# Index can not assign to a default ilm policy

**URL:** <https://discuss.elastic.co/t/index-can-not-assign-to-a-default-ilm-policy/295607>\
**Category:** Logstash\
**Tags:** ilm-index-lifecycle-management\
**Created:** [January 27, 2022, 4:32pm UTC](https://discuss.elastic.co/t/index-can-not-assign-to-a-default-ilm-policy/295607 "2022-01-27T16:32:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![baalchina](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/baalchina/32/100690_2.png) [@baalchina](https://discuss.elastic.co/u/baalchina)\
**Post date:** [January 27, 2022, 4:32pm UTC](https://discuss.elastic.co/t/index-can-not-assign-to-a-default-ilm-policy/295607/1 "2022-01-27T16:32:24Z")

</div>

Hi, I am using logstash to collect my switch's syslog. Here is the logstash config like:

```auto
input{
    syslog{
        type => "syslog-sw-hw-128"
        host => "1.2.3.4"
        port => 580
    }
}

output{
    if [type] == "syslog-sw-hw-128" {
       elasticsearch {
        hosts => ["1.2.3.5:9200"]
            user => "elastic"
            password => "changeme"
            index => "syslog-sw-hw-128-%{+YYYYMMdd}"
            ilm_policy => "180-days-default"
        }
    }
}

```

Ant the question is:

1, the index created successfully, and have data.  
2, but in kibana, ilm, the 180-days-default policy had no assigined index.

btw, kibana/logstash/es all 7.16, and when list plugin list in logstash, the logstash-output-elastisearch plugin is successfule list.

Thanks a lot.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 27, 2022, 6:27pm UTC](https://discuss.elastic.co/t/index-can-not-assign-to-a-default-ilm-policy/295607/2 "2022-01-27T18:27:29Z")

</div>

> [@baalchina](#):
>
> `index => "syslog-sw-hw-128-%{+YYYYMMdd}"`

If that index is created then ILM is not in use. The output checks if ILM is [in use](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/882c9dda75819c8411f3b4291a22146179aa20c2/lib/logstash/outputs/elasticsearch.rb#L319), if it were then it would override the value of the index option and [log a warning](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/882c9dda75819c8411f3b4291a22146179aa20c2/lib/logstash/outputs/elasticsearch/ilm.rb#L7) that it was doing so.

The code that decides if ILM is in use is [here](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/882c9dda75819c8411f3b4291a22146179aa20c2/lib/logstash/outputs/elasticsearch/ilm.rb#L13).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2022, 6:27pm UTC](https://discuss.elastic.co/t/index-can-not-assign-to-a-default-ilm-policy/295607/3 "2022-02-24T18:27:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
