# ILM setup: Logstash vs elasticsearch

**URL:** <https://discuss.elastic.co/t/ilm-setup-logstash-vs-elasticsearch/192471>\
**Category:** Logstash\
**Created:** [July 26, 2019, 3:27pm UTC](https://discuss.elastic.co/t/ilm-setup-logstash-vs-elasticsearch/192471 "2019-07-26T15:27:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![fefo69](https://avatars.discourse-cdn.com/v4/letter/f/b5a626/32.png) [@fefo69](https://discuss.elastic.co/u/fefo69)\
**Post date:** [July 26, 2019, 3:27pm UTC](https://discuss.elastic.co/t/ilm-setup-logstash-vs-elasticsearch/192471/1 "2019-07-26T15:27:22Z")

</div>

Dear all,

I'm trying to create indexes from logstash output plugin but policy assignment and rollover is not working.  
Elasticsearch and logstash version 7.2

This is my test setup:

### Logstash output plugin:

```
elasticsearch {
  hosts => ["<ip>:9200"]
  ilm_enabled => true
  ilm_rollover_alias => "test_roll_alias"
  ilm_pattern => "000001"
  ilm_policy => "test_policy"
}

```

### Policy:

"test\_policy": {  
"version": 4,  
"modified\_date": "2019-07-26T14:23:35.741Z",  
"policy": {  
"phases": {  
"hot": {  
"min\_age": "0ms",  
"actions": {  
"rollover": {  
"max\_size": "50mb"  
}  
}  
},  
"delete": {  
"min\_age": "30d",  
"actions": {  
"delete": {}  
}  
}  
}  
}  
}

### Template

"test\_template": {  
"order": 0,  
"index\_patterns": [  
"tef\_switch\*"  
],  
"settings": {  
"index": {  
"lifecycle": {  
"name": "test\_policy",  
"rollover\_alias": "test\_roll\_alias"  
},  
"number\_of\_shards": "1",  
"number\_of\_replicas": "1"  
}  
},  
"mappings": {},  
"aliases": {}  
}

When I start getting data, index is created by logstash, but not linked to the policy and not doing the rollover when exceed the 50mb.

Appreciate your help to understand the setup of logstash output vs template/policy definitions in elasticsearch cluster (7.2/basic license)

Thanks!

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [July 26, 2019, 3:33pm UTC](https://discuss.elastic.co/t/ilm-setup-logstash-vs-elasticsearch/192471/2 "2019-07-26T15:33:26Z")

</div>

Did you create a bootstrap index? See [https://www.elastic.co/blog/implementing-hot-warm-cold-in-elasticsearch-with-index-lifecycle-management](https://www.elastic.co/blog/implementing-hot-warm-cold-in-elasticsearch-with-index-lifecycle-management)

There isn't a link to that section, search for "bootstrap"

---

<div class="post-metadata">

**Author:** ![fefo69](https://avatars.discourse-cdn.com/v4/letter/f/b5a626/32.png) [@fefo69](https://discuss.elastic.co/u/fefo69)\
**Post date:** [July 26, 2019, 4:16pm UTC](https://discuss.elastic.co/t/ilm-setup-logstash-vs-elasticsearch/192471/3 "2019-07-26T16:16:16Z")

</div>

Hi

How can I handle bootsrap from logstash output plugin ?

Thanks !

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [July 26, 2019, 5:05pm UTC](https://discuss.elastic.co/t/ilm-setup-logstash-vs-elasticsearch/192471/4 "2019-07-26T17:05:57Z")

</div>

The doc always shows bootstrap via curl or the kibana dev tools console.

It reads like "filebeat setup --index-management" would also do it, but I've never had it work correctly, but I'm still 6.x.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2019, 5:05pm UTC](https://discuss.elastic.co/t/ilm-setup-logstash-vs-elasticsearch/192471/5 "2019-08-23T17:05:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
