# ILM policy not attached when index is deleted while Logstash is running

**URL:** <https://discuss.elastic.co/t/ilm-policy-not-attached-when-index-is-deleted-while-logstash-is-running/187185>\
**Category:** Logstash\
**Created:** [June 24, 2019, 6:52pm UTC](https://discuss.elastic.co/t/ilm-policy-not-attached-when-index-is-deleted-while-logstash-is-running/187185 "2019-06-24T18:52:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dennis.rietvink](https://avatars.discourse-cdn.com/v4/letter/d/278dde/32.png) [@dennis.rietvink](https://discuss.elastic.co/u/dennis.rietvink)\
**Post date:** [June 24, 2019, 6:52pm UTC](https://discuss.elastic.co/t/ilm-policy-not-attached-when-index-is-deleted-while-logstash-is-running/187185/1 "2019-06-24T18:52:54Z")

</div>

Hi,

I use logstash to handle ILM configuration on my indexes. This works well on startup of Logstash when no index exists. An index is created using the rollover\_alias with the default ilm pattern and the policy gets attached, all as expected.

However, when I delete the index in es while Logstash is running it creates a new index using the rollover\_alias without default ilm pattern and no ilm policy is attached.

Am I missing something?

I run es and logstash version 7.1.1

```auto
        elasticsearch {
            id => write_to_es
            hosts => "${ELASTICSEARCH_URL:http://elasticsearch:9200}"
            template => "/usr/share/logstash/config/templates/flowlog.template.json"
            template_name => "${NAMESPACE:namespace_not_set}-flowlog-v1"
            template_overwrite => "true"
            user => "${ELASTIC_USER:elastic}"
            password => "${ELASTIC_PASSWORD:secret}"
	    ilm_enabled => "${ILM_ENABLED:true}"
	    ilm_policy => "${NAMESPACE:namespace_not_set}-flowlog"
            ilm_rollover_alias => "${NAMESPACE:namespace_not_set}-flowlog-v1"
        }

```

before index is deleted in ES:

```auto

GET /test4-flowlog-v1*/_settings

{
  "test4-flowlog-v1-2019.06.24-000001" : {
    "settings" : {
      "index" : {
        "lifecycle" : {
          "name" : "test4-flowlog",
          "rollover_alias" : "test4-flowlog-v1"
        },
        "codec" : "best_compression",
        "mapping" : {
          "total_fields" : {
            "limit" : "5000"
          }
        },
        "refresh_interval" : "10s",
        "number_of_shards" : "2",
        "provided_name" : "<test4-flowlog-v1-{now/d}-000001>",
        "creation_date" : "1561403226974",
        "number_of_replicas" : "1",
        "uuid" : "WNhPkp2ZR7i5o8c7I8PhWw",
        "version" : {
          "created" : "7010199"
        }
      }
    }
  }
}

```

After index is deleted in ES:

```auto

GET /test4-flowlog-v1*/_settings

{
  "test4-flowlog-v1" : {
    "settings" : {
      "index" : {
        "creation_date" : "1561401486129",
        "number_of_shards" : "1",
        "number_of_replicas" : "1",
        "uuid" : "oeREy6r9TcW658ozfyTI_A",
        "version" : {
          "created" : "7010199"
        },
        "provided_name" : "test4-flowlog-v1"
      }
    }
  }
}

```

Update: I noticed that this behaviour was the result of the auto index creation being enabled in es. When I disabled auto index creation and repeated the above steps I noticed in the Logstash log that all events were failing because the index was not found. What I would like logstash to do in such and event is to re-create the index with the template and ilm settings or, second best, reload the pipeline that will force the index to be re-created. Is this possible?

Thanks,  
Dennis

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 22, 2019, 6:52pm UTC](https://discuss.elastic.co/t/ilm-policy-not-attached-when-index-is-deleted-while-logstash-is-running/187185/2 "2019-07-22T18:52:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
