Currently have a set up on linux host, using 6.7.1 in the stack - elasticsearch, logstash, kibana, filebeat, metricbeat, etc.
I'm trying to set this up for the data we currently have, and to management indexes yet to be created
So the documentation mostly shows creating the ILM config through the API, but I'm wondering if there is documentation around strictly setting this up through the configuration files, eg. elasticsearch.yml, filebeat.yml,etc.
Has anyone set it up like this? I'd rather not just create policies through kibana UI as I'd like to set up difference environments, and config files for ILM would make it easier.
Would a policy be created under the elasticsearch directory?
then index templates, for example, under filebeat, and then reference the template under output.elasticsearch in some way? I'm under the assumption an alias would be needed for ILM, so this would need to be done under an index template, as all our filebeat indexes are created based on the date