# Lifecycle error

**URL:** <https://discuss.elastic.co/t/lifecycle-error/248987>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [September 17, 2020, 1:54pm UTC](https://discuss.elastic.co/t/lifecycle-error/248987 "2020-09-17T13:54:29Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tuckson](https://avatars.discourse-cdn.com/v4/letter/t/f14d63/32.png) [@Tuckson](https://discuss.elastic.co/u/Tuckson)\
**Post date:** [September 17, 2020, 1:54pm UTC](https://discuss.elastic.co/t/lifecycle-error/248987/1 "2020-09-17T13:54:29Z")

</div>

Hi,

Getting a bit desperate of all things that go wrong.

This time I bump into this lifecycle error. I really want to split indexes op since they grow to hundreds of Gb.

But...  
Index lifecycle error

```
illegal_argument_exception: index.lifecycle.rollover_alias [agl-*] does not point to index [agl-api-7.9.1-2020.09.17-00001]

```

I created that alias agl in the template.

Settings:

```auto
{
  "settings": {
    "index": {
      "lifecycle": {
        "name": "AVS-logs",
        "rollover_alias": "agl-*"
      },
      "refresh_interval": "10s",
      "number_of_shards": "5",
      "provided_name": "agl-api-7.9.1-2020.09.17-00001",
      "creation_date": "1600301134279",
      "priority": "100",
      "number_of_replicas": "1",
      "uuid": "z83FudTWQFK2J5zOZ6gaRw",
      "version": {
        "created": "7090199"
      }
    }
  },
  "defaults": {
    "index": {
      "flush_after_merge": "512mb",
      "final_pipeline": "_none",
      "max_inner_result_window": "100",
      "unassigned": {
        "node_left": {
          "delayed_timeout": "1m"
        }
      },
      "max_terms_count": "65536",
      "lifecycle": {
        "parse_origination_date": "false",
        "indexing_complete": "false",
        "origination_date": "-1"
      },
      "routing_partition_size": "1",
      "force_memory_term_dictionary": "false",
      "max_docvalue_fields_search": "100",
      "merge": {
        "scheduler": {
          "max_thread_count": "4",
          "auto_throttle": "true",
          "max_merge_count": "9"
        },
        "policy": {
          "reclaim_deletes_weight": "2.0",
          "floor_segment": "2mb",
          "max_merge_at_once_explicit": "30",
          "max_merge_at_once": "10",
          "max_merged_segment": "5gb",
          "expunge_deletes_allowed": "10.0",
          "segments_per_tier": "10.0",
          "deletes_pct_allowed": "33.0"
        }
      },
      "max_refresh_listeners": "1000",
      "max_regex_length": "1000",
      "load_fixed_bitset_filters_eagerly": "true",
      "number_of_routing_shards": "1",
      "write": {
        "wait_for_active_shards": "1"
      },
      "verified_before_close": "false",
      "mapping": {
        "coerce": "false",
        "nested_fields": {
          "limit": "50"
        },
        "depth": {
          "limit": "20"
        },
        "field_name_length": {
          "limit": "9223372036854775807"
        },
        "total_fields": {
          "limit": "1000"
        },
        "nested_objects": {
          "limit": "10000"
        },
        "ignore_malformed": "false"
      },
      "source_only": "false",
      "soft_deletes": {
        "enabled": "false",
        "retention": {
          "operations": "0"
        },
        "retention_lease": {
          "period": "12h"
        }
      },
      "max_script_fields": "32",
      "query": {
        "default_field": [
          "*"
        ],
        "parse": {
          "allow_unmapped_fields": "true"
        }
      },
      "format": "0",
      "frozen": "false",
      "sort": {
        "missing": [],
        "mode": [],
        "field": [],
        "order": []
      },
      "codec": "default",
      "max_rescore_window": "10000",
      "max_adjacency_matrix_filters": "100",
      "analyze": {
        "max_token_count": "10000"
      },
      "gc_deletes": "60s",
      "top_metrics_max_size": "10",
      "optimize_auto_generated_id": "true",
      "max_ngram_diff": "1",
      "hidden": "false",
      "translog": {
        "generation_threshold_size": "64mb",
        "flush_threshold_size": "512mb",
        "sync_interval": "5s",
        "retention": {
          "size": "512MB",
          "age": "12h"
        },
        "durability": "REQUEST"
      },
      "auto_expand_replicas": "false",
      "mapper": {
        "dynamic": "true"
      },
      "recovery": {
        "type": ""
      },
      "requests": {
        "cache": {
          "enable": "true"
        }
      },
      "data_path": "",
      "highlight": {
        "max_analyzed_offset": "1000000"
      },
      "routing": {
        "rebalance": {
          "enable": "all"
        },
        "allocation": {
          "enable": "all",
          "total_shards_per_node": "-1"
        }
      },
      "search": {
        "slowlog": {
          "level": "TRACE",
          "threshold": {
            "fetch": {
              "warn": "-1",
              "trace": "-1",
              "debug": "-1",
              "info": "-1"
            },
            "query": {
              "warn": "-1",
              "trace": "-1",
              "debug": "-1",
              "info": "-1"
            }
          }
        },
        "idle": {
          "after": "30s"
        },
        "throttled": "false"
      },
      "fielddata": {
        "cache": "node"
      },
      "default_pipeline": "_none",
      "max_slices_per_scroll": "1024",
      "shard": {
        "check_on_startup": "false"
      },
      "xpack": {
        "watcher": {
          "template": {
            "version": ""
          }
        },
        "version": "",
        "ccr": {
          "following_index": "false"
        }
      },
      "percolator": {
        "map_unmapped_fields_as_text": "false"
      },
      "allocation": {
        "max_retries": "5",
        "existing_shards_allocator": "gateway_allocator"
      },
      "indexing": {
        "slowlog": {
          "reformat": "true",
          "threshold": {
            "index": {
              "warn": "-1",
              "trace": "-1",
              "debug": "-1",
              "info": "-1"
            }
          },
          "source": "1000",
          "level": "TRACE"
        }
      },
      "compound_format": "0.1",
      "blocks": {
        "metadata": "false",
        "read": "false",
        "read_only_allow_delete": "false",
        "read_only": "false",
        "write": "false"
      },
      "max_result_window": "10000",
      "store": {
        "stats_refresh_interval": "10s",
        "type": "",
        "fs": {
          "fs_lock": "native"
        },
        "preload": []
      },
      "queries": {
        "cache": {
          "enabled": "true"
        }
      },
      "warmer": {
        "enabled": "true"
      },
      "max_shingle_diff": "3",
      "query_string": {
        "lenient": "false"
      }
    }
  }
}

```

Lifecycle policy:

```auto
PUT _ilm/policy/AVS-logs
{
  "policy": {
    "phases": {
      "hot": {
        "min_age": "0ms",
        "actions": {
          "rollover": {
            "max_age": "2d",
            "max_size": "50gb",
            "max_docs": 2000000000
          },
          "set_priority": {
            "priority": 100
          }
        }
      },
      "warm": {
        "actions": {
          "set_priority": {
            "priority": 50
          },
          "shrink": {
            "number_of_shards": 2
          }
        }
      },
      "cold": {
        "min_age": "3d",
        "actions": {
          "set_priority": {
            "priority": 0
          }
        }
      },
      "delete": {
        "min_age": "12d",
        "actions": {
          "delete": {
            "delete_searchable_snapshot": true
          }
        }
      }
    }
  }
}

```

What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![Tuckson](https://avatars.discourse-cdn.com/v4/letter/t/f14d63/32.png) [@Tuckson](https://discuss.elastic.co/u/Tuckson)\
**Post date:** [September 17, 2020, 9:59pm UTC](https://discuss.elastic.co/t/lifecycle-error/248987/2 "2020-09-17T21:59:15Z")

</div>

Nobody?  
I think I need to tackle this, so any help is appreciated.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 20, 2020, 11:51pm UTC](https://discuss.elastic.co/t/lifecycle-error/248987/3 "2020-09-20T23:51:45Z")

</div>

Typically, your `rollover_alias` won't use a wildcard like that and it'd be something like `agl-api`.  
Can you alter that?

Otherwise what you need to do is something like;

```auto
PUT /agl-api-7.9.1-2020.09.17-00001/_alias/agl-*

```

But I am not sure a wildcard there will work.

---

<div class="post-metadata">

**Author:** ![Tuckson](https://avatars.discourse-cdn.com/v4/letter/t/f14d63/32.png) [@Tuckson](https://discuss.elastic.co/u/Tuckson)\
**Post date:** [September 23, 2020, 1:48pm UTC](https://discuss.elastic.co/t/lifecycle-error/248987/4 "2020-09-23T13:48:27Z")

</div>

Thnx. this indeed was a thing I needed to alter. I am still not there however.

I create a new index which does not change name per day.And I manually set some aliases and this seems to work.

However... This s not what I need.

My outputfilter in logstash is will be this:

```auto
output {
        # Send the events to ElasticSearch, which a different index based on the log file the events came from.
        if "api-log" in [tags] or "access-log" in [tags] or "tls-proxy" in [tags] {
                elasticsearch {
                        hosts => ["pdbs359.grn.prd.itv.local:9200","pdbs358.grn.prd.itv.local:9200"]
                        document_id => "%{[@metadata][fingerprint]}"
                        index => "%{[@metadata][indexbasename]}-{+YYYY.MM.dd}"
                        sniffing => false
                }
}
}

```

Can I add stuff here to make Elasticsearch add a decent alias based on the indexname and add the appropriate lifecyclepolicy automatically?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 23, 2020, 11:50pm UTC](https://discuss.elastic.co/t/lifecycle-error/248987/5 "2020-09-23T23:50:56Z")

</div>

The thing that needs reconciling here is that ILM will roll an index on a daily basis (if you tell it), but it doesn't change the name of the index to match that date. The date in the index name is the date that the index was created under the policy.

TLDR - change the `index` directive in the output to point to your ILM write alias.

---

<div class="post-metadata">

**Author:** ![Tuckson](https://avatars.discourse-cdn.com/v4/letter/t/f14d63/32.png) [@Tuckson](https://discuss.elastic.co/u/Tuckson)\
**Post date:** [September 24, 2020, 10:00am UTC](https://discuss.elastic.co/t/lifecycle-error/248987/6 "2020-09-24T10:00:07Z")

</div>

Switched ilm off for now. First need to get the rest up and running normally. Just can't get it to work.

Thnx anyway

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2020, 10:00am UTC](https://discuss.elastic.co/t/lifecycle-error/248987/7 "2020-10-22T10:00:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
