# ILM is deleting after rollover

**URL:** <https://discuss.elastic.co/t/ilm-is-deleting-after-rollover/350525>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [January 7, 2024, 8:48am UTC](https://discuss.elastic.co/t/ilm-is-deleting-after-rollover/350525 "2024-01-07T08:48:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![avnere](https://avatars.discourse-cdn.com/v4/letter/a/ba8739/32.png) [@avnere](https://discuss.elastic.co/u/avnere)\
**Post date:** [January 7, 2024, 8:48am UTC](https://discuss.elastic.co/t/ilm-is-deleting-after-rollover/350525/1 "2024-01-07T08:48:47Z")

</div>

Hi,

I have set rollover after 10gb and delete after 7 days.

```auto
PUT _ilm/policy/policy1
{
  "policy": {
    "phases": {
      "hot": {
        "actions": {
          "rollover": {
            "max_primary_shard_size": "10gb"
          }
        }
      },
      "delete": {
        "min_age": "7d",
        "actions": {
          "delete": {}
        }
      }
    }
  }
}

```

I am expecting that the index will be deleted 7 days after rollover.  
But actually it delete it on the same day.  
Why?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 7, 2024, 5:47pm UTC](https://discuss.elastic.co/t/ilm-is-deleting-after-rollover/350525/2 "2024-01-07T17:47:03Z")

</div>

Hi @

Can you run

`GET myindex/_ilm/explain`on one of the indices.

and run

`GET _ilm/policy/policy1`

Technically, the PUT should look like this

```auto
PUT _ilm/policy/policy1
{
  "policy": {
    "phases": {
      "hot": {
        "actions": {
          "rollover": {
            "max_primary_shard_size": "10gb"
          },
          "set_priority": {
            "priority": 100
          }
        },
        "min_age": "0ms"
      },
      "delete": {
        "min_age": "7d",
        "actions": {
          "delete": {}
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![avnere](https://avatars.discourse-cdn.com/v4/letter/a/ba8739/32.png) [@avnere](https://discuss.elastic.co/u/avnere)\
**Post date:** [January 10, 2024, 3:36pm UTC](https://discuss.elastic.co/t/ilm-is-deleting-after-rollover/350525/3 "2024-01-10T15:36:24Z")

</div>

```auto
{
  "indices" : {
    "base_elements_rwr_policy1-2023.11.12-000001" : {
      "index" : "base_elements_rwr_policy1-2023.11.12-000001",
      "managed" : true,
      "policy" : "policy1",
      "lifecycle_date_millis" : 1699747200000,
      "age" : "59.64d",
      "phase" : "hot",
      "phase_time_millis" : 1699792177855,
      "action" : "rollover",
      "action_time_millis" : 1699792177870,
      "step" : "check-rollover-ready",
      "step_time_millis" : 1699792177870,
      "phase_execution" : {
        "policy" : "policy1",
        "phase_definition" : {
          "min_age" : "0ms",
          "actions" : {
            "rollover" : {
              "max_primary_shard_size" : "10gb"
            }
          }
        },
        "version" : 4,
        "modified_date_in_millis" : 1701940116889
      }
    }
  }
}

I am suspecting that it occur due to setting "index.lifecycle.parse_origination_date": true in index template.

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 10, 2024, 4:05pm UTC](https://discuss.elastic.co/t/ilm-is-deleting-after-rollover/350525/4 "2024-01-10T16:05:02Z")

</div>

What version of elasticserach are you on? Important 🙂

So this is what I see...

> [@avnere](#):
>
> ```auto
> "phase_execution" : {
> "policy" : "policy1",
> "phase_definition" : {
> "min_age" : "0ms",
> "actions" : {
> "rollover" : {
> "max_primary_shard_size" : "10gb"
> }
> }
> },
> 
> ```

Couple things... You will notice there is no max\_age.... so can you run

`GET _ilm/policy/policy1`

I suspect that index is under Version 4 which did not have a max age and then you added `max_age` to a later version but that does not take affect on this index.

```auto
        "version" : 4,
        "modified_date_in_millis" : 1701940116889

```

and in that version, there was no max\_age and since it is already in that in the check rollover phase that index is tied to that version... so you will need to rollover manually.

But that new ILM policy should work on newer indices.

---

<div class="post-metadata">

**Author:** ![avnere](https://avatars.discourse-cdn.com/v4/letter/a/ba8739/32.png) [@avnere](https://discuss.elastic.co/u/avnere)\
**Post date:** [January 15, 2024, 11:48am UTC](https://discuss.elastic.co/t/ilm-is-deleting-after-rollover/350525/6 "2024-01-15T11:48:35Z")

</div>

I am suspecting that it occur due to setting "index.lifecycle.parse\_origination\_date": true in index template.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 12, 2024, 11:49am UTC](https://discuss.elastic.co/t/ilm-is-deleting-after-rollover/350525/7 "2024-02-12T11:49:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
