# Illegal\_argument\_exception: index.lifecycle.rollover\_alias does not point to index

**URL:** <https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-does-not-point-to-index/247089>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [September 1, 2020, 12:30pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-does-not-point-to-index/247089 "2020-09-01T12:30:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sgreszcz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sgreszcz/32/46322_2.png) [@sgreszcz](https://discuss.elastic.co/u/sgreszcz)\
**Post date:** [September 1, 2020, 12:30pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-does-not-point-to-index/247089/1 "2020-09-01T12:30:00Z")

</div>

Hi there,

I am getting ILM errors on all of my indexes. For example:

```auto
illegal_argument_exception: index.lifecycle.rollover_alias [ucv-voice-events-cube] does not point to index [ucv-voice-events-cube-2020.08.28]

```

In my case both the index and the alias exist. The ILM profile should roll over each index at max 50GB or 30 days. However the indexes are only rolling over each day.

I think that the problem is I'm not appending -000N to the end of the index. Does anyone know the custom Logstash pattern to get this working? Right now we are consuming from a kafka topic and using that name and the data to create the index. It does roll over every day, but I cannot bind it to an ILM profile to keep the index open until 50GB size is reached and then delete it after 15 days have passed.

```auto
output {
    elasticsearch{
    	hosts => "${ELASTICSEARCH_HOST}:${ELASTICSEARCH_PORT}"
    	index => "%{[@metadata][kafka][topic]}-%{+YYYY.MM.dd}"
    }
}

```

---

<div class="post-metadata">

**Author:** ![sgreszcz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sgreszcz/32/46322_2.png) [@sgreszcz](https://discuss.elastic.co/u/sgreszcz)\
**Post date:** [September 1, 2020, 1:40pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-does-not-point-to-index/247089/2 "2020-09-01T13:40:56Z")

</div>

Also a previous question: [Does ILM work in Logstash with custom index names?](https://discuss.elastic.co/t/does-ilm-work-in-logstash-with-custom-index-names/235816)

And the issue I raised as the ilm\_pattern =\> "000001" didn't work either:

```auto
output {
    elasticsearch{
    	hosts => "${ELASTICSEARCH_HOST}:${ELASTICSEARCH_PORT}"
    	index => "%{[@metadata][kafka][topic]}-%{+YYYY.MM.dd}"
# ilm_rollover_alias => "%{[@metadata][kafka][topic]}"
# ilm_policy => "%{[@metadata][kafka][topic]}"
    	ilm_pattern => "000001"
    }
}

```

I opened an issue here: [https://github.com/elastic/logstash/issues/12214](https://github.com/elastic/logstash/issues/12214)

I saw that @warkolm was addressing a similar question here: [How to correct custom logstash index name for use by ILM](https://discuss.elastic.co/t/how-to-correct-custom-logstash-index-name-for-use-by-ilm/246346)

---

<div class="post-metadata">

**Author:** ![hueyg](https://avatars.discourse-cdn.com/v4/letter/h/8c91f0/32.png) [@hueyg](https://discuss.elastic.co/u/hueyg)\
**Post date:** [September 1, 2020, 3:37pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-does-not-point-to-index/247089/3 "2020-09-01T15:37:50Z")

</div>

I am running into a very related issues. I hope there is some clarification on this soon.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 1, 2020, 8:53pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-does-not-point-to-index/247089/4 "2020-09-01T20:53:46Z")

</div>

Check out [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ilm](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ilm) for how Logstash works with ILM.

---

<div class="post-metadata">

**Author:** ![sgreszcz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sgreszcz/32/46322_2.png) [@sgreszcz](https://discuss.elastic.co/u/sgreszcz)\
**Post date:** [September 1, 2020, 9:27pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-does-not-point-to-index/247089/5 "2020-09-01T21:27:28Z")

</div>

I did read that documentation, but unfortunately the example there didn't work (see above) and there is no good, working example on how to do Logstash + custom index + ILM. If I uncomment the lines in my example above (to make custom aliases and policies), I get an exception. As-is Logstash ignores the ilm\_pattern =\> "000001" and I just get the default YYYY-mm-dd daily rollover However when it tries the ILM profile I get the error: " [Illegal\_argument\_exception: index.lifecycle.rollover\_alias does not point to index](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-does-not-point-to-index/247089)" probably because there isn't the expected -00000N after the index name-date format.

Default filebeat, metricbeat and Logstash ILM finally works in current ElasticStack versions (this wasn't the case for several releases) but I cannot figure out how to get custom Logstash indexes to work with ILM despite reading all the documentation, tutorials, and stack overflow and this forum.

I think I've got to believe that it doesn't work and I'll just have to manage the life of my daily indexes with an external cronjob and the API.

Thanks for the suggestions though, I just wish I could get this working as-built in ElasticSearch.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 3, 2020, 11:50pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-does-not-point-to-index/247089/6 "2020-09-03T23:50:17Z")

</div>

It looks like the section you are missing is [https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started-index-lifecycle-management.html#ilm-gs-alias-bootstrap](https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started-index-lifecycle-management.html#ilm-gs-alias-bootstrap)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 1, 2020, 11:50pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-does-not-point-to-index/247089/7 "2020-10-01T23:50:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
