# Index template create automatically

**URL:** <https://discuss.elastic.co/t/index-template-create-automatically/360815>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [June 5, 2024, 2:49am UTC](https://discuss.elastic.co/t/index-template-create-automatically/360815 "2024-06-05T02:49:06Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Frances\_Chu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frances_chu/32/127298_2.png) [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Post date:** [June 5, 2024, 2:49am UTC](https://discuss.elastic.co/t/index-template-create-automatically/360815/1 "2024-06-05T02:49:06Z")

</div>

I would like to setup the index lifecycle by using index template to create a new index ( **test\_index-yyyy.MM.dd** ) every 30 days

My log will send form **filebeat** --\> **logstash** --\> **Elasticsearch**.

1. configuration a policy ( **test\_policy** ) --\> enable rollover--\>set maximum age:30 days

2. create index templates ( **test\_template** )--\> index pattern ( **test\_index** \*) --\>setting (index.lifecycle.name= **test\_policy** ) (index.lifecycle.rollover\_alias= **test\_index** )  

3.Bootstrap the initial time series index with a write index alias

```auto
PUT test_index_2024.06.05-000001
{
  "aliases": {
    "test_index": {
      "is_write_index": true
    }
  }
}

```

1. configure filebeat.yml to set the tag of the log

```auto
- type: log
  enabled: true
  paths:
      - /etc/monitor/*.log
  tags: ["test_index"]

```

restart filebeat serivce

1. configure /etc/logstash/conf.d/test\_index.conf

```auto
output {
  if "test_index" in [tags] {
    elasticsearch {
      hosts => ["https://x.x.x.x:9200"]
      user => "filebeat_user"
      password => "filebeat_password"
      ssl_certificate_authorities => "/etc/certs/xxxx.crt"
      ilm_rollover_alias => "test_index"
      ilm_pattern => "{now/d}-000001"
  }
}

```

Restart logstash service

1. When the index rollover i find one more template created automatically ( **test\_index** ), in additional to my test\_template,  
which pointed to the index pattern ( **test\_index** \*)  
 ![autoTemplate](https://us1.discourse-cdn.com/elastic/original/3X/1/0/105df6d6dbf9152152816ed29bba03258e7bcdd7.png)

settings

```auto

{
  "index": {
    "lifecycle": {
      "name": "logstash-policy",
      "rollover_alias": "test_index"
    },
    "mapping": {
      "total_fields": {
        "limit": "10000"
      }
    },
    "refresh_interval": "5s"
  }
}

```

With some mappings too.

Is there anything wrong to my steps??
