# ILM policy is not working

**URL:** <https://discuss.elastic.co/t/ilm-policy-is-not-working/189393>\
**Category:** Elasticsearch\
**Created:** [July 8, 2019, 5:26pm UTC](https://discuss.elastic.co/t/ilm-policy-is-not-working/189393 "2019-07-08T17:26:50Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [July 8, 2019, 5:26pm UTC](https://discuss.elastic.co/t/ilm-policy-is-not-working/189393/1 "2019-07-08T17:26:50Z")

</div>

Hi

I am using ELK stack 7.2, I have an ILM policy set but looks like its not working. The maximum index size I set is 14GB.  
Note: I am running ES on a single vm.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/b/db6cdfc8add4faef6ef716331f4b3d7e5aba9a27.png)

I see the index size is 28gb but it does not rollover to a new index.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/1/8182b821462040a41057d8953208627500d31113.png)

---

<div class="post-metadata">

**Author:** ![gbrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbrown/32/34482_2.png) [@gbrown](https://discuss.elastic.co/u/gbrown)\
**Post date:** [July 9, 2019, 10:21pm UTC](https://discuss.elastic.co/t/ilm-policy-is-not-working/189393/2 "2019-07-09T22:21:20Z")

</div>

Can you run, via the console:

```auto
GET metricbeat-2019.06.25-000001/_ilm/explain

```

And post the output here? This will tell us what ILM thinks is going on with this index.

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [July 9, 2019, 11:20pm UTC](https://discuss.elastic.co/t/ilm-policy-is-not-working/189393/3 "2019-07-09T23:20:10Z")

</div>

```
{
  "indices" : {
    "metricbeat-2019.06.25-000001" : {
      "index" : "metricbeat-2019.06.25-000001",
      "managed" : true,
      "policy" : "metricbeat-7.2.0",
      "lifecycle_date_millis" : 1561497717119,
      "phase" : "hot",
      "phase_time_millis" : 1562707292481,
      "action" : "rollover",
      "action_time_millis" : 1562707378617,
      "step" : "ERROR",
      "step_time_millis" : 1562707978577,
      "failed_step" : "check-rollover-ready",
      "step_info" : {
        "type" : "illegal_argument_exception",
        "reason" : "index [metricbeat] is not the write index for alias [metricbeat-2019.06.25-000001]",
        "stack_trace" : """
java.lang.IllegalArgumentException: index [metricbeat] is not the write index for alias [metricbeat-2019.06.25-000001]
	at org.elasticsearch.xpack.core.indexlifecycle.WaitForRolloverReadyStep.evaluateCondition(WaitForRolloverReadyStep.java:100)
	at org.elasticsearch.xpack.indexlifecycle.IndexLifecycleRunner.runPeriodicStep(IndexLifecycleRunner.java:133)
	at org.elasticsearch.xpack.indexlifecycle.IndexLifecycleService.triggerPolicies(IndexLifecycleService.java:270)
	at org.elasticsearch.xpack.indexlifecycle.IndexLifecycleService.triggered(IndexLifecycleService.java:213)
	at org.elasticsearch.xpack.core.scheduler.SchedulerEngine.notifyListeners(SchedulerEngine.java:168)
	at org.elasticsearch.xpack.core.scheduler.SchedulerEngine$ActiveSchedule.run(SchedulerEngine.java:196)
	at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:511)
	at java.util.concurrent.FutureTask.run(FutureTask.java:266)
	at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.access$201(ScheduledThreadPoolExecutor.java:180)
	at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.run(ScheduledThreadPoolExecutor.java:293)
	at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
	at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
	at java.lang.Thread.run(Thread.java:748)

"""
      },
      "phase_execution" : {
        "policy" : "metricbeat-7.2.0",
        "phase_definition" : {
          "min_age" : "0ms",
          "actions" : {
            "rollover" : {
              "max_size" : "14gb",
              "max_age" : "5d"
            }
          }
        },
        "version" : 48,
        "modified_date_in_millis" : 1562704667671
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [July 9, 2019, 11:24pm UTC](https://discuss.elastic.co/t/ilm-policy-is-not-working/189393/4 "2019-07-09T23:24:19Z")

</div>

@gbrown

Currently I have these indicex.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ff8c6da00ce96005b5e6b0214aaaebdff7089e99.png)

metricbeat-2019.06.25-00001 was created after roll over.

What I have noticed is that the ILM policy is being over written after installing a new metricbeats agent on servers with every install.

metricbeat-2019.06.25-00001 -- This rollover index was created after removing the index from ILM policy and then adding it back.

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [July 10, 2019, 3:47pm UTC](https://discuss.elastic.co/t/ilm-policy-is-not-working/189393/5 "2019-07-10T15:47:21Z")

</div>

@gbrown

One more thing. When ever I install the beats systems it overwrites the ilm policy.

But when I look at the index it does not take that new policy. As you see in the image its showing the old ilm policy. For index to use the new policy I have to remove and add the ILM policy back to that index.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/2/52ccfc224f23f5e81a2ae4c8f3c5e3909fb518bc.png)

---

<div class="post-metadata">

**Author:** ![gbrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbrown/32/34482_2.png) [@gbrown](https://discuss.elastic.co/u/gbrown)\
**Post date:** [July 12, 2019, 10:15pm UTC](https://discuss.elastic.co/t/ilm-policy-is-not-working/189393/6 "2019-07-12T22:15:48Z")

</div>

That error message indicates (although there's a bug in the error message, the index name and the alias name should be swapped) that there isn't an alias `metricbeat` that points to the index `metricbeat-2019.06.25-000001`. If you've confirmed that the alias exists, and `metricbeat-2019.06.25-000001` has `is_write_index: true` for that alias, try using the [Retry policy API](https://www.elastic.co/guide/en/elasticsearch/reference/7.1/ilm-retry-policy.html).

> [@syedsfayaz](#):
>
> One more thing. When ever I install the beats systems it overwrites the ilm policy.

You may be better off asking about this in the Beats section of the forum, but it looks like you can prevent new Beats from doing this by setting `setup.ilm.overwrite` to `false` in the Beats configuration (see the [ILM settings](https://www.elastic.co/guide/en/beats/filebeat/current/ilm.html#setup-ilm-overwrite-option) section of the Beats documentation).

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [July 12, 2019, 10:17pm UTC](https://discuss.elastic.co/t/ilm-policy-is-not-working/189393/7 "2019-07-12T22:17:24Z")

</div>

I tried this option. `setup.ilm.overwrite` to `false`

But this does not work.

---

<div class="post-metadata">

**Author:** ![gbrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbrown/32/34482_2.png) [@gbrown](https://discuss.elastic.co/u/gbrown)\
**Post date:** [July 12, 2019, 10:18pm UTC](https://discuss.elastic.co/t/ilm-policy-is-not-working/189393/8 "2019-07-12T22:18:42Z")

</div>

Unfortunately I'm not a Beats expert so I can't really troubleshoot that very effectively - I recommend opening a new topic in [the Beats section](https://discuss.elastic.co/c/beats) of this forum.

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [July 12, 2019, 10:19pm UTC](https://discuss.elastic.co/t/ilm-policy-is-not-working/189393/9 "2019-07-12T22:19:17Z")

</div>

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2019, 10:19pm UTC](https://discuss.elastic.co/t/ilm-policy-is-not-working/189393/10 "2019-08-09T22:19:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
