# ILM isn’t it working properly

**URL:** <https://discuss.elastic.co/t/ilm-isn-t-it-working-properly/253248>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [October 25, 2020, 9:06pm UTC](https://discuss.elastic.co/t/ilm-isn-t-it-working-properly/253248 "2020-10-25T21:06:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Armen\_Khachikyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/armen_khachikyan/32/46158_2.png) [@Armen\_Khachikyan](https://discuss.elastic.co/u/Armen_Khachikyan)\
**Post date:** [October 25, 2020, 9:06pm UTC](https://discuss.elastic.co/t/ilm-isn-t-it-working-properly/253248/1 "2020-10-25T21:06:51Z")

</div>

Hey guys, I have a question about ILM...  
I am working on devices logs, have Logstash pipeline for logs, and all of them work correctly. After Installing ILM policy, I have added the policy to my logstash’s elasticsearch output plugin. That all works, but not properly, I Installed 10mb max\_size in Hot phase, but my index is in the rollingover in 16-17mb random sizes. Why ILM policy isn’t working properly?  
Below you will find all needed information.

logstash output

```
output {
  if [type] == "syslog"{
    elasticsearch {
      hosts => ["localhost:9200"]
      ilm_rollover_alias => "syslog"
      ilm_pattern => "000001"
      ilm_policy => "syslog_policy"
    }
  }
}

```

ILM policy

```
"syslog_policy" : {
  "version" : 8,
  "modified_date" : "2020-10-25T15:22:55.418Z",
  "policy" : {
    "phases" : {
      "hot" : {
        "min_age" : "0ms",
        "actions" : {
          "rollover" : {
            "max_size" : "10mb"
          },
          "set_priority" : {
            "priority" : 200
          }
        }
      },
      "delete" : {
        "min_age" : "45m",
        "actions" : {
          "delete" : {
            "delete_searchable_snapshot" : true
          }
        }
      }
    }
  }
},

```

finally my indices

 ![Capture1](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8af75ad52bc96de9d9bd3c8a8120ace5f5c83def.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 26, 2020, 5:54am UTC](https://discuss.elastic.co/t/ilm-isn-t-it-working-properly/253248/2 "2020-10-26T05:54:43Z")

</div>

Is this to test given that 10MB shard sizes are very small and not generally recommended? Rollover by default checks at an interval (10 minutes?) which means that it will not cut exactly if you are indexing too fast with a low threshold.

---

<div class="post-metadata">

**Author:** ![Armen\_Khachikyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/armen_khachikyan/32/46158_2.png) [@Armen\_Khachikyan](https://discuss.elastic.co/u/Armen_Khachikyan)\
**Post date:** [November 19, 2020, 12:51pm UTC](https://discuss.elastic.co/t/ilm-isn-t-it-working-properly/253248/3 "2020-11-19T12:51:44Z")

</div>

thanks bro, now I'm using g with the `max_size` 500mb and `delete` after 7 days, and working in right way

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2020, 12:51pm UTC](https://discuss.elastic.co/t/ilm-isn-t-it-working-properly/253248/4 "2020-12-17T12:51:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
