# I just want a simple ILM rollover policy

**URL:** <https://discuss.elastic.co/t/i-just-want-a-simple-ilm-rollover-policy/175269>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [April 3, 2019, 7:13pm UTC](https://discuss.elastic.co/t/i-just-want-a-simple-ilm-rollover-policy/175269 "2019-04-03T19:13:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [April 3, 2019, 7:13pm UTC](https://discuss.elastic.co/t/i-just-want-a-simple-ilm-rollover-policy/175269/1 "2019-04-03T19:13:18Z")

</div>

But I can't get it working...

I want to replicate with filebeat does, create a new index daily. I just want to rollover on the event of unusual data volume. Say I normally get 20G a day, so I set 1 shard. I want to rollover if I get more than 50G any one day.

It seems to work with for the first day, but it didn't roll over, it showed an error in Kibana index management, something like "index.lifecycle.rollover\_alias" not defined. That IS defined in the logstash output, but it wasn't in the my-index-dd.yy.mm-000001 settings. I added it, then rollover happened. (So I can't get the exact error message back).

Do I need to add this field to the template for my-index? The rollover\_alias isn't in the -00002 index yet either, so I anticipate the same error at the next rollover.

Do I need a different alias? I just set it to "my-index" to try to keep it simple.

Thanks

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [April 3, 2019, 7:16pm UTC](https://discuss.elastic.co/t/i-just-want-a-simple-ilm-rollover-policy/175269/2 "2019-04-03T19:16:31Z")

</div>

I already got the error:

> X Index lifecycle error
> 
> illegal\_argument\_exception: setting [index.lifecycle.rollover\_alias] for index [my-index-2019.04.03-000002] is empty or not defined

---

<div class="post-metadata">

**Author:** ![gbrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbrown/32/34482_2.png) [@gbrown](https://discuss.elastic.co/u/gbrown)\
**Post date:** [April 4, 2019, 3:25am UTC](https://discuss.elastic.co/t/i-just-want-a-simple-ilm-rollover-policy/175269/3 "2019-04-04T03:25:06Z")

</div>

> Do I need to add this field to the template for my-index?

Yes, your index template for the `my-index*` indices should have the setting `index.lifecycle.rollover_alias` set, similar to the example in [this documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/_applying_a_policy_to_our_index.html).

I found it a bit odd that you would need to do this if you have the rollover alias set in Logstash, but there is a note in [the Elasticsearch output docs](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ilm) that looks like it might be saying you need to do this:

> If the rollover alias or pattern is modified, the index template will need to be overwritten as the settings `index.lifecycle.name` and `index.lifecycle.rollover_alias` are automatically written to the template

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2019, 3:25am UTC](https://discuss.elastic.co/t/i-just-want-a-simple-ilm-rollover-policy/175269/4 "2019-05-02T03:25:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
