# ILM not rolling over at correct size

**URL:** https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160
**Category:** Elasticsearch
**Created:** [July 12, 2019, 8:04am UTC](https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160 "2019-07-12T08:04:34Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![jamesp220291](https://avatars.discourse-cdn.com/v4/letter/j/91b2a8/32.png) [@jamesp220291](https://discuss.elastic.co/u/jamesp220291)
#### Post date: [July 12, 2019, 8:04am UTC](https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160/1 "2019-07-12T08:04:35Z")

</div>

Hi

I have created an ILM policy and applied it to my Index -

{  
"policy": "my\_logs\_policy",  
"phase\_definition": {  
"min\_age": "0ms",  
"actions": {  
"rollover": {  
"max\_size": "30gb"  
}  
}  
},

I have also set the below -  
PUT /\_cluster/settings  
{  
"persistent" : {  
"indices.lifecycle.poll\_interval": "5s"  
}  
}

However, my index is rolling over at 60GB, and not 30GB, can anyone advise why and how to resolve this?

---

<div class="post-metadata">

### Author: ![jamesp220291](https://avatars.discourse-cdn.com/v4/letter/j/91b2a8/32.png) [@jamesp220291](https://discuss.elastic.co/u/jamesp220291)
#### Post date: [July 12, 2019, 12:47pm UTC](https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160/2 "2019-07-12T12:47:47Z")

</div>

The ILM is deffo applied, as it does rollover just not when it should.

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [July 12, 2019, 1:59pm UTC](https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160/3 "2019-07-12T13:59:56Z")

</div>

Is the older index still 60GB after refreshing and flushing it, and ensuring that there aren't any ongoing merges? Is that 60GB the size of the store or are you including the translog size too? Looking through the code, it seems we ignore "transient" data like the translog and invisible segments when computing the size for rollover purposes, because those transient data are eventually discarded.

---

<div class="post-metadata">

### Author: ![jamesp220291](https://avatars.discourse-cdn.com/v4/letter/j/91b2a8/32.png) [@jamesp220291](https://discuss.elastic.co/u/jamesp220291)
#### Post date: [July 15, 2019, 8:26am UTC](https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160/4 "2019-07-15T08:26:30Z")

</div>

Hi

Yes i have refreshed/flushed it and it is still 60GB.

The ILM seems to be rolling over @60GB instead of 30GB for some reason, as over the weekend it has created 2 more indexs @ 60GB.

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [July 15, 2019, 8:40am UTC](https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160/5 "2019-07-15T08:40:41Z")

</div>

How are you measuring the size of these rolled-over indices? Can you share the exact API call you're using as well as its output?

---

<div class="post-metadata">

### Author: ![jamesp220291](https://avatars.discourse-cdn.com/v4/letter/j/91b2a8/32.png) [@jamesp220291](https://discuss.elastic.co/u/jamesp220291)
#### Post date: [July 15, 2019, 8:56am UTC](https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160/6 "2019-07-15T08:56:29Z")

</div>

Hi

I am just looking in Kibana under index management, no using any sort of API ect.

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [July 15, 2019, 9:11am UTC](https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160/7 "2019-07-15T09:11:08Z")

</div>

Ok, I'm not quite sure where that UI gets its data. Can you share the output of `GET /<index>/_stats` for the index in question?

---

<div class="post-metadata">

### Author: ![jamesp220291](https://avatars.discourse-cdn.com/v4/letter/j/91b2a8/32.png) [@jamesp220291](https://discuss.elastic.co/u/jamesp220291)
#### Post date: [July 15, 2019, 9:13am UTC](https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160/8 "2019-07-15T09:13:40Z")

</div>

> [@DavidTurner](#):
>
> `GET /<index>/_stats` for the index in question?

```auto
{
  "_shards" : {
    "total" : 6,
    "successful" : 6,
    "failed" : 0
  },
  "_all" : {
    "primaries" : {
      "docs" : {
        "count" : 32112036,
        "deleted" : 0
      },
      "store" : {
        "size_in_bytes" : 32410447708
      },
      "indexing" : {
        "index_total" : 32112036,
        "index_time_in_millis" : 16358145,
        "index_current" : 0,
        "index_failed" : 0,
        "delete_total" : 0,
        "delete_time_in_millis" : 0,
        "delete_current" : 0,
        "noop_update_total" : 0,
        "is_throttled" : false,
        "throttle_time_in_millis" : 0
      },
      "get" : {
        "total" : 0,
        "time_in_millis" : 0,
        "exists_total" : 0,
        "exists_time_in_millis" : 0,
        "missing_total" : 0,
        "missing_time_in_millis" : 0,
        "current" : 0
      },
      "search" : {
        "open_contexts" : 0,
        "query_total" : 308,
        "query_time_in_millis" : 182324,
        "query_current" : 0,
        "fetch_total" : 3,
        "fetch_time_in_millis" : 425,
        "fetch_current" : 0,
        "scroll_total" : 0,
        "scroll_time_in_millis" : 0,
        "scroll_current" : 0,
        "suggest_total" : 0,
        "suggest_time_in_millis" : 0,
        "suggest_current" : 0
      },
      "merges" : {
        "current" : 0,
        "current_docs" : 0,
        "current_size_in_bytes" : 0,
        "total" : 4682,
        "total_time_in_millis" : 21228980,
        "total_docs" : 76385733,
        "total_size_in_bytes" : 98041573499,
        "total_stopped_time_in_millis" : 0,
        "total_throttled_time_in_millis" : 12440347,
        "total_auto_throttle_in_bytes" : 15728640
      },
      "refresh" : {
        "total" : 13865,
        "total_time_in_millis" : 1719787,
        "listeners" : 0
      },
      "flush" : {
        "total" : 140,
        "periodic" : 131,
        "total_time_in_millis" : 817375
      },
      "warmer" : {
        "current" : 0,
        "total" : 13671,
        "total_time_in_millis" : 296
      },
      "query_cache" : {
        "memory_size_in_bytes" : 3332620,
        "total_count" : 622,
        "hit_count" : 129,
        "miss_count" : 493,
        "cache_size" : 22,
        "cache_count" : 22,
        "evictions" : 0
      },
      "fielddata" : {
        "memory_size_in_bytes" : 67497800,
        "evictions" : 0
      },

```

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [July 15, 2019, 9:22am UTC](https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160/9 "2019-07-15T09:22:21Z")

</div>

The size of the primaries looks to be around 30GB, which is what we expect:

```
    "size_in_bytes" : 32410447708

```

The stats are truncated, but does this index have 1 replica? If so, I'm guessing the UI you're looking at is counting the sizes of the replicas too, but index rollover [does not do this](https://www.elastic.co/guide/en/elasticsearch/reference/7.2/indices-rollover-index.html):

> max\_size: The maximum estimated size of the **primary** shard of the index

---

<div class="post-metadata">

### Author: ![jamesp220291](https://avatars.discourse-cdn.com/v4/letter/j/91b2a8/32.png) [@jamesp220291](https://discuss.elastic.co/u/jamesp220291)
#### Post date: [July 15, 2019, 11:19am UTC](https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160/10 "2019-07-15T11:19:55Z")

</div>

Ah, Ok, so the dashboard is showing the size plus replicas.

Which would be 60GB.

Thank you.

While i've got you, can I ask a question re sharding?

I have 6 Data nodes, and all my indexs are set to 3 shards, would increasing this to 6, increase performance, as some of my queries time out.

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [July 15, 2019, 12:44pm UTC](https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160/11 "2019-07-15T12:44:20Z")

</div>

Your shards, at ~10GB each, are already a little smaller than recommended:

> **[How many shards should I have in my Elasticsearch cluster?](https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster)**
>
> If you are looking for practical guidelines around how many indices and shards to have in your cluster, this blog post will help you avoid common pitfalls.

That said, predicting the performance of different configurations is very hard. You can normally only answer questions like this with careful benchmarking.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 12, 2019, 12:44pm UTC](https://discuss.elastic.co/t/ilm-not-rolling-over-at-correct-size/190160/12 "2019-08-12T12:44:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
