# How to create a new ILM policy for Filebeat with Elasticsearch on Kubernetes?

**URL:** <https://discuss.elastic.co/t/how-to-create-a-new-ilm-policy-for-filebeat-with-elasticsearch-on-kubernetes/375552>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Tags:** ilm-index-lifecycle-management\
**Created:** [March 7, 2025, 9:55am UTC](https://discuss.elastic.co/t/how-to-create-a-new-ilm-policy-for-filebeat-with-elasticsearch-on-kubernetes/375552 "2025-03-07T09:55:32Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![zhangjingqiang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zhangjingqiang/32/99257_2.png) [@zhangjingqiang](https://discuss.elastic.co/u/zhangjingqiang)\
**Post date:** [March 7, 2025, 9:55am UTC](https://discuss.elastic.co/t/how-to-create-a-new-ilm-policy-for-filebeat-with-elasticsearch-on-kubernetes/375552/1 "2025-03-07T09:55:32Z")

</div>

I'm using [ECK helm chart](https://artifacthub.io/packages/helm/elastic/eck-operator) and created a Filebeat with Beat CRD:

```bash
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
  name: quickstart
  namespace: default
spec:
  type: filebeat
  version: 8.17.3
  elasticsearchRef:
    name: quickstart
  config:
    filebeat.inputs:
    - type: container
      paths:
      - /var/log/containers/*.log
    output.elasticsearch:
      ilm:
        enabled: true
        policy_name: "filebeat_policy"
  ......

```

I created a `filebeat_policy.json` policy:

```bash
{
    "policy":{
       "phases":{
          "hot":{
             "actions":{
                "rollover":{
                    "max_age": "1d",
                    "max_docs": 10000,
                    "max_size": "10gb"
                }
             }
          },
          "delete":{
             "min_age":"30d",
             "actions":{
                "delete":{
                   
                }
             }
          }
       }
    }
}

```

But after I create policy this way:

```bash
curl -X PUT -k -u elastic:$ELASTIC_PASSWORD "https://localhost:9200/_ilm/policy/filebeat_policy" -H 'Content-Type: application/json' -d @./values/elastic/filebeat-policy.json

```

I can't find the `filebeat_policy` in the current Elasticsearch indices:

```bash
curl -X GET -k -u elastic:$ELASTIC_PASSWORD "https://localhost:9200/_data_stream/filebeat-*?pretty"

```

If I do this way, it works:

```bash
curl -X PUT -k -u elastic:$ELASTIC_PASSWORD "https://localhost:9200/_component_template/filebeat-settings" -H 'Content-Type: application/json' -d '
{
  "template": {
    "settings": {
      "index.lifecycle.name": "filebeat_policy"
    }
  }
}'
curl -X PUT -k -u elastic:$ELASTIC_PASSWORD "https://localhost:9200/_index_template/filebeat-8.15.3" -H 'Content-Type: application/json' -d '
{
  "index_patterns": ["filebeat-*"],
  "data_stream": {},
  "composed_of": ["filebeat-settings"]
}'

```

So my question is, if use Beat CRD, doesn't it work in `config` section below?

```bash
    output.elasticsearch:
      ilm:
        enabled: true
        policy_name: "filebeat_policy"

```
