# Index auto increment issue

**URL:** <https://discuss.elastic.co/t/index-auto-increment-issue/87040>\
**Category:** Logstash\
**Created:** [May 24, 2017, 8:25pm UTC](https://discuss.elastic.co/t/index-auto-increment-issue/87040 "2017-05-24T20:25:36Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![kamran.matloob](https://avatars.discourse-cdn.com/v4/letter/k/e47c2d/32.png) [@kamran.matloob](https://discuss.elastic.co/u/kamran.matloob)\
**Post date:** [May 24, 2017, 8:25pm UTC](https://discuss.elastic.co/t/index-auto-increment-issue/87040/1 "2017-05-24T20:25:37Z")

</div>

My requirement is to rollover indices after 7days. I successfully created dynamic index in my logstsh.conf file by using below link  
[https://www.elastic.co/guide/en/elasticsearch/reference/5.1/indices-aliases.html](https://www.elastic.co/guide/en/elasticsearch/reference/5.1/indices-aliases.html)  
Below Is my dynamic index name with my rollover template  
index =\> "coffii\_amq-000001"  
template =\> "/etc/logstash\_worker/templates/coffii\_rollover\_logs\_template.json"  
In my rollover template, I created aliase for my dynamic index with the following script  
"aliases" : {  
"amq-rollover-alias" : {}  
}

then I wrote curator rollover script by the help of below link  
[https://www.elastic.co/guide/en/elasticsearch/client/curator/5.0/ex\_rollover.html](https://www.elastic.co/guide/en/elasticsearch/client/curator/5.0/ex_rollover.html)  
Below is the curator rollover script  
actions:  
1:  
action: rollover  
description: \>-  
Rollover the index associated with index 'name', which should be in the  
form of prefix-000001 (or similar), or prefix-YYYY.MM.DD-1.  
options:  
disable\_action: False  
name: amq-rollover-alias  
conditions:  
max\_age: 7d  
max\_docs: 1000

Everything is working fine but when I run curator script, It successfully created a new index name coffii\_amq-000002 but in my logstash.conf file I hard coded name coffii\_amq-000001 that’s why after running curator script, System still creating documents in the old index (coffii\_amq-000001).Is there a way to define dynamic index in my logstash.conf file. Kindly advise.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 24, 2017, 10:46pm UTC](https://discuss.elastic.co/t/index-auto-increment-issue/87040/2 "2017-05-24T22:46:43Z")

</div>

Configure Logstash to point to the alias:

```auto
index => "amq-rollover-alias"

```

That's what you need to do.

---

<div class="post-metadata">

**Author:** ![kamran.matloob](https://avatars.discourse-cdn.com/v4/letter/k/e47c2d/32.png) [@kamran.matloob](https://discuss.elastic.co/u/kamran.matloob)\
**Post date:** [May 25, 2017, 4:22am UTC](https://discuss.elastic.co/t/index-auto-increment-issue/87040/3 "2017-05-25T04:22:15Z")

</div>

If we declare alias as index as you suggested then where we put our index name series (coffii\_amq-000001) or should i use both (index and alias) like below this.

index =\> "coffii\_amq-000001"  
index =\> "amq-rollover-alias"

Furthermore should i still retain our index template and in curator script should i use alias(amq-rollover-alias)or index name (coffii\_amq-000001).Kindly advise.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 25, 2017, 5:02am UTC](https://discuss.elastic.co/t/index-auto-increment-issue/87040/4 "2017-05-25T05:02:13Z")

</div>

You defined your index name pattern when you made the alias: `amq-rollover-alias` and assigned it to index `koffii_amq-000001`. You need to set your logstash index to the alias. When you do the rollover through Curator, if the conditions you set are matched, Elasticsearch will create index `koffii_amq-000002` and then point the alias at that index. This action will be nearly instantaneous. Indexing to the alias will continue without interruption, but the data will flow into the new index.

You do not define a dynamic index in Logstash. You set `index => amq-rollover-alias`

---

<div class="post-metadata">

**Author:** ![kamran.matloob](https://avatars.discourse-cdn.com/v4/letter/k/e47c2d/32.png) [@kamran.matloob](https://discuss.elastic.co/u/kamran.matloob)\
**Post date:** [May 26, 2017, 12:21am UTC](https://discuss.elastic.co/t/index-auto-increment-issue/87040/5 "2017-05-26T00:21:16Z")

</div>

I got it about working in logstash using index =\> amq-rollover-alias  
And also got your suggestion. But my confusion is that how we would define your below suggestion  
“You defined your index name pattern when you made the alias: amq-rollover-alias and assigned it to index koffii\_amq-000001. ”  
My first question is that above suggestion will incorporate into index template. The option I know is only defining alias as shown below  
"aliases" : {  
"amq-rollover-alias" : {}  
}  
but don’t know how to tell that this alias is attach in that particular index in the template. Can you please share some code example in template? Or share any link.Thanks.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 26, 2017, 2:19pm UTC](https://discuss.elastic.co/t/index-auto-increment-issue/87040/6 "2017-05-26T14:19:16Z")

</div>

This is a misunderstanding.

You seem to believe that you need to have the rollover alias in the index template. **You do not.**

Once you have created the incrementable index with the initial alias:

```auto
PUT /koffii_amq-000001 
{
  "aliases": {
    "amq-rollover-alias": {}
  }
}

```

...you don't need the alias in the index template. You should have created the index mapping template first, so that when you created that first index (`koffii_amq-000001`), the desired mapping was applied at creation time.

Once that incrementable index + alias are created, there is no need to keep re-associating each new index with the alias via the index template. The rollover API keeps pointing the new indices to the existing alias, and unassociating the old index. I repeat: the Rollover API does it all for you after the initial index + alias are created.

Your index template should match the pattern `koffii_amq-*`, so that all indices created thereafter will get the desired mapping. But you don't need to include any alias data in the mapping template _unless you're also mapping to_ another _alias in addition to the rollover alias._

---

<div class="post-metadata">

**Author:** ![kamran.matloob](https://avatars.discourse-cdn.com/v4/letter/k/e47c2d/32.png) [@kamran.matloob](https://discuss.elastic.co/u/kamran.matloob)\
**Post date:** [May 30, 2017, 3:29am UTC](https://discuss.elastic.co/t/index-auto-increment-issue/87040/7 "2017-05-30T03:29:05Z")

</div>

Thanks a lot Aaron. My issue resolved under your kind guidance.

---

<div class="post-metadata">

**Author:** ![zzayale](https://avatars.discourse-cdn.com/v4/letter/z/9e8a1a/32.png) [@zzayale](https://discuss.elastic.co/u/zzayale)\
**Post date:** [June 26, 2017, 8:39am UTC](https://discuss.elastic.co/t/index-auto-increment-issue/87040/8 "2017-06-26T08:39:30Z")

</div>

It work for me! The greatest thanks for this post! 3 days could not understand! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2017, 8:39am UTC](https://discuss.elastic.co/t/index-auto-increment-issue/87040/9 "2017-07-24T08:39:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
