# Logstash ILM problem

**URL:** <https://discuss.elastic.co/t/logstash-ilm-problem/199830>\
**Category:** Logstash\
**Tags:** ilm-index-lifecycle-management\
**Created:** [September 17, 2019, 1:31pm UTC](https://discuss.elastic.co/t/logstash-ilm-problem/199830 "2019-09-17T13:31:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bharath.krishn2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bharath.krishn2/32/130240_2.png) [@bharath.krishn2](https://discuss.elastic.co/u/bharath.krishn2)\
**Post date:** [September 17, 2019, 1:31pm UTC](https://discuss.elastic.co/t/logstash-ilm-problem/199830/1 "2019-09-17T13:31:54Z")

</div>

I've created a life cycle policy and added it to an index-template.  
In the policy I've enabled the hot phase which will rollover the index if max\_docs is 50 or max\_age is 1h.  
Now the problem is that the new indices are created only when the document count exceeds 150.

Below is my life cycle policy

"logstash-policy" : {  
"version" : 4,  
"modified\_date" : "2019-09-17T12:59:47.001Z",  
"policy" : {  
"phases" : {  
"hot" : {  
"min\_age" : "0ms",  
"actions" : {  
"rollover" : {  
"max\_docs" : "50",  
"max\_age" : "1h"  
}  
}  
}  
}  
}  
}

Index settings:

```
"index": {
  "lifecycle": {
    "name": "logstash-policy",
    "rollover_alias": "logstash",
    "indexing_complete": "true"
  },
  "number_of_shards": "5",
  "provided_name": "<logstash-000004>",
  "creation_date": "1568725169438",
  "number_of_replicas": "1",
  "uuid": "YJOVjP2UT1etiVF-dYazeA",
  "version": {
    "created": "6060199"
  }
}

```

}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 17, 2019, 1:38pm UTC](https://discuss.elastic.co/t/logstash-ilm-problem/199830/2 "2019-09-17T13:38:22Z")

</div>

ILM only check limits every 10 minutes or so which is generally fine for real life scenarios but can trip up testing.

---

<div class="post-metadata">

**Author:** ![dakrone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dakrone/32/23351_2.png) [@dakrone](https://discuss.elastic.co/u/dakrone)\
**Post date:** [September 17, 2019, 4:42pm UTC](https://discuss.elastic.co/t/logstash-ilm-problem/199830/3 "2019-09-17T16:42:17Z")

</div>

As Christian mentioned, you can check out the setting (`indices.lifecycle.poll_interval`) here: [https://www.elastic.co/guide/en/elasticsearch/reference/7.4/ilm-settings.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/ilm-settings.html)

---

<div class="post-metadata">

**Author:** ![bharath.krishn2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bharath.krishn2/32/130240_2.png) [@bharath.krishn2](https://discuss.elastic.co/u/bharath.krishn2)\
**Post date:** [September 17, 2019, 4:59pm UTC](https://discuss.elastic.co/t/logstash-ilm-problem/199830/4 "2019-09-17T16:59:30Z")

</div>

Thanks @dakrone and @Christian_Dahlqvist I'll give it a try.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2019, 5:01pm UTC](https://discuss.elastic.co/t/logstash-ilm-problem/199830/5 "2019-10-15T17:01:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
