# Index ILM+logstash

**URL:** <https://discuss.elastic.co/t/index-ilm-logstash/370823>\
**Category:** Elastic Search\
**Created:** [November 20, 2024, 9:07am UTC](https://discuss.elastic.co/t/index-ilm-logstash/370823 "2024-11-20T09:07:24Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marek\_Galbavy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marek_galbavy/32/132943_2.png) [@Marek\_Galbavy](https://discuss.elastic.co/u/Marek_Galbavy)\
**Post date:** [November 20, 2024, 9:07am UTC](https://discuss.elastic.co/t/index-ilm-logstash/370823/1 "2024-11-20T09:07:24Z")

</div>

Hi i try use logstash for my data with ILM policy.  
Index rollover and create new index with template and so on. But the name of the index just increase a number but not wroks with date. Date is still the same.

Here is a part of logstash output for this index

```auto
manage_template => false
ilm_rollover_alias => huawei_sw
ilm_pattern => "{now/d}-000001"
ilm_policy => Huawei_SW_ILM_policy

```

Can u help where is the problem?

---

<div class="post-metadata">

**Author:** ![ashishtiwari1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashishtiwari1993/32/135241_2.png) [@ashishtiwari1993](https://discuss.elastic.co/u/ashishtiwari1993)\
**Post date:** [November 20, 2024, 10:00am UTC](https://discuss.elastic.co/t/index-ilm-logstash/370823/2 "2024-11-20T10:00:11Z")

</div>

1. Hows your policy looks like? If you can share?
2. Is your first index is create with date prefix?

---

<div class="post-metadata">

**Author:** ![Marek\_Galbavy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marek_galbavy/32/132943_2.png) [@Marek\_Galbavy](https://discuss.elastic.co/u/Marek_Galbavy)\
**Post date:** [November 20, 2024, 12:31pm UTC](https://discuss.elastic.co/t/index-ilm-logstash/370823/3 "2024-11-20T12:31:29Z")

</div>

hi,

ILM policy:

```auto
    "version": 9,
    "modified_date": "2024-11-19T07:19:44.783Z",
    "policy": {
      "phases": {
        "cold": {
          "min_age": "5h",
          "actions": {
            "allocate": {
              "include": {
                "_tier_preference": "data_cold"
              },
              "exclude": {},
              "require": {}
            },
            "set_priority": {
              "priority": 0
            }
          }
        },
        "delete": {
          "min_age": "365d",
          "actions": {
            "delete": {
              "delete_searchable_snapshot": true
            }
          }
        },
        "hot": {
          "min_age": "0ms",
          "actions": {
            "rollover": {
              "max_age": "5h",
              "max_docs": 1000,
              "max_size": "5gb"
            },
            "set_priority": {
              "priority": 100
            }
          }
        }
      }
    },

```

and yes i first create ILM policy template a then first index

```auto
PUT huawei_sw-2024.11.19-000001
{
  "aliases": {
    "huawei_sw": {
      "is_write_index": true
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [November 20, 2024, 3:37pm UTC](https://discuss.elastic.co/t/index-ilm-logstash/370823/4 "2024-11-20T15:37:47Z")

</div>

You have to use the "date math" when you create the first index, see [API conventions | Elasticsearch Guide [8.16] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/api-conventions.html#api-date-math-index-names).

You could use data streams, they are easier.

---

<div class="post-metadata">

**Author:** ![Marek\_Galbavy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marek_galbavy/32/132943_2.png) [@Marek\_Galbavy](https://discuss.elastic.co/u/Marek_Galbavy)\
**Post date:** [November 21, 2024, 7:36am UTC](https://discuss.elastic.co/t/index-ilm-logstash/370823/5 "2024-11-21T07:36:11Z")

</div>

so this shoul be work yes?

```auto
PUT /%3Chuawi_sw-index-%7Bnow%2Fd%7D%3E
{
  "aliases": {
    "huawei_sw": {
      "is_write_index": true
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [November 21, 2024, 3:26pm UTC](https://discuss.elastic.co/t/index-ilm-logstash/370823/6 "2024-11-21T15:26:13Z")

</div>

Looks better, but I'm not going to desk check it here 🙂

Create the index, look at it in stack management (or GET), the setting provided\_name needs to contain "-{now/d}-". If you look at your first one, it has the literal date.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 19, 2024, 3:26pm UTC](https://discuss.elastic.co/t/index-ilm-logstash/370823/7 "2024-12-19T15:26:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
