# ILM index rollover error

**URL:** <https://discuss.elastic.co/t/ilm-index-rollover-error/315938>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [October 6, 2022, 8:15am UTC](https://discuss.elastic.co/t/ilm-index-rollover-error/315938 "2022-10-06T08:15:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Khaled\_Saidi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khaled_saidi/32/98636_2.png) [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Post date:** [October 6, 2022, 8:15am UTC](https://discuss.elastic.co/t/ilm-index-rollover-error/315938/1 "2022-10-06T08:15:40Z")

</div>

Hi everyone,  
Hope you will be able to help me another time.  
I have an elasticsearch cluster with an ILM Policy to manage the index rollover.  
The rollover is based on the index size.  
Everything was running well. The coordinator node load balance to another master eligible node  
when index size limit is reached **OR** when the disk is full.  
But i'm facing a "strange" behavior that i don't understand.  
When the index size is reached **AND** the disk is full at the same time, an error is logged :

> policy [ilm-traffics-logs-policy] for index  
> [idx-aggregated-logs-000001] failed on step  
> [{"phase":"hot","action":"rollover",  
> "name":"check-rollover-ready"}]. Moving to ERROR step  
> java.lang.IllegalArgumentException: setting [index.lifecycle.rollover\_alias]  
> for index [idx-aggregated-logs-000001] is empty or not defined

Documents are no more stored in elasticsearch, because the index was set to read-only mode .

> [b9891m.prv] flood stage disk watermark [95%] exceeded on  
> [seMsQpW-QrylKpA0AUZvZA][b9891m.prv]  
> [/appli/elasticsearch/data\_elasticsearch/nodes/0] free: 1mb[0%],  
> all indices on this node will be marked read-only

Is someone understand this and know how to fix it ?  
Thanks for your help !

BR,  
KS

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 6, 2022, 10:36am UTC](https://discuss.elastic.co/t/ilm-index-rollover-error/315938/2 "2022-10-06T10:36:04Z")

</div>

Elasticsearch has [built-in protection against filling up the disk](https://www.elastic.co/guide/en/elasticsearch/reference/8.4/disk-usage-exceeded.html) as this could cause corruption and data loss. If you get too close to the limit, indices will be made read only. You therefore probably need to adjust your parameters so you rollover and move data off the node before this level is reached.

---

<div class="post-metadata">

**Author:** ![Khaled\_Saidi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khaled_saidi/32/98636_2.png) [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Post date:** [October 6, 2022, 2:50pm UTC](https://discuss.elastic.co/t/ilm-index-rollover-error/315938/3 "2022-10-06T14:50:34Z")

</div>

Sorry for my question but which parameters need to be adjusted to avoid my error ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 6, 2022, 2:51pm UTC](https://discuss.elastic.co/t/ilm-index-rollover-error/315938/4 "2022-10-06T14:51:43Z")

</div>

Your settings for rollover in the ILM policy.

---

<div class="post-metadata">

**Author:** ![Khaled\_Saidi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khaled_saidi/32/98636_2.png) [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Post date:** [October 6, 2022, 3:06pm UTC](https://discuss.elastic.co/t/ilm-index-rollover-error/315938/5 "2022-10-06T15:06:31Z")

</div>

here are the details of my ILM Policy :

```auto
{
  "ilm-traffics-logs-policy": {
    "version": 1,
    "modified_date": "2022-10-05T13:48:01.632Z",
    "policy": {
      "phases": {
        "hot": {
          "min_age": "0ms",
          "actions": {
            "rollover": {
              "max_size": "10mb",
              "max_age": "365d"
            }
          }
        },
        "delete": {
          "min_age": "3d",
          "actions": {
            "delete": {
              "delete_searchable_snapshot": true
            }
          }
        }
      }
    },
    "in_use_by": {
      "indices": [
        "idx-aggregated-logs-000001"
      ],
      "data_streams": [],
      "composable_templates": [
        "ilm-traffics-logs-template"
      ]
    }
  }
}

```

I don't see which ones to adjust to avoid the behavior i actually has.... 😢  
if i increase the index max\_size value, the problem will occurs later, but will occurs

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 6, 2022, 3:18pm UTC](https://discuss.elastic.co/t/ilm-index-rollover-error/315938/6 "2022-10-06T15:18:06Z")

</div>

> [@Khaled\_Saidi](#):
>
> ```auto
> "rollover": {
> "max_size": "10mb",
> "max_age": "365d"
> 
> ```

10MB is very small. This should typically be at least a few GB. 365 days is also a very long period. You typically set this as a fraction of your total retention period. If you want to keep data for only 3 days you should set this to 1 day. If you want to keep data in the cluster for 365 days a value of 30 days may be more appropriate.

How much disk space does the node have? How much data are you ingesting per day?

---

<div class="post-metadata">

**Author:** ![Khaled\_Saidi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khaled_saidi/32/98636_2.png) [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Post date:** [October 7, 2022, 1:10pm UTC](https://discuss.elastic.co/t/ilm-index-rollover-error/315938/7 "2022-10-07T13:10:06Z")

</div>

Hello Christian,  
Thank you to take time to explain to me. i appreciate 🙂 !  
The settings i have posted are for my sandbox environment.  
I set the max size to 10mb just to reproduce the bug faster.  
In reality, the index max\_size is 50Gb, and the disk capacity is 400Gb.  
The cluster ingest about 3000000 docs by day

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 1:10pm UTC](https://discuss.elastic.co/t/ilm-index-rollover-error/315938/8 "2022-11-04T13:10:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
