# Index life cycle policy not deleting the index when reached the defined size

**URL:** <https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management, datastreams\
**Created:** [March 24, 2023, 3:29pm UTC](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475 "2023-03-24T15:29:14Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![breakandfix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/breakandfix/32/118890_2.png) [@breakandfix](https://discuss.elastic.co/u/breakandfix)\
**Post date:** [March 24, 2023, 3:29pm UTC](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475/1 "2023-03-24T15:29:14Z")

</div>

Hello

I have vector agent running on a k8s. it creates a data stream and indexes.

I created ILM with only hot and delete phase. It should keep the index in hot phase until it reaches the defined size [100MB] and then rollover and delete previous index right away.

below is how the ILM gets attached to the index.

I created component templates with ILM ---\> attached to template with data stream name pattern  
--\> vector creates data stream --\> it creates index and ILM is attached.

ILM:

```auto
{
  "vector_prod_ilm": {
    "version": 16,
    "modified_date": "2023-03-24T15:23:34.142Z",
    "policy": {
      "phases": {
        "hot": {
          "min_age": "0ms",
          "actions": {
            "rollover": {
              "max_size": "100mb"
            }
          }
        },
        "delete": {
          "min_age": "0d",
          "actions": {
            "delete": {
              "delete_searchable_snapshot": true
            }
          }
        }
      }
    },
    "in_use_by": {
      "indices": [
        ".ds-vector-kubernetes_logs-prod-2023.03.24-000001"
      ],
      "data_streams": [
        "vector-kubernetes_logs-prod"
      ],
      "composable_templates": [
        "vector_prod_datastream_template"
      ]
    }
  }
}

```

component\_templates:

```auto
{
  "component_templates": [
    {
      "name": "vector_prod_datastream_component_template",
      "component_template": {
        "template": {
          "settings": {
            "index": {
              "lifecycle": {
                "name": "vector_prod_ilm"
              }
            }
          },
          "aliases": {
            "my_alias": {}
          }
        }
      }
    }
  ]
}

```

template:

```auto
{
  "index_templates": [
    {
      "name": "vector_prod_datastream_template",
      "index_template": {
        "index_patterns": [
          "vector-kubernetes_logs-prod*"
        ],
        "composed_of": [
          "vector_prod_datastream_component_template"
        ],
        "priority": 200,
        "data_stream": {
          "hidden": false,
          "allow_custom_routing": false
        }
      }
    }
  ]
}

```

datastream created by victor:

```auto
{
  "data_streams": [
    {
      "name": "vector-kubernetes_logs-prod",
      "timestamp_field": {
        "name": "@timestamp"
      },
      "indices": [
        {
          "index_name": ".ds-vector-kubernetes_logs-prod-2023.03.24-000001",
          "index_uuid": "vK8qLxTkS9aNW81SAHY9aQ"
        }
      ],
      "generation": 1,
      "status": "GREEN",
      "template": "vector_prod_datastream_template",
      "ilm_policy": "vector_prod_ilm",
      "hidden": false,
      "system": false,
      "allow_custom_routing": false,
      "replicated": false
    }
  ]
}

```

index:

GET /.ds-vector-kubernetes\_logs-prod-2023.03.24-000001/\_ilm/explain?human

```auto
{
  "indices": {
    ".ds-vector-kubernetes_logs-prod-2023.03.24-000001": {
      "index": ".ds-vector-kubernetes_logs-prod-2023.03.24-000001",
      "managed": true,
      "policy": "vector_prod_ilm",
      "index_creation_date": "2023-03-24T15:23:56.036Z",
      "index_creation_date_millis": 1679671436036,
      "time_since_index_creation": "4.41m",
      "lifecycle_date": "2023-03-24T15:23:56.036Z",
      "lifecycle_date_millis": 1679671436036,
      "age": "4.41m",
      "phase": "hot",
      "phase_time": "2023-03-24T15:23:56.260Z",
      "phase_time_millis": 1679671436260,
      "action": "rollover",
      "action_time": "2023-03-24T15:23:56.460Z",
      "action_time_millis": 1679671436460,
      "step": "check-rollover-ready",
      "step_time": "2023-03-24T15:23:56.460Z",
      "step_time_millis": 1679671436460,
      "phase_execution": {
        "policy": "vector_prod_ilm",
        "phase_definition": {
          "min_age": "0ms",
          "actions": {
            "rollover": {
              "max_size": "100mb"
            }
          }
        },
        "version": 16,
        "modified_date": "2023-03-24T15:23:34.142Z",
        "modified_date_in_millis": 1679671414142
      }
    }
  }
}

```

index was not deleted:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/5/95781dd6eaa781441d5c481605df14b58e244076.png)

---

<div class="post-metadata">

**Author:** ![breakandfix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/breakandfix/32/118890_2.png) [@breakandfix](https://discuss.elastic.co/u/breakandfix)\
**Post date:** [March 24, 2023, 3:32pm UTC](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475/2 "2023-03-24T15:32:42Z")

</div>

What could be the issue. Can anyone take a look?

Thanks.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2023, 4:25pm UTC](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475/3 "2023-03-24T16:25:50Z")

</div>

The index has not yet rolled over as it has not reached the configured size of 100MB. Note that [the max\_size parameter only takes primary shard size into account](https://www.elastic.co/guide/en/elasticsearch/reference/8.6/ilm-rollover.html#ilm-rollover-options) and the index you showed has a primary and replica shard sized 184.49MB, which means the primary shard is a bit over 92MB in size.

---

<div class="post-metadata">

**Author:** ![breakandfix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/breakandfix/32/118890_2.png) [@breakandfix](https://discuss.elastic.co/u/breakandfix)\
**Post date:** [March 24, 2023, 5:22pm UTC](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475/4 "2023-03-24T17:22:18Z")

</div>

Hey Christian, thanks for your reply. I changed the ILM policy and kept it to 1GB max size,  
and it's weird that it rolled over when **Primary storage size** reached 1.6gb even though max size in ILM is set to 1GB and the index number also jumped from 9 to 12, not sure why.

ILM

```auto
{
  "vector_prod_ilm": {
    "version": 17,
    "modified_date": "2023-03-24T16:19:00.496Z",
    "policy": {
      "phases": {
        "hot": {
          "min_age": "0ms",
          "actions": {
            "rollover": {
              "max_size": "1gb"
            }
          }
        },
        "delete": {
          "min_age": "0d",
          "actions": {
            "delete": {
              "delete_searchable_snapshot": true
            }
          }
        }
      }
    },
    "in_use_by": {
      "indices": [
        ".ds-vector-kubernetes_logs-prod-2023.03.24-000012",
        ".ds-vector-kubernetes_logs-prod-2023.03.24-000009"
      ],
      "data_streams": [
        "vector-kubernetes_logs-prod"
      ],
      "composable_templates": [
        "vector_prod_datastream_template"
      ]
    }
  }
}

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5d32d886eeeebc3ecd4bf13343665a0af4966140.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/8/98b8f42fa529d739684ccc81325bf9125a10066e.png)

---

<div class="post-metadata">

**Author:** ![breakandfix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/breakandfix/32/118890_2.png) [@breakandfix](https://discuss.elastic.co/u/breakandfix)\
**Post date:** [March 24, 2023, 5:26pm UTC](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475/5 "2023-03-24T17:26:45Z")

</div>

Is it because it does document compression or something? because I checked in like 2 min later and now the size decreased to 1.26GB primary storage from 1.6GB in above image

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/4/449035a0d7464cb78b59c4ede9a1584aaf1e2891.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2023, 5:30pm UTC](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475/6 "2023-03-24T17:30:42Z")

</div>

The size of an index can fluctuate over time as merging takes place and new, merged segments are created before old ones are removed. I believe the size calculation averages out the size over time in order to not trigger consistently too early.

---

<div class="post-metadata">

**Author:** ![breakandfix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/breakandfix/32/118890_2.png) [@breakandfix](https://discuss.elastic.co/u/breakandfix)\
**Post date:** [March 24, 2023, 6:30pm UTC](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475/7 "2023-03-24T18:30:49Z")

</div>

I understand. Any specific reason for index ending number to not follow the order? 009 index should rollover to 010 and so on.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2023, 8:56pm UTC](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475/8 "2023-03-24T20:56:08Z")

</div>

That I do not know.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2023, 8:56pm UTC](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475/9 "2023-04-21T20:56:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
