Hi Thats actually quite useful.

I guess the only remaining question is how do I apply that to the datastream I don't see that in what you added above?

Thanks in Advance.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 4, 2025, 3:21pm UTC](https://discuss.elastic.co/t/how-to-change-the-policy-of-an-existing-datastream/373811/5 "2025-02-04T15:21:55Z")

</div>

> **[Scenario 2: Apply an ILM policy to specific data streams generated from Fleet...](https://www.elastic.co/guide/en/fleet/current/data-streams-scenario2.html#data-streams-scenario2-step3)**

When you rollover the datastream it will automatically be applied behind the scenes... to the new backing indices...

Try the tutorial in detail
