# Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[actions-logs\] does not point to index \[actions-logs\]

**URL:** <https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916>\
**Category:** Kibana\
**Created:** [January 12, 2024, 7:50am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916 "2024-01-12T07:50:15Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![emoxam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emoxam/32/125661_2.png) [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Post date:** [January 12, 2024, 7:50am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916/1 "2024-01-12T07:50:15Z")

</div>

Got a template with this

> {  
> "index": {  
> "lifecycle": {  
> "name": "logstash-policy",  
> "rollover\_alias": "actions-logs"  
> },  
> "number\_of\_replicas": "0"  
> }  
> }

Got index with name "actions-logs"

But at index "actiong-logs"

Index lifecycle error

> illegal\_argument\_exception: index.lifecycle.rollover\_alias [actions-logs] does not point to index [actions-logs]

Why is it "does not point to index" ?

I see at index settings

> {  
> "settings": {  
> "index": {  
> "lifecycle": {  
> "name": "logstash-policy",  
> "rollover\_alias": "actions-logs"  
> ...

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 12, 2024, 2:15pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916/2 "2024-01-12T14:15:45Z")

</div>

> [@emoxam](#):
>
> Got a template with this
> 
> > {  
> > "index": {  
> > "lifecycle": {  
> > "name": "logstash-policy",  
> > "rollover\_alias": "actions-logs"  
> > },  
> > "number\_of\_replicas": "0"  
> > }  
> > }
> 
> Got index with name "actions-logs"
> 
> But at index "actiong-logs"
> 
> Index lifecycle error
> 
> > illegal\_argument\_exception: index.lifecycle.rollover\_alias [actions-logs] does not point to index [actions-logs]
> 
> Why is it "does not point to index" ?
> 
> I see at index settings
> 
> > {  
> > "settings": {  
> > "index": {  
> > "lifecycle": {  
> > "name": "logstash-policy",  
> > "rollover\_alias": "actions-logs"  
> > ...

Hi,

In your case, you've set the `rollover_alias` to "actions-logs" in your index lifecycle policy. This means that you should have an index alias named "actions-logs" that points to your index.

However, from your message, it seems like "actions-logs" is the name of your index, not an alias. The `rollover_alias` should be an alias that points to the index, not the index name itself.

To resolve this issue, you need to create an alias named "actions-logs" that points to your index.

Regards

---

<div class="post-metadata">

**Author:** ![emoxam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emoxam/32/125661_2.png) [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Post date:** [January 12, 2024, 5:12pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916/3 "2024-01-12T17:12:44Z")

</div>

How to create the alias ?

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 12, 2024, 9:40pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916/4 "2024-01-12T21:40:15Z")

</div>

> [@emoxam](#):
>
> How to create the alias ?

Hi,

go to this link

> **[Aliases | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.11/aliases.html#aliases)**

regards

---

<div class="post-metadata">

**Author:** ![emoxam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emoxam/32/125661_2.png) [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Post date:** [January 13, 2024, 12:04pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916/5 "2024-01-13T12:04:08Z")

</div>

I missed "aliases" setting at kibana at the template settings.  
So i use  
index =\> "actions-logs-%{+YYYY.MM.dd}"  
at my logstash.conf  
then does rollover is mandatory action ?  
I want to keep last 7 days and then remove indexes.  
Thanks

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 14, 2024, 9:20am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916/6 "2024-01-14T09:20:49Z")

</div>

> [@emoxam](#):
>
> I missed "aliases" setting at kibana at the template settings.  
> So i use  
> index =\> "actions-logs-%{+YYYY.MM.dd}"  
> at my logstash.conf  
> then does rollover is mandatory action ?  
> I want to keep last 7 days and then remove indexes.  
> Thanks

Hi,

Rollover is not a mandatory action.

However, if you want to keep the last 7 days of data and then remove indices, you can achieve this by setting up an Index Lifecycle Management (ILM) policy without the rollover action. Here's an example of how you can do this:

```auto
PUT _ilm/policy/my_policy
{
  "policy": {
    "phases": {
      "hot": {
        "min_age": "0ms",
        "actions": {}
      },
      "delete": {
        "min_age": "7d",
        "actions": {
          "delete": {}
        }
      }
    }
  }
}

```

After creating the policy, you can apply it to your index template like this:

```auto
PUT _template/my_template
{
  "index_patterns": ["actions-logs-*"],
  "settings": {
    "number_of_shards": 1,
    "number_of_replicas": 0,
    "index.lifecycle.name": "my_policy",
    "index.lifecycle.rollover_alias": "actions-logs"
  }
}

```

Regards

---

<div class="post-metadata">

**Author:** ![emoxam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emoxam/32/125661_2.png) [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Post date:** [January 14, 2024, 10:55am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916/7 "2024-01-14T10:55:27Z")

</div>

1. At the kibana it's written that hot phase is required

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cd548e845c188c7f9606ad401da8a7f2cd87e5d9.png)

1. If i turn off rollover and stop logstash, delete index, start logstash than my index creating with no mention of deleting.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/9/0942cbba8ceea09cc6611587829e43cab5eda64d.png)

my logstash.conf include this, if this is matter

index =\> "actions-logs-%{+YYYY.MM.dd}"

that's why i am asking does hot action required ? What could it be except than rolover ?

---

<div class="post-metadata">

**Author:** ![emoxam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emoxam/32/125661_2.png) [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Post date:** [January 14, 2024, 11:04am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916/8 "2024-01-14T11:04:16Z")

</div>

GET \_ilm/policy/logstash-policy

> {  
> "logstash-policy": {  
> "version": 15,  
> "modified\_date": "2024-01-14T11:01:17.873Z",  
> "policy": {  
> "phases": {  
> "hot": {  
> "min\_age": "0ms",  
> "actions": {}  
> },  
> "delete": {  
> "min\_age": "7d",  
> "actions": {  
> "delete": {  
> "delete\_searchable\_snapshot": true  
> }  
> }  
> }  
> }  
> },  
> "in\_use\_by": {  
> "indices": [  
> "actions-logs-2024.01.14"  
> ],  
> "data\_streams": ,  
> "composable\_templates": [  
> "actions-logs-alias",  
> "custom",  
> "actions-logs"  
> ]  
> }  
> }  
> }

i see

> ```
> "delete": {
> "min_age": "7d",
> "actions": {
> "delete": {
> 
> ```

Maybe I'm wrong to doubt. I just need it to create new index for every next day. Will it ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2024, 11:04am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916/9 "2024-02-11T11:04:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
