# Как добавить "is\_write\_index": true в index template?

**URL:** <https://discuss.elastic.co/t/is-write-index-true-index-template/218598>\
**Category:** Вопросы на русском языке\
**Created:** [February 10, 2020, 1:47pm UTC](https://discuss.elastic.co/t/is-write-index-true-index-template/218598 "2020-02-10T13:47:20Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![11191](https://avatars.discourse-cdn.com/v4/letter/1/9dc877/32.png) [@11191](https://discuss.elastic.co/u/11191)\
**Post date:** [February 10, 2020, 1:47pm UTC](https://discuss.elastic.co/t/is-write-index-true-index-template/218598/1 "2020-02-10T13:47:21Z")

</div>

Если добавляю эту опцию к template который указываю в template\_name в output { elasticsearch { template\_name =\> "haproxy" } }, то она просто пропадает.  
И в GET /\_template/haproxy вижу:  
"aliases" : {  
"haproxy" : { }  
}  
Хотя в PUT /\_template/haproxy четко указал:  
"aliases" : {  
"haproxy" : {  
"is\_write\_index": true  
}  
}

Как добавить эту опцию чтобы ILM не ругался на  
illegal\_argument\_exception: source alias [haproxy] does not point to a write index

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [February 10, 2020, 1:56pm UTC](https://discuss.elastic.co/t/is-write-index-true-index-template/218598/2 "2020-02-10T13:56:55Z")

</div>

Do any aliases exist?

GET \_cat/indices/haproxy\*

I think you assigned the alias to the template, the alias needs to be assigned to the index with one having "is\_write\_index": true.

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [February 10, 2020, 3:43pm UTC](https://discuss.elastic.co/t/is-write-index-true-index-template/218598/3 "2020-02-10T15:43:09Z")

</div>

Через template не получится (я открыл [https://github.com/elastic/elasticsearch/issues/52152](https://github.com/elastic/elasticsearch/issues/52152)), надо либо индекс либо алиас вручную создавать.

---

<div class="post-metadata">

**Author:** ![11191](https://avatars.discourse-cdn.com/v4/letter/1/9dc877/32.png) [@11191](https://discuss.elastic.co/u/11191)\
**Post date:** [February 11, 2020, 7:59am UTC](https://discuss.elastic.co/t/is-write-index-true-index-template/218598/4 "2020-02-11T07:59:39Z")

</div>

Но индексы каждый час создает logstash, назначать alias там возможности нет, есть только такой функционал:  
output {  
elasticsearch {  
ilm\_rollover\_alias =\> "custom"  
ilm\_pattern =\> "000001"  
ilm\_policy =\> "custom\_policy"  
}  
}  
У меня конфигурация такая:  
output {  
elasticsearch {  
id =\> "HAP Out"  
hosts =\>   
user =\> ""  
password =\> ""  
index =\> "haproxy-%{+YYYY.MM.dd-HH}"  
template\_name =\> "haproxy"  
}  
Что тогда в ilm\_pattern прописать?

---

<div class="post-metadata">

**Author:** ![11191](https://avatars.discourse-cdn.com/v4/letter/1/9dc877/32.png) [@11191](https://discuss.elastic.co/u/11191)\
**Post date:** [February 11, 2020, 8:01am UTC](https://discuss.elastic.co/t/is-write-index-true-index-template/218598/5 "2020-02-11T08:01:05Z")

</div>

No aliases. How can I assign alias to index created hourly by logstash?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [February 11, 2020, 2:24pm UTC](https://discuss.elastic.co/t/is-write-index-true-index-template/218598/6 "2020-02-11T14:24:48Z")

</div>

ILM rollover phase will move the is\_write\_alias to the new index at rollover. To get started, the first index needs to exist and have is\_write\_alias: true. Use a [POST like this](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-aliases.html#aliases-write-index) to update the latest haproxy index with the is\_write\_alias.

```
POST /_aliases
{
    "actions" : [
        {
            "add" : {
                 "index" : "haproxy-000001",
                 "alias" : "haproxy",
                 "is_write_index" : true
            }
        }
}

```

If you don't have the initial ILM style index, you can create it as in the doc example

```
PUT datastream-000001
{
  "aliases": {
    "datastream": {
      "is_write_index": true
    }
  }
}

```

It's a frequent confusion getting ILM working for the first time in more complex configurations, but once it works, you will see that there are many different ways to configure ILM.

---

<div class="post-metadata">

**Author:** ![11191](https://avatars.discourse-cdn.com/v4/letter/1/9dc877/32.png) [@11191](https://discuss.elastic.co/u/11191)\
**Post date:** [February 12, 2020, 2:50pm UTC](https://discuss.elastic.co/t/is-write-index-true-index-template/218598/7 "2020-02-12T14:50:02Z")

</div>

Logstash creates index every hour, I posted my output section above, what exactly should I do?

To output all data in one manually created index? I don't get it, sorry.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [February 12, 2020, 7:32pm UTC](https://discuss.elastic.co/t/is-write-index-true-index-template/218598/8 "2020-02-12T19:32:41Z")

</div>

After creating the "haproxy-000001" index that has the is\_write\_alias: true, the output below should work. You will point to the alias, the index where is\_write\_alias is true will get the output. Only one is allowed and it will move to haproxy-000002 at rollover.

```
output {
  elasticsearch {
    id => "HAP Out"
    hosts =>
    user => ""
    password => ""
    index => "haproxy"
    ilm_enabled => true
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 11, 2020, 7:32pm UTC](https://discuss.elastic.co/t/is-write-index-true-index-template/218598/9 "2020-03-11T19:32:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
