# Index rollover issues

**URL:** <https://discuss.elastic.co/t/index-rollover-issues/290669>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [December 1, 2021, 1:22pm UTC](https://discuss.elastic.co/t/index-rollover-issues/290669 "2021-12-01T13:22:20Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 3, 2021, 3:38pm UTC](https://discuss.elastic.co/t/index-rollover-issues/290669/5 "2021-12-03T15:38:00Z")

</div>

> [@sandeepmuthathi](#):
>
> . But index gives the following error. Any idea?  
> illegal\_argument\_exception: index.lifecycle.rollover\_alias [test-index] does not point to index [test-index-2021.12.01]

I suspect perhaps You need to create the initial managed index that maps the writer alias to a concrete index.

See [Here](https://www.elastic.co/guide/en/elasticsearch/reference/current/set-up-lifecycle-policy.html#create-initial-index)

Yours would look something like

```auto
PUT test-index-2021.12.01
{
  "aliases": {
    "test-index":{
      "is_write_index": true 
    }
  }
}

```

Also

```auto
            "rollover" : {
              "max_size" : "300kb", <!----- This is not going to work well
              "max_primary_shard_size" : "10gb",
              "max_age" : "1d"

```

ILM is mean to work on the scale of GBs etc. so it will not rollover exactly on 300KB etc. I have written a bit about that [here](https://discuss.elastic.co/t/ilm-doesnt-work/284285/3)

Also you will never want 300KB indices that is very small and inefficient.

> [@sandeepmuthathi](#):
>
> What is the best practice? Create the index from beat/logstash with date or configuring entire rollover stuff from ES itself?

Well typically I would suggest starting with the defaults from say filebeat where all this is already configured... and works out of the box... get used to how elastic works.

Today we suggest Shard Sized based Rollover ... Time Based / Daily has some usefulness but can end up with many small indices and shards which can be wasteful.

And of course there are some nice docs [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-management.html) and [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/size-your-shards.html)

---

_[View the full topic](https://discuss.elastic.co/t/index-rollover-issues/290669)._
