# Logstash index lifecycle management

**URL:** <https://discuss.elastic.co/t/logstash-index-lifecycle-management/196142>\
**Category:** Logstash\
**Tags:** ilm-index-lifecycle-management\
**Created:** [August 21, 2019, 3:08pm UTC](https://discuss.elastic.co/t/logstash-index-lifecycle-management/196142 "2019-08-21T15:08:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jiri\_Safar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jiri_safar/32/44982_2.png) [@Jiri\_Safar](https://discuss.elastic.co/u/Jiri_Safar)\
**Post date:** [August 21, 2019, 3:08pm UTC](https://discuss.elastic.co/t/logstash-index-lifecycle-management/196142/1 "2019-08-21T15:08:58Z")

</div>

Hi guys,

I would like to set "index lifecycle management " on LOGSTASH output.  
It would means that everything that goes via this output will get "ndex lifecycle management" which was created in Kibana.

This is how my OUTPUT looks like:

elasticsearch {  
hosts =\> "[http://elasticsearchserverxxx:9200/](http://elasticsearchserverxxx:9200/)"  
index =\> "%{application}-dev-%{+YYYY.MM.dd}"  
user =\> "user"  
password =\> "pasword"  
ilm\_enabled =\> true  
ilm\_policy =\> "DEV/TEST/PROD\_Delete\_old\_data"  
}  
}

But any of new index doesn't apply this "DEV/TEST/PROD\_Delete\_old\_data" policy. Do I have to set something differently? Thanks

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [August 22, 2019, 3:03am UTC](https://discuss.elastic.co/t/logstash-index-lifecycle-management/196142/2 "2019-08-22T03:03:32Z")

</div>

You didn't say what version, but it looks like 6x. In 7x the ilm\_ options are moved out of the plugin to a setup section, to make it clear that the mostly do things at setup, not at ingest time.

Before ILM, you could allow new %{application} values to automatically create new indices. WIth ILM, you can't. You will need to create a template and bootstrap (empty) index for each %{appliction} before you ingest. You can even use different ilm policies on indices, from the templates, I don't put that value in the plugin config.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2019, 3:03am UTC](https://discuss.elastic.co/t/logstash-index-lifecycle-management/196142/3 "2019-09-19T03:03:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
