# Index Frequency & Rollover

**URL:** <https://discuss.elastic.co/t/index-frequency-rollover/296598>\
**Category:** Kibana\
**Created:** [February 8, 2022, 1:17pm UTC](https://discuss.elastic.co/t/index-frequency-rollover/296598 "2022-02-08T13:17:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tim\_Mobley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tim_mobley/32/94741_2.png) [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Post date:** [February 8, 2022, 1:17pm UTC](https://discuss.elastic.co/t/index-frequency-rollover/296598/1 "2022-02-08T13:17:33Z")

</div>

If you have an ILM policy set to the default rollover settings (30 days or 50 GB), how should you configure your indexing in the LogStash output to align with that? Here's what I mean... if you have the following output block:

```auto
output {
  elasticsearch {
    hosts => ["https://hotdata1:9200", "https://hotdata2:9200"]
    index => "data-source-%{YYYY.MM.dd}"
  }
}

```

That creates a new index each day. But if the index isn't yet 50 GB we don't want that. Should I make the index setting this:

```auto
index => "data-source-%{YYYY.MM}"

```

...or just leave off the date altogether?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2022, 1:17pm UTC](https://discuss.elastic.co/t/index-frequency-rollover/296598/2 "2022-03-08T13:17:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
