# ILM Policy - Help!\>!\>!\>

**URL:** <https://discuss.elastic.co/t/ilm-policy-help/250217>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [September 28, 2020, 3:15pm UTC](https://discuss.elastic.co/t/ilm-policy-help/250217 "2020-09-28T15:15:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gary\_Wilson1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gary_wilson1/32/47827_2.png) [@Gary\_Wilson1](https://discuss.elastic.co/u/Gary_Wilson1)\
**Post date:** [September 28, 2020, 3:15pm UTC](https://discuss.elastic.co/t/ilm-policy-help/250217/1 "2020-09-28T15:15:42Z")

</div>

Hello,

I have set up an index called `filebeat-7-7-1*`, which creates a daily index for my filebeat logs. So far so good - elastic creates a new index daily, which fills up with logs and all the other good stuff I need.

However, I soon run out of storage space as my ILM policy doesn't rollover after the hot phase, nor does it delete the indices after the designated time. The below error message appears on each and every index:

`"setting [index.lifecycle.rollover_alias] for index [filebeat-7.7.1-2020.09.22] is empty or not defined",`

I have the following ilm policy (nothing too complex):

```
    PUT _ilm/policy/filebeat-7.7
{
  "policy": {
    "phases": {
      "hot": {
        "min_age": "0ms",
        "actions": {
          "rollover": {
            "max_age": "3d",
            "max_size": "10gb"
          },
          "set_priority": {
            "priority": 100
          }
        }
      },
      "delete": {
        "min_age": "5d",
        "actions": {
          "delete": {}
        }
      }
    }
  }
}

```

I have the following in my index template.

```
{
  "index": {
"lifecycle": {
  "name": "filebeat-7.7",
  "rollover_alias": "filebeat-7.7.1-0000N"
}
  }
}

```

Any help would be most appreciated as to where I'm going wrong.

Thanks,

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 29, 2020, 2:57am UTC](https://discuss.elastic.co/t/ilm-policy-help/250217/2 "2020-09-29T02:57:11Z")

</div>

Try;

```auto
PUT /filebeat-7.7.1-2020.09.22/_alias/filebeat-7.7

```

Then change;

> [@Gary\_Wilson1](#):
>
> ```auto
> "rollover_alias": "filebeat-7.7.1-0000N"
> 
> ```

With;

```auto
"rollover_alias": "filebeat-7.7.1"

```

You don't want to use `filebeat-7.7.1-0000N` as the alias, because ILM adds the `-0000N` part automatically when it rolls over.

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [September 29, 2020, 8:10am UTC](https://discuss.elastic.co/t/ilm-policy-help/250217/3 "2020-09-29T08:10:50Z")

</div>

Hi Mark,

> [@warkolm](#):
>
> Try;
> 
> ```auto
> PUT /filebeat-7.7.1-2020.09.22/_alias/filebeat-7.7
> 
> ```

Is this command correct?  
shouldn't it be :  
`PUT /filebeat-7.7.1-2020.09.22/_alias/filebeat-7.7.1` ?  
because I think your solution is to add rollover\_alias to index aliases, am I correct?

---

<div class="post-metadata">

**Author:** ![Gary\_Wilson1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gary_wilson1/32/47827_2.png) [@Gary\_Wilson1](https://discuss.elastic.co/u/Gary_Wilson1)\
**Post date:** [September 29, 2020, 9:34am UTC](https://discuss.elastic.co/t/ilm-policy-help/250217/4 "2020-09-29T09:34:19Z")

</div>

Thanks guys - assuming one of those variants works for the index created on the 22nd Sept, how does that then work for each index created on a daily basis? Presumably I don't need to go through and manually set the alias on each index?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 27, 2020, 9:34am UTC](https://discuss.elastic.co/t/ilm-policy-help/250217/5 "2020-10-27T09:34:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
