# Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[cisco-switch\] does not point to index \[cisco-switch-2022.07.27\]

**URL:** <https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-cisco-switch-does-not-point-to-index-cisco-switch-2022-07-27/310719>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [July 27, 2022, 7:39am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-cisco-switch-does-not-point-to-index-cisco-switch-2022-07-27/310719 "2022-07-27T07:39:22Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![MADxHAWK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madxhawk/32/103219_2.png) [@MADxHAWK](https://discuss.elastic.co/u/MADxHAWK)\
**Post date:** [July 27, 2022, 7:39am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-cisco-switch-does-not-point-to-index-cisco-switch-2022-07-27/310719/1 "2022-07-27T07:39:22Z")

</div>

Hello,

after trying to figure out some stuff about ILM i need some help now.  
I have about 400 Cisco-Devices sending their logs to a syslog-ng server from where they are send to Elasticsearch via Filebeat / Logstash.  
The logs on the syslogserver are rotated every day at 0:00 UTC and elasticsearch indexing the logs as  
cisco-switch-2022-07.26  
cisco-switch-2022.07.27  
and so on.

I have followed this tutorial to create a ILM : [Tutorial: Automate rollover with ILM | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started-index-lifecycle-management.html) and usesd the 90-days-default ILM

I did the folowing steps:

1. Create the index template

```auto
PUT _index_template/cisco-switch
{
  "template": {
    "settings": {
      "index": {
        "lifecycle": {
          "name": "90-days-default",
          "rollover_alias": "cisco-switch"
        },
        "number_of_shards": "1",
        "number_of_replicas": "0"
      }
    }
  },
  "index_patterns": [
    "cisco-switch-*"
  ],
  "composed_of": []
}

```

1. create initial index

```auto
PUT cisco-switch-000001
{
  "aliases": {
    "cisco-switch": {
      "is_write_index": true
    }
  }
}

```

1. Start Filebeat and Logstash to start loading the logs into elasticsearch

But it doesnt seems to work at all cause im getting the folowing error

> Index lifecycle error
> 
> illegal\_argument\_exception: index.lifecycle.rollover\_alias [cisco-switch] does not point to index [cisco-switch-2022.07.27]

All i want is that indices older than 90ß days get deleted from the index .

Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![bianca6](https://avatars.discourse-cdn.com/v4/letter/b/85e7bf/32.png) [@bianca6](https://discuss.elastic.co/u/bianca6)\
**Post date:** [July 27, 2022, 8:04am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-cisco-switch-does-not-point-to-index-cisco-switch-2022-07-27/310719/2 "2022-07-27T08:04:01Z")

</div>

Hello,

I'm not a professional, I have discovered those ILM last week and came across this problem too.

According to the documentation:  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-error-handling.html#\_index\_lifecycle\_rollover\_alias\_x\_does\_not\_point\_to\_index\_y](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-error-handling.html#_index_lifecycle_rollover_alias_x_does_not_point_to_index_y)

You should check your aliases with `_cat/aliases.`. There I noticed that my first index didn't have the alias (despite the fact I use the `"is_write_index": true` too).

One solution was to run:

- template (as you did)
- create the index (as you did)
- run `PUTcisco-switch-000001/_alias/cisco-switch` to link the alias to the index

It's just for the first index, then it's automatic.  
I hope it will works for you too!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 27, 2022, 10:43pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-cisco-switch-does-not-point-to-index-cisco-switch-2022-07-27/310719/3 "2022-07-27T22:43:01Z")

</div>

Can you share your ILM policy as well please.

---

<div class="post-metadata">

**Author:** ![MADxHAWK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madxhawk/32/103219_2.png) [@MADxHAWK](https://discuss.elastic.co/u/MADxHAWK)\
**Post date:** [July 28, 2022, 5:57am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-cisco-switch-does-not-point-to-index-cisco-switch-2022-07-27/310719/4 "2022-07-28T05:57:56Z")

</div>

@bianca6  
thank you very much.  
put \_cat/aliases shows

```auto
.transform-notifications-read .transform-notifications-000002 - - - -
.kibana-event-log-8.3.2 .kibana-event-log-8.3.2-000001 - - - true
.preview.alerts-security.alerts-default .internal.preview.alerts-security.alerts-default-000059 - - - false
.kibana_task_manager_8.2.2 .kibana_task_manager_8.2.2_001 - - - -
.lists-default .lists-default-000001 - - - true
.preview.alerts-security.alerts-default .internal.preview.alerts-security.alerts-default-000060 - - - true
.kibana_task_manager .kibana_task_manager_8.3.2_001 - - - -
.kibana_task_manager_8.3.2 .kibana_task_manager_8.3.2_001 - - - -
.items-default .items-default-000001 - - - true
.kibana_8.2.2 .kibana_8.2.2_001 - - - -
.security .security-7 - - - -
cisco-switch cisco-switch-000001 - - - -
.kibana .kibana_8.3.2_001 - - - -
.kibana_8.3.2 .kibana_8.3.2_001 - - - -
.kibana-event-log-8.2.2 .kibana-event-log-8.2.2-000002 - - - false
.kibana-event-log-8.2.2 .kibana-event-log-8.2.2-000001 - - - false
cisco-asa cisco-asa-000001 - - - -
.kibana-event-log-8.2.2 .kibana-event-log-8.2.2-000003 - - - true

```

but cisco\_switch-2022.07.26, cisco-switch-2022.07.27 and cisco-switch2022.07.28 are not listed there, same for cisco-asa-2022.07.xx

somehow the template seems to not add the aliases to the new created indices and i keep getting the error.

@warkolm im using the default ILM Policy 90-days-default that came with ELK-Stack without any changes to it, but here it is:

```auto
PUT _ilm/policy/90-days-default
{
  "policy": {
    "phases": {
      "hot": {
        "min_age": "0ms",
        "actions": {
          "rollover": {
            "max_age": "30d",
            "max_primary_shard_size": "50gb"
          }
        }
      },
      "warm": {
        "min_age": "2d",
        "actions": {
          "shrink": {
            "number_of_shards": 1
          },
          "forcemerge": {
            "max_num_segments": 1
          }
        }
      },
      "cold": {
        "min_age": "30d",
        "actions": {}
      },
      "delete": {
        "min_age": "90d",
        "actions": {
          "delete": {
            "delete_searchable_snapshot": true
          }
        }
      }
    },
    "_meta": {
      "managed": true,
      "description": "built-in ILM policy using the hot, warm, and cold phases with a retention of 90 days"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 28, 2022, 6:10am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-cisco-switch-does-not-point-to-index-cisco-switch-2022-07-27/310719/5 "2022-07-28T06:10:27Z")

</div>

If you are sending data to time-based indices with date in the name you can not use rollover as part of ILM. The whole point of [rollover](https://www.elastic.co/blog/managing-time-based-indices-efficiently) is to have a single alias that you write to and let Elasticsearch roll over backing indices automatically based on size and age. This relies on you giving up control of exactly which data that go into which backing index.

You therefore have 2 options. The first is to use rollover and require you to write to the `cisco-switch` alias instead of index names with date in the names.

If you instead prefer to write to indices in the form `cisco-switch-2022-07.26` you should remove rollover from the ILM policy.

---

<div class="post-metadata">

**Author:** ![MADxHAWK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madxhawk/32/103219_2.png) [@MADxHAWK](https://discuss.elastic.co/u/MADxHAWK)\
**Post date:** [July 28, 2022, 6:17am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-cisco-switch-does-not-point-to-index-cisco-switch-2022-07-27/310719/6 "2022-07-28T06:17:08Z")

</div>

Hello @Christian_Dahlqvist

You mean something like this should delete my indices when they become older than 90 days?

```auto
PUT _ilm/policy/cisco-90-days
{
  "policy": {
    "phases": {
      "hot": {
        "actions": {
          "set_priority": {
            "priority": 100
          }
        },
        "min_age": "0ms"
      },
      "delete": {
        "min_age": "90d",
        "actions": {
          "delete": {}
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 28, 2022, 6:20am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-cisco-switch-does-not-point-to-index-cisco-switch-2022-07-27/310719/7 "2022-07-28T06:20:54Z")

</div>

Yes, something like that.

---

<div class="post-metadata">

**Author:** ![MADxHAWK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madxhawk/32/103219_2.png) [@MADxHAWK](https://discuss.elastic.co/u/MADxHAWK)\
**Post date:** [July 28, 2022, 6:26am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-cisco-switch-does-not-point-to-index-cisco-switch-2022-07-27/310719/8 "2022-07-28T06:26:19Z")

</div>

thank you 🙂 I will try

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2022, 6:26am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-cisco-switch-does-not-point-to-index-cisco-switch-2022-07-27/310719/9 "2022-08-25T06:26:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
