# \[Index Lifecycle Management\] Dynamic rollover alias and template name

**URL:** <https://discuss.elastic.co/t/index-lifecycle-management-dynamic-rollover-alias-and-template-name/169614>\
**Category:** Logstash\
**Tags:** ilm-index-lifecycle-management\
**Created:** [February 22, 2019, 5:21pm UTC](https://discuss.elastic.co/t/index-lifecycle-management-dynamic-rollover-alias-and-template-name/169614 "2019-02-22T17:21:08Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cyril\_Berber](https://avatars.discourse-cdn.com/v4/letter/c/e19b73/32.png) [@Cyril\_Berber](https://discuss.elastic.co/u/Cyril_Berber)\
**Post date:** [February 22, 2019, 5:21pm UTC](https://discuss.elastic.co/t/index-lifecycle-management-dynamic-rollover-alias-and-template-name/169614/1 "2019-02-22T17:21:08Z")

</div>

Use Case:

- ELK pipeline with Filebeat \> Logstash \> Elasticsearch
- Many Filebeat instances read different logs files and Docker output
- Logstash processes messages to parse and route them in different indices
- Use ILM on the different indices according to the documentation [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ilm](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ilm)

Could it be possible to allow using variables in the properties " **ilm\_rollover\_alias**" as well as " **template\_name**" in the Elasticsearch output, like we can do with the "index" property?  
The configuration below raises an error on parsing the value of ilm\_rollover\_alias and template\_name:

output {  
if [@metadata][index] {  
elasticsearch {  
hosts =\> ["{ELASTICSEARCH\_HOST}:{ELASTICSEARCH\_PORT}"]  
ilm\_enabled =\> "true"  
ilm\_policy =\> "default-policy"  
ilm\_rollover\_alias =\> "%{[@metadata][index]}"  
template\_name =\> "%{[@metadata][index]}"  
}  
}  
}

While this is not working I use an IF statement for each different indices I need:

output {  
if [@metadata][index] == "nginx" {  
elasticsearch {  
hosts =\> ["{ELASTICSEARCH\_HOST}:{ELASTICSEARCH\_PORT}"]  
ilm\_enabled =\> "true"  
ilm\_policy =\> "default-policy"  
ilm\_rollover\_alias =\> "nginx"  
template\_name =\> "nginx"  
}  
}  
if [@metadata][index] == "app-logs" {  
elasticsearch {  
hosts =\> ["{ELASTICSEARCH\_HOST}:{ELASTICSEARCH\_PORT}"]  
ilm\_enabled =\> "true"  
ilm\_policy =\> "default-policy"  
ilm\_rollover\_alias =\> "app-logs"  
template\_name =\> "app-logs"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![jsvd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsvd/32/6203_2.png) [@jsvd](https://discuss.elastic.co/u/jsvd)\
**Post date:** [February 25, 2019, 8:07am UTC](https://discuss.elastic.co/t/index-lifecycle-management-dynamic-rollover-alias-and-template-name/169614/2 "2019-02-25T08:07:55Z")

</div>

Hi @Cyril_Berber

The template is used only at pipeline startup time, where the output plugin will install the template in `template_path` if `manage_template` is set to true (default).  
So in this context it's not possible to accept a template name per event, as these management tasks should be either before indexing data.

In the case of ilm\_rollover\_alias the problem is similar: the `ilm_*` options are used to install an ILM policy at plugin startup time so it does not make sense here to accept values from events to configure the policy.

If you're managing ILM policies outside of logstash (see the documentation [here](https://www.elastic.co/guide/en/elasticsearch/reference/6.6/index-lifecycle-management.html)) then you just can set `ilm_enabled => false` and just use the normal `index` option which supports fetching the value per event.

---

<div class="post-metadata">

**Author:** ![juusom](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juusom/32/42405_2.png) [@juusom](https://discuss.elastic.co/u/juusom)\
**Post date:** [March 20, 2019, 5:20pm UTC](https://discuss.elastic.co/t/index-lifecycle-management-dynamic-rollover-alias-and-template-name/169614/3 "2019-03-20T17:20:37Z")

</div>

If ILM policies are managed outside of logstash, does the first index need to be created explicitly?

In our setup, we have different indices for, for example, Kubernetes namespaces: `logstash-kube_<ns>-<date>`. Different indices have different lifecycles, currently implemented using curator. Many of them also have their own ES index templates.

So if we were to move to ILM, and change to a `logstash-kube_<ns>-<sequence>` type index naming, would we need to always make sure that the `logstash-kube_<ns>-00001` index is created beforehand and aliased as `logstash-kube_<ns>`, and then have logstash write to the alias?

Currently, adding new namespaces requires no manual actions in Logstash/ES and I'd really like to keep it that way. It would be great if Logstash could be configured not to manage the ILM policy itself, but still create the alias automatically for new indices.

---

<div class="post-metadata">

**Author:** ![OrangeDog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orangedog/32/4630_2.png) [@OrangeDog](https://discuss.elastic.co/u/OrangeDog)\
**Post date:** [March 27, 2019, 4:47pm UTC](https://discuss.elastic.co/t/index-lifecycle-management-dynamic-rollover-alias-and-template-name/169614/4 "2019-03-27T16:47:59Z")

</div>

But the rollover alias is not set on the policy, it's set on the index (same as `ilm_policy`).

I've got custom policies and custom templates (not in a 1-1 relationship), and really just want to switch from `index => '%{type}-%{+YYYY.MM.dd}'` to `ilm_rollover_alias => '%{type}'`

> If you're managing ILM policies outside of logstash then you just can set `ilm_enabled => false`

That's not what the documentation says - it says to use `ilm_policy`.

---

<div class="post-metadata">

**Author:** ![OrangeDog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orangedog/32/4630_2.png) [@OrangeDog](https://discuss.elastic.co/u/OrangeDog)\
**Post date:** [March 27, 2019, 4:56pm UTC](https://discuss.elastic.co/t/index-lifecycle-management-dynamic-rollover-alias-and-template-name/169614/5 "2019-03-27T16:56:48Z")

</div>

The `ilm_policy` should probably also be dynamic, and set directly on the index (especially if `manage_template => false`).

---

<div class="post-metadata">

**Author:** ![OrangeDog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orangedog/32/4630_2.png) [@OrangeDog](https://discuss.elastic.co/u/OrangeDog)\
**Post date:** [March 27, 2019, 5:04pm UTC](https://discuss.elastic.co/t/index-lifecycle-management-dynamic-rollover-alias-and-template-name/169614/6 "2019-03-27T17:04:09Z")

</div>

> It would be great if Logstash could be configured not to manage the ILM policy itself

The documentation says that's what `ilm_policy` is for:

> Modify this setting to use a custom Index Lifecycle Management policy, rather than the default. If this value is not set, the default policy will be automatically installed into Elasticsearch

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [March 27, 2019, 5:52pm UTC](https://discuss.elastic.co/t/index-lifecycle-management-dynamic-rollover-alias-and-template-name/169614/7 "2019-03-27T17:52:10Z")

</div>

This cannot be done dynamically, as the initial index and alias are set at Logstash init time, if they haven't been set yet.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2019, 5:52pm UTC](https://discuss.elastic.co/t/index-lifecycle-management-dynamic-rollover-alias-and-template-name/169614/8 "2019-04-24T17:52:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![ppf2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppf2/32/52219_2.png) [@ppf2](https://discuss.elastic.co/u/ppf2)\
**Post date:** [August 13, 2019, 7:28pm UTC](https://discuss.elastic.co/t/index-lifecycle-management-dynamic-rollover-alias-and-template-name/169614/9 "2019-08-13T19:28:17Z")

</div>

This is becoming a common ask in the field.  
For those interested in an enhancement request to make this type of setup easier, please +1 to the issue [here](https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/858).
