# How to specify ILM policies in Elastic agent policy config?

**URL:** <https://discuss.elastic.co/t/how-to-specify-ilm-policies-in-elastic-agent-policy-config/341296>\
**Category:** Elastic Agent\
**Tags:** fleet\
**Created:** [August 21, 2023, 7:43pm UTC](https://discuss.elastic.co/t/how-to-specify-ilm-policies-in-elastic-agent-policy-config/341296 "2023-08-21T19:43:06Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Craig\_Rodrigues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craig_rodrigues/32/121875_2.png) [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Post date:** [August 21, 2023, 7:43pm UTC](https://discuss.elastic.co/t/how-to-specify-ilm-policies-in-elastic-agent-policy-config/341296/1 "2023-08-21T19:43:06Z")

</div>

I have about 2000 Elastic agents (version 8.9.0) connected to a system with 3 Fleet servers (version 8.9.0).

We have about 20 different agent policies, because the various Elastic agents are sending  
slightly different logs, and for certain cases we need to specify specific pipelines to process the logs.

In the Fleet UI, if I go to kbn:/app/fleet/data-streams ,  
I can see each dataset associated with each Elastic Agent.

Is it possible to specify ILM policies for each elastic agent's data set in the agent policy?

Or do ILM policies for an elastic agent's data set need to be specified outside of the agent policy?

I'm having difficulty figuring this out.  
Thanks for any help.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 21, 2023, 9:33pm UTC](https://discuss.elastic.co/t/how-to-specify-ilm-policies-in-elastic-agent-policy-config/341296/2 "2023-08-21T21:33:26Z")

</div>

Elastic Agent uses the same ILM policy for everything, it is an ILM policy named `logs`, every integration will use this same ILM policy.

You can customize the data retention using a custom ILM policy according to the [documentation](https://www.elastic.co/guide/en/fleet/current/data-streams-ilm-tutorial.html#data-streams-ilm-tutorial), but this is a manual process that needs to be done for every data set in every integration.

For example, if an integration have 10 data sets, you will need to create 10 custom templates, you can use the same ILM policy for these templates, but you will need one template per dataset per integration.

The same thing applies to custom ingest pipelines, you can create custom ingest pipelines per dataset per integration.

---

<div class="post-metadata">

**Author:** ![Craig\_Rodrigues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craig_rodrigues/32/121875_2.png) [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Post date:** [August 21, 2023, 10:19pm UTC](https://discuss.elastic.co/t/how-to-specify-ilm-policies-in-elastic-agent-policy-config/341296/3 "2023-08-21T22:19:04Z")

</div>

Thank you @leandrojmp . Your response is very concise and accurate.

I have a related post about elastic agent datasets: [Performance impact of setting 'namespace' in Elastic agent policy config](https://discuss.elastic.co/t/performance-impact-of-setting-namespace-in-elastic-agent-policy-config/341294)

If I have 2000 Elastic agents, 20 agent policies, does that mean that:

1. Look up the Elastic agents that I want to have a customized data retention policy
2. For each Elastic agent, I need to look up the datastream used by that agent going to kbn:/app/fleet/data-streams
3. For each datastream that I want to have a customized ILM, I would need to use custom ILM policies according to the [documentation](https://www.elastic.co/guide/en/fleet/current/data-streams-ilm-tutorial.html#data-streams-ilm-tutorial)

Is my understanding correct?

---

<div class="post-metadata">

**Author:** ![Craig\_Rodrigues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craig_rodrigues/32/121875_2.png) [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Post date:** [August 21, 2023, 10:26pm UTC](https://discuss.elastic.co/t/how-to-specify-ilm-policies-in-elastic-agent-policy-config/341296/4 "2023-08-21T22:26:49Z")

</div>

Also, you mentioned that the default ILM policy used by Elastic agent is `logs`.

In Elastic 8.9.0, if I navigate to:

kbn:/app/management/data/index\_lifecycle\_management/policies

I only see these ILM policies listed:

- .items-default
- .lists-default
- .monitoring-8-ilm-policy
- .preview.alerts-security.alerts-policy
- Systems-Security-Policy
- filebeat
- heartbeat
- kibana-event-log-policy
- kibana-reporting
- log-explorer-policy
- metricbeat
- my-data-lifecycle

Do you know which ILM policy is being used by datastreams created by Elastic agent?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 21, 2023, 10:31pm UTC](https://discuss.elastic.co/t/how-to-specify-ilm-policies-in-elastic-agent-policy-config/341296/5 "2023-08-21T22:31:50Z")

</div>

> [@Craig\_Rodrigues](#):
>
> Do you know which ILM policy is being used by datastreams created by Elastic agent?

I'm not using 8.9, but unless anything has changed the policy is still named `logs`, you need to toggle the option _Include managed system policies_ to show the _managed_ policies.

> [@Craig\_Rodrigues](#):
>
> If I have 2000 Elastic agents, 20 agent policies, does that mean that:
> 
> 1. Look up the Elastic agents that I want to have a customized data retention policy
> 2. For each Elastic agent, I need to look up the datastream used by that agent going to kbn:/app/fleet/data-streams
> 3. For each datastream that I want to have a customized ILM, I would need to use custom ILM policies according to the [documentation](https://www.elastic.co/guide/en/fleet/current/data-streams-ilm-tutorial.html#data-streams-ilm-tutorial)

You need to follow the steps in the documentation, which is basically what you described, but yes, you will need a template for every data stream.

---

<div class="post-metadata">

**Author:** ![Craig\_Rodrigues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craig_rodrigues/32/121875_2.png) [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Post date:** [August 21, 2023, 10:48pm UTC](https://discuss.elastic.co/t/how-to-specify-ilm-policies-in-elastic-agent-policy-config/341296/6 "2023-08-21T22:48:50Z")

</div>

Oh OK! I did the following:

1. navigated to kbn:/app/management/data/index\_lifecycle\_management/policies
2. clicked on **Include managed system policies**

At that point I could see the `logs` ILM policy.

Thank you for your clear and concise explanations!

They really helped me out!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 18, 2023, 10:49pm UTC](https://discuss.elastic.co/t/how-to-specify-ilm-policies-in-elastic-agent-policy-config/341296/7 "2023-09-18T22:49:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
