# ILM Hot, Warm, Cold?

**URL:** <https://discuss.elastic.co/t/ilm-hot-warm-cold/256958>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [November 28, 2020, 5:50pm UTC](https://discuss.elastic.co/t/ilm-hot-warm-cold/256958 "2020-11-28T17:50:58Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![lamp123432](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Post date:** [November 28, 2020, 5:50pm UTC](https://discuss.elastic.co/t/ilm-hot-warm-cold/256958/1 "2020-11-28T17:50:59Z")

</div>

Hello,  
When I try to setup ILM to make an index to become "Warm" after 30 days, then "Cold" after 60 days, and deleted after 90 days, I get the following:

`You can't control shard allocation without node attributes.`

Can someone help me with what to do next?

Thanks!

---

<div class="post-metadata">

**Author:** ![egalpin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/egalpin/32/79772_2.png) [@egalpin](https://discuss.elastic.co/u/egalpin)\
**Post date:** [November 29, 2020, 3:59am UTC](https://discuss.elastic.co/t/ilm-hot-warm-cold/256958/2 "2020-11-29T03:59:06Z")

</div>

To get started, have a look [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/shard-allocation-filtering.html) and [here](https://www.elastic.co/blog/hot-warm-architecture-in-elasticsearch-5-x).

---

<div class="post-metadata">

**Author:** ![Grim](https://avatars.discourse-cdn.com/v4/letter/g/b4bc9f/32.png) [@Grim](https://discuss.elastic.co/u/Grim)\
**Post date:** [November 29, 2020, 7:44am UTC](https://discuss.elastic.co/t/ilm-hot-warm-cold/256958/3 "2020-11-29T07:44:42Z")

</div>

Hi @lamp123432

This warning is telling you that you need to configure your Elasticsearch nodes before using ILM in this way. Open your elasticsearch.yml and use the following setting:

```
node.attr.temp: warm

```

This will tell Elasticsearch where to "move" indices which have been declared as "warm" by your ILM. For more details refer to the links @egalpin posted

---

<div class="post-metadata">

**Author:** ![lamp123432](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Post date:** [November 29, 2020, 3:46pm UTC](https://discuss.elastic.co/t/ilm-hot-warm-cold/256958/4 "2020-11-29T15:46:50Z")

</div>

Hello, thanks for the reply. If I only have one node, does this mean I cannot use this feature?

Even with multiple node, one node should be dedicated to "warm" indexes while other nodes to hot and cold?

---

<div class="post-metadata">

**Author:** ![Grim](https://avatars.discourse-cdn.com/v4/letter/g/b4bc9f/32.png) [@Grim](https://discuss.elastic.co/u/Grim)\
**Post date:** [November 29, 2020, 8:07pm UTC](https://discuss.elastic.co/t/ilm-hot-warm-cold/256958/5 "2020-11-29T20:07:10Z")

</div>

Hey  
well if you have a single node setup, then a hot-warm-cold architecture doesn't make much sense. The background is cost saving. So if you store sequential, time-based data (for example logs), after a while the data gets less relevant and indexing/querying doesn't need to be as fast and performant any more.

Example:

- 3 data nodes – one is "hot", one is "warm" and one is "cold"
- The "hot" node is running on really expensive, super fast hardware, while "warm" and "cold" are running on cheap, old hardware
- Now you can configure your Cluster so only the most recents logs (for example past 14 days) remain on the "hot" node --\> super fast indexing and querying
- After 14 days the indices are rolled over to "warm"
- After 28 days your indices get rolled over to "cold"

---

<div class="post-metadata">

**Author:** ![lamp123432](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Post date:** [November 29, 2020, 10:46pm UTC](https://discuss.elastic.co/t/ilm-hot-warm-cold/256958/6 "2020-11-29T22:46:44Z")

</div>

Great explanation, I do have a client that has 3 nodes, so this will be beneficial.

But I have a second client with only one node, after some time Logstash cannot send anything to Elasticsearch because it complains that all the shards have been allocated. It happens after 3 months, then I have to delete old indexes. So that's why I thought ILM policies could help keep the data longer.

In this case, do you think roll-ups would be my only option?

---

<div class="post-metadata">

**Author:** ![Grim](https://avatars.discourse-cdn.com/v4/letter/g/b4bc9f/32.png) [@Grim](https://discuss.elastic.co/u/Grim)\
**Post date:** [November 29, 2020, 10:51pm UTC](https://discuss.elastic.co/t/ilm-hot-warm-cold/256958/7 "2020-11-29T22:51:24Z")

</div>

Do you have a more precise error? All shards being "allocated" is actually a good thing and should not cause any problems.  
Nevertheless, using Index Lifecycle Policies is best practice and saves you a lot of manual work and disc space when configured correctly 😉  
You can use those policies no matter how many nodes you have - just moving shards based on "temperature" won't be possible on a single node cluster

---

<div class="post-metadata">

**Author:** ![lamp123432](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Post date:** [December 4, 2020, 11:02pm UTC](https://discuss.elastic.co/t/ilm-hot-warm-cold/256958/8 "2020-12-04T23:02:45Z")

</div>

Here's the error:

`Dec 04 18:01:09 node1 logstash[1578]: [2020-12-04T18:01:09,812][WARN][logstash.outputs.elasticsearch][netflow][4bs9s93560b30d657e23c4241487efc] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"netflow-node1-2020.12.04", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0x6c768f05>], :response=>{"index"=>{"_index"=>"netflow-node1-2020.12.04", "_type"=>"_doc", "_id"=>nil, "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"Validation Failed: 1: this action would add [6] total shards, but this cluster currently has [2000]/[2000] maximum shards open;"}}}}`

Logstash cannot send new data to Elasticsearch, because a new index would be created and there is no enough shards available.

This seems to tell me that too many shards are open, I need to close a few of them. So without having dedicated "warm" or "cold" nodes, my only option is to delete indexes to get back some shards?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 4, 2020, 11:41pm UTC](https://discuss.elastic.co/t/ilm-hot-warm-cold/256958/10 "2020-12-04T23:41:09Z")

</div>

What is the output of:

```auto
GET /
GET /_cat/nodes?v
GET /_cat/health?v
GET /_cat/indices?v

```

If some outputs are too big, please share them on [gist.github.com](http://gist.github.com) and link them here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 1, 2021, 11:41pm UTC](https://discuss.elastic.co/t/ilm-hot-warm-cold/256958/11 "2021-01-01T23:41:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
