# Implementing Rollover+ILM with Logstash and time based index name

**URL:** <https://discuss.elastic.co/t/implementing-rollover-ilm-with-logstash-and-time-based-index-name/247883>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [September 8, 2020, 11:45am UTC](https://discuss.elastic.co/t/implementing-rollover-ilm-with-logstash-and-time-based-index-name/247883 "2020-09-08T11:45:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![xenoid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xenoid/32/20672_2.png) [@xenoid](https://discuss.elastic.co/u/xenoid)\
**Post date:** [September 8, 2020, 11:45am UTC](https://discuss.elastic.co/t/implementing-rollover-ilm-with-logstash-and-time-based-index-name/247883/1 "2020-09-08T11:45:10Z")

</div>

Hi there,

I used to index logs with Logstash into time-based indices (logstash-YYYY.MM.DD). Time-based index names make administration easier on us.  
We already use lifecycle management to pull the indices to slower nodes and delete the indices after a certain amount of time. Now I want to take advantage of rollover to decrease index size.  
I looked in the Rollover documentation and also have a basic understanding, but could not quite grasp how to implement this in my case.

I have an index template set up for logstash-\*. Included is an ILM-policy.  
When trying to set up rollover in the ILM-policy in Kibana I get a prompt asking me for an "alias for rollover index". I suppose this is the alias that gets applied to the current write-to index?:  
 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/5/6/56221c469bd97a805c115c6974f5bd683b613519.png)  
I would now want to enter some sort of pattern like "_logstash-YYYY.MM.DD_" to state my time-based index pattern, because Logstash shall always write to "_logstash-[current-date]_" even if in the backend indices are named logstash-[current-date]-_ **00004** _.

Am I still on the right path?

BTW: This is how my Elasticsearch output in Logstash looks like:

```auto
 elasticsearch {
            id => "12341234"
            hosts => ["192.168.1.2:9200"]
    	    user => "my_admin_user"
            password => "his_password"
            ssl => "true"
            ssl_certificate_verification => "false"
            document_type => "_doc"
    	    template_name => "logstash"
    	    index => "logstash-%{+YYYY.MM.dd}"
 }

```

Component versions:

- Logstash: 6.8.8 (need to upgrade soon)
- Elasticsearch: 7.9.0
- Kibana: 7.9.0

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 9, 2020, 12:07am UTC](https://discuss.elastic.co/t/implementing-rollover-ilm-with-logstash-and-time-based-index-name/247883/2 "2020-09-09T00:07:02Z")

</div>

The idea with ILM is that you write to the alias rather than a specific index pattern, and then behind the scenes it does the rotation. This removes the traditional approach of having a date in the index name entirely.

In your case you may want to setup the index pattern to be `logstash-write`, or whatever you want.

---

<div class="post-metadata">

**Author:** ![xenoid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xenoid/32/20672_2.png) [@xenoid](https://discuss.elastic.co/u/xenoid)\
**Post date:** [September 9, 2020, 4:46am UTC](https://discuss.elastic.co/t/implementing-rollover-ilm-with-logstash-and-time-based-index-name/247883/3 "2020-09-09T04:46:50Z")

</div>

Hmm yeah, that would be the way to go then.  
But in my opinion this makes management of the cluster not so straight forward, or did I miss something?  
Here's an example:  
In our case we usually close older indices to save resources.  
Sometimes though we need to look at specific data again. With a day-based index name I know exactly which index to open.  
How would I know which events withing a specific date range are in which index?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 7, 2020, 4:46am UTC](https://discuss.elastic.co/t/implementing-rollover-ilm-with-logstash-and-time-based-index-name/247883/4 "2020-10-07T04:46:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
