How to Stop Deletion of a Specific Index?


Using Securityonion's 'advanced clustering' which means us managing it's cluster.

Our delete time is set to 15 days for our so-* indices.

If I want to stop specific index: so-zeek-11232022 from being deleted after 15 days, how would I do that.

My only solution that I know how to do, is set the deletion times to super long, then just manually delete and manage the indices.

Any advice? Thank you

There's no way to exclude an index that is part of an ILM policy. You could clone the index to a new name to keep it though.

