# Index Policies Never Rollover to the Defined Index Life-cycle Policy

**URL:** <https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [March 3, 2021, 5:52pm UTC](https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146 "2021-03-03T17:52:15Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [March 3, 2021, 5:52pm UTC](https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146/1 "2021-03-03T17:52:15Z")

</div>

No matter what how I edit the index policies. The indexes never roll over to Warm tier.

My indexes just goes straight from hot to delete. Even though my index policy says the following:

```
PUT _ilm/policy/filebeat
{
  "policy": {
    "phases": {
      "hot": {
        "min_age": "0ms",
        "actions": {
          "forcemerge": {
            "max_num_segments": 1
          },
          "rollover": {
            "max_size": "15gb",
            "max_age": "7d"
          },
          "set_priority": {
            "priority": 100
          },
          "shrink": {
            "number_of_shards": 1
          }
        }
      },
      "warm": {
        "min_age": "30d",
        "actions": {
          "forcemerge": {
            "max_num_segments": 1
          },
          "set_priority": {
            "priority": 75
          },
          "shrink": {
            "number_of_shards": 1
          }
        }
      },
      "cold": {
        "min_age": "7d",
        "actions": {
          "freeze": {},
          "set_priority": {
            "priority": 50
          }
        }
      },
      "delete": {
        "min_age": "7d",
        "actions": {
          "delete": {
            "delete_searchable_snapshot": true
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 3, 2021, 10:22pm UTC](https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146/2 "2021-03-03T22:22:18Z")

</div>

Can you show an `_explain` for that policy?

---

<div class="post-metadata">

**Author:** ![dakrone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dakrone/32/23351_2.png) [@dakrone](https://discuss.elastic.co/u/dakrone)\
**Post date:** [March 3, 2021, 10:46pm UTC](https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146/3 "2021-03-03T22:46:09Z")

</div>

Your policy has a `min_age` for the warm phase of `30d`, but then the `cold` and `delete` phases both have a `min_age` of `7d`. This means that once your index hits the warm phase, it executes the actions in the warm phase, then goes directly to the cold, executes those, then directly goes to the delete phase and deletes the index.

Generally you'll always want the `min_age` to be getting increasingly longer, so something like 30d for warm, 45d for cold, and 60d for delete.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 3, 2021, 10:53pm UTC](https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146/4 "2021-03-03T22:53:41Z")

</div>

@dakrone would it make sense for the code to enforce incremental ages to prevent this?

---

<div class="post-metadata">

**Author:** ![dakrone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dakrone/32/23351_2.png) [@dakrone](https://discuss.elastic.co/u/dakrone)\
**Post date:** [March 3, 2021, 11:02pm UTC](https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146/5 "2021-03-03T23:02:01Z")

</div>

@warkolm we could enforce `>=`, but not `>`, as it's still valid to have a policy that just runs through actions sequentially regardless of timing (for instance, 0d for both a warm and cold phase).

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [March 5, 2021, 3:06am UTC](https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146/6 "2021-03-05T03:06:45Z")

</div>

I'm trying to make it do this.

7 Days = Hot

30 Days = Warm

7 Days = Cold

7 Days = Delete

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [March 5, 2021, 3:17am UTC](https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146/7 "2021-03-05T03:17:29Z")

</div>

What would `_explain ` for filebeat policy look like. I've never used that query before.

---

<div class="post-metadata">

**Author:** ![dakrone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dakrone/32/23351_2.png) [@dakrone](https://discuss.elastic.co/u/dakrone)\
**Post date:** [March 5, 2021, 6:45pm UTC](https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146/8 "2021-03-05T18:45:01Z")

</div>

> [@austinsonger](#):
>
> I'm trying to make it do this.
> 
> 7 Days = Hot
> 
> 30 Days = Warm
> 
> 7 Days = Cold
> 
> 7 Days = Delete

ILM timings are _absolute_ time. So you'd need something like:

- warm - `min_age: 7d`
- cold - `min_age: 37d`
- delete - `min_age: 44d`

This means "enter the warm phase after the index is 7 days old[1]", then "enter the cold phase after the index is 37 days old", then "delete the index when it is 44 days old".

The 44 is 7 + 30 + 7 = 44.

[1]: technically it's calculated based on the time rollover completes, but calling it "age" is easier to reason about.

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [March 5, 2021, 7:11pm UTC](https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146/9 "2021-03-05T19:11:42Z")

</div>

```
{
  "indices" : {
    "filebeat-7.10.0-2021.02.16-000048" : {
      "index" : "filebeat-7.10.0-2021.02.16-000048",
      "managed" : true,
      "policy" : "filebeat",
      "lifecycle_date_millis" : 1614030669690,
      "age" : "10.88d",
      "phase" : "hot",
      "phase_time_millis" : 1613733539746,
      "action" : "complete",
      "action_time_millis" : 1614030672843,
      "step" : "complete",
      "step_time_millis" : 1614030672843,
      "phase_execution" : {
        "policy" : "filebeat",
        "phase_definition" : {
          "min_age" : "0ms",
          "actions" : {
            "rollover" : {
              "max_size" : "15gb",
              "max_age" : "7d"
            }
          }
        },
        "version" : 16,
        "modified_date_in_millis" : 1613433116392
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![dakrone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dakrone/32/23351_2.png) [@dakrone](https://discuss.elastic.co/u/dakrone)\
**Post date:** [March 5, 2021, 7:13pm UTC](https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146/10 "2021-03-05T19:13:57Z")

</div>

> [@austinsonger](#):
>
> ` "age" : "10.88d",`

Here you can see that the index is 10.88 days old, not old enough yet to entire the `warm` phase, which is configured with `min_age: "30d"`

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [March 5, 2021, 7:17pm UTC](https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146/11 "2021-03-05T19:17:25Z")

</div>

Oh Okay. I was looking at it in the wrong way. I read so much documentation about it, but you cleared it up way easier then the documentation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2021, 7:17pm UTC](https://discuss.elastic.co/t/index-policies-never-rollover-to-the-defined-index-life-cycle-policy/266146/12 "2021-03-19T19:17:34Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
