# ILM parameters in config

**URL:** <https://discuss.elastic.co/t/ilm-parameters-in-config/212885>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 23, 2019, 7:00pm UTC](https://discuss.elastic.co/t/ilm-parameters-in-config/212885 "2019-12-23T19:00:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![torten](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/torten/32/50639_2.png) [@torten](https://discuss.elastic.co/u/torten)\
**Post date:** [December 23, 2019, 7:00pm UTC](https://discuss.elastic.co/t/ilm-parameters-in-config/212885/1 "2019-12-23T19:00:12Z")

</div>

Good day,

I want to set up ILM **rollover\_alias** and **policy\_name** parameters from the event fields, but no luck, all I got is errors like:

```
`ERROR instance/beat.go:878 Exiting: failed to read the ilm rollover alias: key not found`

```

Config example:

```
filebeat.inputs:
  - type: log
    enabled: true
    paths:
      - /var/log/app/*.log
    json.keys_under_root: true
    json.add_error_key: true
    scan_frequency: 1s
    fields:
      rollover_alias: "infra-application"
      policy_name: "2_shards_30_days"

output.elasticsearch:
  enabled: true
  hosts: ["http://host1:9200", "http://host2:9200"]

setup.ilm.enabled: true
setup.ilm.rollover_alias: "%{[fields.rollover_alias]}"
setup.ilm.pattern: "{now/d}-000001"
setup.ilm.policy_name: "%{[fields.policy_name]}"
```

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [December 23, 2019, 7:34pm UTC](https://discuss.elastic.co/t/ilm-parameters-in-config/212885/2 "2019-12-23T19:34:44Z")

</div>

Hi @torten,

Which version of Filebeat are you running?

Shaunak

---

<div class="post-metadata">

**Author:** ![torten](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/torten/32/50639_2.png) [@torten](https://discuss.elastic.co/u/torten)\
**Post date:** [December 23, 2019, 7:52pm UTC](https://discuss.elastic.co/t/ilm-parameters-in-config/212885/3 "2019-12-23T19:52:20Z")

</div>

Sorry for didn't mention it. 7.4.2 with basic licence and Elasticsearch with the same version.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [December 23, 2019, 10:54pm UTC](https://discuss.elastic.co/t/ilm-parameters-in-config/212885/4 "2019-12-23T22:54:19Z")

</div>

Thanks. Reading through the [code](https://github.com/elastic/beats/blob/7.4/libbeat/idxmgmt/ilm/ilm.go#L144-L164), it looks like only certain fields may be used in the `setup.ilm.rollover_alias` and `setup.ilm.policy_name` settings: `beat.name`, `beat.version`, `agent.name`, `agent.version`, `observer.name`, `observer.version`. Of these the first two — `beat.name` and `beat.version` are only available for backwards compatibility and must not be used; use `agent.name` and `agent.version` instead.

So any fields other than the "global" ones mentioned above are not available in the format string used in `setup.ilm.rollover_alias` and `setup.ilm.policy_name` settings.

In your configuration I see you have `fields.rollover_alias` and `fields.policy_name` which are defined under the input configuration. These fields will get added to each Beat event as it is created by the input. However, the ILM setup can happen when a user runs `filebeat setup` or `filebeat setup --index-management`. When one of these commands is run Filebeat does not read data from inputs, so the fields configured in the `filebeat.inputs` section don't come into play at all.

Shaunak

---

<div class="post-metadata">

**Author:** ![torten](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/torten/32/50639_2.png) [@torten](https://discuss.elastic.co/u/torten)\
**Post date:** [December 24, 2019, 12:03pm UTC](https://discuss.elastic.co/t/ilm-parameters-in-config/212885/5 "2019-12-24T12:03:06Z")

</div>

Thanks for the explanation! I believe in my case the best option will be to send event to Logstash and then process it accroding to logic patterns.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 21, 2020, 12:03pm UTC](https://discuss.elastic.co/t/ilm-parameters-in-config/212885/6 "2020-01-21T12:03:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
