# Index Lifecycle dilemma

**URL:** <https://discuss.elastic.co/t/index-lifecycle-dilemma/177598>\
**Category:** Elasticsearch\
**Created:** [April 19, 2019, 10:08am UTC](https://discuss.elastic.co/t/index-lifecycle-dilemma/177598 "2019-04-19T10:08:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mesmer](https://avatars.discourse-cdn.com/v4/letter/m/0ea827/32.png) [@Mesmer](https://discuss.elastic.co/u/Mesmer)\
**Post date:** [April 19, 2019, 10:08am UTC](https://discuss.elastic.co/t/index-lifecycle-dilemma/177598/1 "2019-04-19T10:08:56Z")

</div>

Hello,

Trying to get my head around how ILM works.  
I have logstash creating these daily indices: and want to implement a simple ILM.

```
output {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "deposit-%{+YYYY.MM.dd}"
  }

```

ILM is like this:

```
{
    "policy": {
        "phases": {
            "hot": {
                "min_age": "0ms",
                "actions": {
                    "rollover": {
                        "max_age": "2d",
                        "max_size": "5gb"
                    },
                    "set_priority": {
                        "priority": 100
                    }
                }
            },
            "delete": {
                "min_age": "1d",
                "actions": {
                    "delete": {}
                }
            }
        }
    }
}

```

Problem is i'm getting this error:

> illegal\_argument\_exception: index.lifecycle.rollover\_alias [delete\_deposit] does not point to index [deposit-2019.04.17]

This is the index template where the ILM applies:

```
  "deposit" : {
    "order" : 0,
    "index_patterns" : [
      "deposit*"
    ],
    "settings" : {
      "index" : {
        "lifecycle" : {
          "name" : "Delete",
          "rollover_alias" : "delete_deposit"
        },
        "number_of_shards" : "1"
      }
    },
    "mappings" : { },
    "aliases" : { }
  },

```

From what i understand an alias still needs to be created (delete\_deposit). But where does this need to point to?? Is it the deposit\* daily indices or towards the rollover index??

---

<div class="post-metadata">

**Author:** ![dakrone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dakrone/32/23351_2.png) [@dakrone](https://discuss.elastic.co/u/dakrone)\
**Post date:** [April 26, 2019, 2:03pm UTC](https://discuss.elastic.co/t/index-lifecycle-dilemma/177598/2 "2019-04-26T14:03:41Z")

</div>

> [@Mesmer](#):
>
> From what i understand an alias still needs to be created (delete\_deposit). But where does this need to point to?? Is it the deposit\* daily indices or towards the rollover index??

That's correct, usually the alias is created with the first alias, so someone does something like:

```auto
PUT /deposit-000001
{
  "aliases": {
    "delete_deposit":{
      "is_write_index": true
    }
  }
}

```

That would create the first "deposit" index and also create the "delete\_deposit" alias pointing to this index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2019, 2:03pm UTC](https://discuss.elastic.co/t/index-lifecycle-dilemma/177598/3 "2019-05-24T14:03:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
