# Index templates lifecycle management

**URL:** <https://discuss.elastic.co/t/index-templates-lifecycle-management/254950>\
**Category:** Kibana\
**Tags:** ilm-index-lifecycle-management\
**Created:** [November 10, 2020, 4:34pm UTC](https://discuss.elastic.co/t/index-templates-lifecycle-management/254950 "2020-11-10T16:34:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [November 10, 2020, 4:34pm UTC](https://discuss.elastic.co/t/index-templates-lifecycle-management/254950/1 "2020-11-10T16:34:27Z")

</div>

I created an Index lifecycle policy to delete logs file entries older than 93 days to help with disk space and retention policies.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/a/3a1cea176b8f9dece3d756ea676e4086eb17fe6c.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/6/66375fc733136dd016b46e6fa17f72b94d0d8fd0.png)

I noticed that I need to create an index template to link to the policy, so I created the one below:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/d/7deed729454b1e4af84b43721818eb3325a7b0c6.png)

However, when I try to link the retention policy to this index template, it doesn't show up in the list:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5e9d81995eca8dbf8a66a93d082577b94aa709ea.png)

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [November 11, 2020, 5:16pm UTC](https://discuss.elastic.co/t/index-templates-lifecycle-management/254950/2 "2020-11-11T17:16:45Z")

</div>

Looks like you are only seeing "legacy" index templates, which was fixed in the release of 7.10.0 a few hours ago. So you can either upgrade to use the Kibana UI, or you can work around the UI bug in older versions by running the API request directly. You can [update the template settings](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-template.html) manually by assigning the `index.lifecycle.name` to`93-Day-Retention-Policy`. There's also a way to assign this manually to indices even if they weren't matched by the template:

> **[Configure a lifecycle policy | Elasticsearch Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/set-up-lifecycle-policy.html#apply-policy-manually)**

Hopefully this helps!

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [November 11, 2020, 5:20pm UTC](https://discuss.elastic.co/t/index-templates-lifecycle-management/254950/3 "2020-11-11T17:20:57Z")

</div>

One more option for you: you can enter this manually as JSON by going to the Edit Template UI, typing the same JSON key for `index.lifecycle.name`

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [November 12, 2020, 9:34am UTC](https://discuss.elastic.co/t/index-templates-lifecycle-management/254950/4 "2020-11-12T09:34:43Z")

</div>

Would I have to update all components, so Elastic, Kibana, Logstash, Filebeat, Winlogbeat? Or could I get away with updating just Kibana?

I haven't used the JSON stuff before, how would I apply it via this method?

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [November 12, 2020, 10:44am UTC](https://discuss.elastic.co/t/index-templates-lifecycle-management/254950/5 "2020-11-12T10:44:44Z")

</div>

So, I created the following:

```auto
POST logstash-*/_delete_by_query
{
 "query": {
   "range": {
     "@timestamp": {
       "lte": "now-93d"
      }
    }
  }
}

POST winlogbeat-*/_delete_by_query
{
 "query": {
   "range": {
     "@timestamp": {
       "lte": "now-93d"
      }
    }
  }
}

POST filebeat-*/_delete_by_query
{
 "query": {
   "range": {
     "@timestamp": {
       "lte": "now-93d"
      }
    }
  }
}

```

Does this need to be manually run, or can it run automatically every so often somehow?  
I presume this would be correct to delete anything older than 93 days for those queries? I ran them and they came back with successful results, although nothing was deleted as it hasn't been running for 93 days yet.

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [November 12, 2020, 4:38pm UTC](https://discuss.elastic.co/t/index-templates-lifecycle-management/254950/6 "2020-11-12T16:38:24Z")

</div>

The purpose of Index Lifecycle Management is to automate that- you shouldn't need to manually delete documents. Like I said, you can do this from the Kibana UI by going to the "Edit template" UI. You can find it in:

Stack Management \> Index Management \> Index Templates \> metricbeat-\* \> Edit \> Page 3, Index settings

And then you can use the setting `{ "index.lifecycle.name": "93-Day-Retention-Policy" }`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 10, 2020, 4:38pm UTC](https://discuss.elastic.co/t/index-templates-lifecycle-management/254950/7 "2020-12-10T16:38:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
