# Ilm question/troubleshooting

**URL:** <https://discuss.elastic.co/t/ilm-question-troubleshooting/333676>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [May 17, 2023, 3:36pm UTC](https://discuss.elastic.co/t/ilm-question-troubleshooting/333676 "2023-05-17T15:36:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mark\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_s/32/98686_2.png) [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Post date:** [May 17, 2023, 3:36pm UTC](https://discuss.elastic.co/t/ilm-question-troubleshooting/333676/1 "2023-05-17T15:36:50Z")

</div>

My ilm policy does not work, although I have created a similar one a couple of weeks before in another cluster and it is working just fine..

Here is what I did:

1. I pointed Logstash towards ind\_alias
2. Created index template that will be used for creating the indices (see bellow)
3. Bootstrap index with a PUT command (see bellow), but i get an "invalid alias name" error (already exists). It exists because Logstash sends data and so the index is created (so of course it exists! I am wondering how this worked before...)

A desparate next step would be stopping all Logstash (there are many VMs sending so If possible i would prefer to avoid this). And starting from the beginning... But I would like to understand what am i doing wrong

Here are the details  
Template:

```auto
{
  "template": {
    "settings": {
      "index": {
        "lifecycle": {
          "name": "Mypolicy",
          "rollover_alias": "ind_alias"
        },
        "number_of_replicas": "1"
      }
    },
    "mappings": {
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "@version": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "field3": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        }
      }
    },
    "aliases": {
      "ind-search-all": {}
    }
  }
}

```

ilm:

```auto
{
  "Mypolicy" : {
    "version" : 1,
    "modified_date" : "2023-04-26T10:02:14.694Z",
    "policy" : {
      "phases" : {
        "hot" : {
          "min_age" : "0ms",
          "actions" : {
            "rollover" : {
              "max_primary_shard_size" : "1gb",
              "max_age" : "1d"
            },
            "set_priority" : {
              "priority" : 100
            }
          }
        },
        "delete" : {
          "min_age" : "30d",
          "actions" : {
            "delete" : {
              "delete_searchable_snapshot" : true
            }
          }
        }
      }
    },
    "in_use_by" : {
      "indices" : [
        "ind_alias"
      ],
      "data_streams" : [],
      "composable_templates" : [
        "ind_template"
      ]
    }
  }
}

```

Bootstrap command:

```auto
PUT ind_alias-000000
{
  "aliases": {
    "ind_alias": {
      "is_write_index": true
    }
  }
}

```

This bootstrap command gives the error

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "invalid_alias_name_exception",
        "reason" : "Invalid alias name [ind_alias]: an index or data stream exists with the same name 

```

---

<div class="post-metadata">

**Author:** ![eMitch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emitch/32/93607_2.png) [@eMitch](https://discuss.elastic.co/u/eMitch)\
**Post date:** [May 17, 2023, 5:02pm UTC](https://discuss.elastic.co/t/ilm-question-troubleshooting/333676/2 "2023-05-17T17:02:27Z")

</div>

If the index already exists and there is data in the `ind_alias` index - are you concerned about the data?

If you want to keep the data, then it may be best to err on the side of caution and stop Logstash in order to reindex your data into a new index. Then remove the old index and replace it with your bootstrapped index.

If you're not concerned with the data and are ok with the data loss, then you can use the [Alias API](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-aliases.html) to drop the index and add the new index with corresponding alias in an atomic way:

```auto
POST _aliases
{
  "actions": [
    {
      "add": {
        "index": "ind_alias-000000",
        "alias": "ind-alias",
        "is_write_index": true
      }
    },
    {
      "remove_index": {
        "index": "ind_alias"
      }
    }
  ]
}

```

Another option, if you don't want to stop the Logstash instances, is to mark the current `ind_alias` index as read-only. Logstash will no longer be able to send to it and will continue with retries. This is entirely dependent on many factors - including your own SLAs, how Logstash is configured, how much data is being ingested, how large the index is, etc.

---

<div class="post-metadata">

**Author:** ![Mark\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_s/32/98686_2.png) [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Post date:** [May 19, 2023, 8:25am UTC](https://discuss.elastic.co/t/ilm-question-troubleshooting/333676/3 "2023-05-19T08:25:20Z")

</div>

@eMitch : Thanks for the answer! I dropped the index and added a new one &the alias. I was not familiar with the way POST \_aliases {"actions" work: It must be executing first the remove and then the add, without letting any logstash input interfere during these actions (because it worked perfectly without having to stop logstash)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2023, 8:25am UTC](https://discuss.elastic.co/t/ilm-question-troubleshooting/333676/4 "2023-06-16T08:25:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
