# "index.lifecycle.rollover\_alias does not point to index

**URL:** <https://discuss.elastic.co/t/index-lifecycle-rollover-alias-does-not-point-to-index/192525>\
**Category:** Logstash\
**Created:** [July 27, 2019, 2:26pm UTC](https://discuss.elastic.co/t/index-lifecycle-rollover-alias-does-not-point-to-index/192525 "2019-07-27T14:26:59Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mhsh64](https://avatars.discourse-cdn.com/v4/letter/m/d6d6ee/32.png) [@mhsh64](https://discuss.elastic.co/u/mhsh64)\
**Post date:** [July 27, 2019, 2:26pm UTC](https://discuss.elastic.co/t/index-lifecycle-rollover-alias-does-not-point-to-index/192525/1 "2019-07-27T14:26:59Z")

</div>

Please help:

logstash output:

I have a index template for logstash, which i defined in logstash output:

```
output {
    elasticsearch {
        hosts => ["https://elasticsearchurl.domain.com:9200"]
        user => 'logstash_internal'
        password => "${es_pwd}"
        ssl => true
        cacert => '/path/to/ca-bundle.trust.crt'
        sniffing => false
        index => "log-%{+yyyy.MM.dd}"
    }
}

```

I have a policy which is:

```
PUT _ilm/policy/log_policy   
{
  "policy": {                       
    "phases": {
      "hot": {                      
        "actions": {
          "rollover": {             
            "max_docs": 20,
            "max_age": "1h"
          }
        }
      },
      "delete": {
        "min_age": "1h",           
        "actions": {
          "delete": {}              
        }
      }
    }
  }
}

```

and an index template, which is assigned to policy and has a pattern to get logstash data, and rollover\_alias is log

```
PUT _template/log_template
{
  "index_patterns": ["log-*"],
  "settings": {
    "number_of_shards": 1,
    "number_of_replicas": 1,
    "index.lifecycle.name": "log_policy",
    "index.lifecycle.rollover_alias": "log"
  }
}

```

As per document, I created the bellow index manually

```
PUT log-000001
{
  "aliases": {
    "log": {
      "is_write_index": true
    }
  }
}

```

But I get the following error, during roll over action:

`"index.lifecycle.rollover_alias [log] does not point to index [log-2019.07.27]",`

Please can you help?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 27, 2019, 2:59pm UTC](https://discuss.elastic.co/t/index-lifecycle-rollover-alias-does-not-point-to-index/192525/2 "2019-07-27T14:59:10Z")

</div>

I believe you should be writing to the alias. So if you have an alias 'log' then your elasticsearch output should have

```
index => "log"
```

---

<div class="post-metadata">

**Author:** ![mhsh64](https://avatars.discourse-cdn.com/v4/letter/m/d6d6ee/32.png) [@mhsh64](https://discuss.elastic.co/u/mhsh64)\
**Post date:** [July 27, 2019, 4:40pm UTC](https://discuss.elastic.co/t/index-lifecycle-rollover-alias-does-not-point-to-index/192525/3 "2019-07-27T16:40:16Z")

</div>

but if I change the index to "log", how can I have my template in Elasticsearch? and how can I have indices with the following pattern?  
log-%{+yyyy.MM.dd}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 27, 2019, 4:46pm UTC](https://discuss.elastic.co/t/index-lifecycle-rollover-alias-does-not-point-to-index/192525/4 "2019-07-27T16:46:27Z")

</div>

If you want to have one index each day, what are hoping ILM will do for you?

---

<div class="post-metadata">

**Author:** ![mhsh64](https://avatars.discourse-cdn.com/v4/letter/m/d6d6ee/32.png) [@mhsh64](https://discuss.elastic.co/u/mhsh64)\
**Post date:** [July 27, 2019, 4:54pm UTC](https://discuss.elastic.co/t/index-lifecycle-rollover-alias-does-not-point-to-index/192525/5 "2019-07-27T16:54:12Z")

</div>

The reason for ILM for me it to roll over the indices which are for example having more than specific number of docs to another index with fewer shards, and after a few months, I want to delete them... However, I need to keep each day log into a separate index.  
If you see also this:  
[https://discuss.elastic.co/t/index-lifecycle-dilemma/177598](https://discuss.elastic.co/t/index-lifecycle-dilemma/177598)  
he wants to do the same thing, but for me it does not work.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 27, 2019, 5:22pm UTC](https://discuss.elastic.co/t/index-lifecycle-rollover-alias-does-not-point-to-index/192525/6 "2019-07-27T17:22:18Z")

</div>

> [@mhsh64](#):
>
> to roll over the indices which are for example having more than specific number of docs to another index with fewer shards, and after a few months, I want to delete them... However, I need to keep each day log into a separate index.

I cannot reconcile rolling over on anything other that age with keeping each day in a separate index. Have you looked at [using date math](https://www.elastic.co/guide/en/elasticsearch/reference/7.x/indices-rollover-index.html#_using_date_math_with_the_rollover_api)?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2019, 5:28pm UTC](https://discuss.elastic.co/t/index-lifecycle-rollover-alias-does-not-point-to-index/192525/8 "2019-08-24T17:28:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
