# Logstash - Elastichsearch Output - ILM

**URL:** <https://discuss.elastic.co/t/logstash-elastichsearch-output-ilm/263700>\
**Category:** Logstash\
**Created:** [February 9, 2021, 9:15am UTC](https://discuss.elastic.co/t/logstash-elastichsearch-output-ilm/263700 "2021-02-09T09:15:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jurilz](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@Jurilz](https://discuss.elastic.co/u/Jurilz)\
**Post date:** [February 9, 2021, 9:15am UTC](https://discuss.elastic.co/t/logstash-elastichsearch-output-ilm/263700/1 "2021-02-09T09:15:26Z")

</div>

Good day,

I'm trying to establish an Index Lifecycle Management for my indices by using the elasticsearch output in Logstash.

This is the elasticsearch output plugin config:

```auto
output {
  if "tomcat" in [type] {
    elasticsearch {
    hosts => ["https://elasticsearch:9200"]
    index => "filebeat-tomcat-7.10.0"
    user => "elastic"
    password => "<pw>"
    ssl => true
    cacert => "<path-to>-ca.crt"
    ilm_rollover_alias => "filebeat-tomcat"
    ilm_pattern => "000001"
    ilm_policy => "logs"
    }
  } else if "apache_access" in [type] {
    elasticsearch {
    hosts => ["https://elasticsearch:9200"]
    index => "filebeat-apache_access-7.10.0"
    user => "elastic"
    password => "<pw>"
    ssl => true
    cacert => "<path-to>-ca.crt"
    ilm_rollover_alias => "filebeat-apache_access"
    ilm_pattern => "000001"
    ilm_policy => "logs"
    }
  } else if "apache_error" in [type] {
    elasticsearch {
    hosts => ["https://elasticsearch:9200"]
    index => "filebeat-apache_error-7.10.0"
    user => "elastic"
    password => "<pw>"
    ssl => true
    cacert => "<path-to>-ca.crt"
    ilm_rollover_alias => "filebeat-apache_error"
    ilm_pattern => "000001"
    ilm_policy => "logs"
    }
  } else {
    elasticsearch {
    hosts => ["https://elasticsearch:9200"]
    index => "%{[@metadata][beat]}-%{[type]}-%{[@metadata][version]}"
    user => "elastic"
    password => "<pw>"
    ssl => true
    cacert => "<path-to>-ca.crt"
    }
  }
}

```

The indices are created with th indx name e. g. `filebeat-tomcat-000001`.

But in Kibana I get the error:

```auto
Index lifecycle error
illegal_argument_exception: setting [index.lifecycle.rollover_alias] for index [filebeat-apache_access-000001] is empty or not defined

```

And indeed a look at the filebeat-tomcat-000001 settings tells me:

```auto
"defaults": {
    "index": {
      ...
      "lifecycle": {
        "parse_origination_date": "false",
        "indexing_complete": "false",
        "rollover_alias": "",
        "origination_date": "-1"
      },
 ....

```

Did I configure the elasticsearch output plugin wrongly or can I add the rollover\_alias through the Rollover Index API?

Any help would be very much appreciated. TIA!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2021, 9:16am UTC](https://discuss.elastic.co/t/logstash-elastichsearch-output-ilm/263700/2 "2021-03-09T09:16:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
