# Lifecycle Policy

**URL:** https://discuss.elastic.co/t/lifecycle-policy/381211
**Category:** Elasticsearch
**Tags:** ilm-index-lifecycle-management
**Created:** [August 21, 2025, 6:27pm UTC](https://discuss.elastic.co/t/lifecycle-policy/381211 "2025-08-21T18:27:39Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![GiorgioS13](https://avatars.discourse-cdn.com/v4/letter/g/5fc32e/32.png) [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)
#### Post date: [August 21, 2025, 6:27pm UTC](https://discuss.elastic.co/t/lifecycle-policy/381211/1 "2025-08-21T18:27:39Z")

</div>

I created a lifecycle policy in Kibana and attached it to a data stream, for example:

`logs-system.syslog-default`

However, the indices it created, such as:

`.ds-logs-system.syslog-default-2025.08.21-000001`

are still showing the old policy.

Do I need to manually update each index, or since this is a data stream, will the policy applied to the data stream (in this case `logs-system.syslog-default`) automatically propagate to its backing indices?

Thanks.

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [August 21, 2025, 6:48pm UTC](https://discuss.elastic.co/t/lifecycle-policy/381211/2 "2025-08-21T18:48:59Z")

</div>

> [@GiorgioS13](#):
>
> Do I need to manually update each index, or since this is a data stream, will the policy applied to the data stream (in this case `logs-system.syslog-default`) automatically propagate to its backing indices?

Any change on the template of a data stream will only be applied to new backing indices, the already existing back indices will not change.

You would need to edit each backing indice in the Index Management page and change the policy name.

---

<div class="post-metadata">

### Author: ![GiorgioS13](https://avatars.discourse-cdn.com/v4/letter/g/5fc32e/32.png) [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)
#### Post date: [August 22, 2025, 3:01pm UTC](https://discuss.elastic.co/t/lifecycle-policy/381211/4 "2025-08-22T15:01:05Z")

</div>

> [@GiorgioS13](#):
>
> I tested it on a specific index — it worked, and the data moved to the **cold node**.  
> However, it still appears under the hot node as well. Why is that?
> 
> In Stack Monitoring, when I select the hot node (as well as the cold node), I see the same shard listed in the hot also cold

I tested it on a specific index — it worked, and the data moved to the **cold node**.  
However, it still appears under the hot node as well. Why is that?

In Stack Monitoring, when I select the hot node (as well as the cold node), I see the same shard listed in the hot also cold. @leandrojmp

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [August 22, 2025, 3:03pm UTC](https://discuss.elastic.co/t/lifecycle-policy/381211/5 "2025-08-22T15:03:03Z")

</div>

> [@GiorgioS13](#):
>
> However, it still appears under the hot node as well. Why is that?

You need to provide more context about your nodes.

What are the roles you have in `elasticsearch.yml` for each node?

Also, share a screenshot of what you are seeing, it is not clear exactly what you are seeing.

---

<div class="post-metadata">

### Author: ![GiorgioS13](https://avatars.discourse-cdn.com/v4/letter/g/5fc32e/32.png) [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)
#### Post date: [August 22, 2025, 3:13pm UTC](https://discuss.elastic.co/t/lifecycle-policy/381211/6 "2025-08-22T15:13:10Z")

</div>

Here is Hot data node .yam configuration file:

node.roles: [data, data\_content, data\_hot, data\_warm, ingest, master, remote\_cluster\_client, transform]

and here is cold:  
node.roles: [data\_cold,master, voting\_only]

See screenshot from cold machine:

 ![Screenshot from 2025-08-22 19-09-47](https://us1.discourse-cdn.com/elastic/original/3X/d/e/de439d899574a7c455d6b8c87cf061f4a80521c5.png)

See screenshot from hot machine:

 ![2](https://us1.discourse-cdn.com/elastic/original/3X/3/6/36f24d008a0b130ad3bf8141760fa7ea5242c271.png)

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [August 22, 2025, 3:16pm UTC](https://discuss.elastic.co/t/lifecycle-policy/381211/7 "2025-08-22T15:16:53Z")

</div>

> [@GiorgioS13](#):
>
> node.roles: [data, data\_content, data\_hot, data\_warm, ingest, master, remote\_cluster\_client, transform]

Your hot node have the `data` role, this puts the node in all tiers and takes precedence over specialized roles. [[documentation](https://www.elastic.co/docs/deploy-manage/distributed-architecture/clusters-nodes-shards/node-roles#data-node-role)]

You need to remove the `data` role from the hot nodes and restart them.

---

<div class="post-metadata">

### Author: ![GiorgioS13](https://avatars.discourse-cdn.com/v4/letter/g/5fc32e/32.png) [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)
#### Post date: [August 22, 2025, 3:21pm UTC](https://discuss.elastic.co/t/lifecycle-policy/381211/8 "2025-08-22T15:21:33Z")

</div>

Do I need to take any additional steps to ensure it is moved completely,or just remove the data roles and next restart, so that it no longer shows up under both nodes?

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [August 22, 2025, 3:23pm UTC](https://discuss.elastic.co/t/lifecycle-policy/381211/9 "2025-08-22T15:23:33Z")

</div>

How many nodes of each tier do you have?

Since you have replicas you need at least 2 nodes of each tier, or else your cluster will be in a yellow state and you would need to remove the replicas to change the state back to green.

---

<div class="post-metadata">

### Author: ![GiorgioS13](https://avatars.discourse-cdn.com/v4/letter/g/5fc32e/32.png) [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)
#### Post date: [August 22, 2025, 3:31pm UTC](https://discuss.elastic.co/t/lifecycle-policy/381211/10 "2025-08-22T15:31:57Z")

</div>

It is just test environment

**Hot A** node.roles: [data, data\_content, data\_hot, data\_warm, ingest, master, remote\_cluster\_client, transform]

**Hot B** node.roles: [data, data\_content, data\_hot, data\_warm, ingest, master, remote\_cluster\_client, transform]

**Cold** node.roles: [data\_cold, master, voting\_only]

I want just move completely move in cold node some specific indices without stay on the hot node(s)

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [August 22, 2025, 3:35pm UTC](https://discuss.elastic.co/t/lifecycle-policy/381211/11 "2025-08-22T15:35:43Z")

</div>

Then you just need to remove the `data` role from your nodes and restart them, the cluster will organize the shards.

---

<div class="post-metadata">

### Author: ![GiorgioS13](https://avatars.discourse-cdn.com/v4/letter/g/5fc32e/32.png) [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)
#### Post date: [August 22, 2025, 10:08pm UTC](https://discuss.elastic.co/t/lifecycle-policy/381211/13 "2025-08-22T22:08:22Z")

</div>

After I removed the data role from the YAML file, I tried adding the Windows integration for testing, but it now gets stuck at this stage.

Do you have any idea what might be causing this? @leandrojmp

Screenshot:

 ![Screenshot from 2025-08-23 02-05-36](https://us1.discourse-cdn.com/elastic/original/3X/1/0/102bf6a38c09fb5b13c5802120021b57067eda74.png)
